Cisco NAC server and check active number? Would this work?

Hi all

A client has achieved a question when we introduced Cisco NAC today.  They wondered, lets say, a client of Cisco NAC agent installed may be connected to the network switch. It has all valid requests and patch levels on his machine (posture validation check pass)

However, even if the customer takes the position of all the parameters, they want to know that if the host name of the client (for most Windows laptops) does not exist in their active database (this database is a database of estate number which is in a similar format or .csv) posture validation must fail.

Have you met such request like this before? Is there a function on the NAC server which checks a field against an external database as an active database?

See you soon.

Dumlu,

Currently, it is not possible. You can create controls who can check values locally, but not against external data warehouses, so for this card against your thinking, NAC would have to know all the names of workstation before hand and then check against that. It is unwieldy and very very difficult to scale.

If it's something you and your client think would be a good addition (and it sounds like a good idea) Please engage with your account team and ask them to request a feature for you.

Thank you

Faisal

Tags: Cisco Security

Similar Questions

  • I have cs5 on my home mac. I had it on my old mac laptop. I disabled it is then rendered to reinstall on my new laptop and my serial number does not work. Any help?

    I have photoshop CS5 extended on my Mac at home. I also had it on my computer mac laptop. I disabled it from my old laptop and tried to install it on my new laptop and the serial number would not work. Any thoughts?

    David o "bryan do you migrate/transfer of files/folders/applications for the new laptop Mac?  You can check that your serial number is valid by checking your account on http://www.adobe.com/.  You can find more information on how to locate your serial number to find your serial number fast - http://helpx.adobe.com/x-productkb/global/find-serial-number.html.

  • difference between cisco NAC agent and cisco Clean Access Agent

    Hi all

    If anyone has the idea on different between cisco NAC agent and cisco Clean Access Agent, please let us know your ideas.

    Thank you

    In 4.6, the agent has been revised and is now called the NAC agent.  Previous versions were called the clean access Agent.  So roughly, 4.5 and 4.1.3.2 agent are own access agents, and agents 4.6.x and 4.7.x are called NAC agents.

    Some of the changes are moving a lot of the agent configuration in an XML file, redesign of the GUI, adding a service portion (of the sort that the agent of heel is no longer necessary) and the best journaling agent.

  • You can wrap text around a picture in E10 by using the rich editor? You cannot superimpose an image and an area of just text, so how would this work?

    You can wrap text around a picture in E10 by using the rich editor? You cannot superimpose an image and an area of just text, so how would this work?

    Amy,

    You must place the image in the text box to wrap around him, or a heavier way test, you can use text several boxes and place them strategically around the image, but if you want to hyperlink the image you have to place it inside the text box and you can not overlap images and text in e-mail boxes.

    Hope this helps,

    Leigh

  • I need to re - install Photoshop and my serial number does not work?

    I need to re - install Photoshop and my serial number does not work?

    Quickly find your serial number

    Error "serial number is not valid for this product". Creative Suite

  • I changed my computer and my serial number no longer works

    I changed my computer and my serial number no longer works

    then contact adobe support: www.adobe.com/support/chat/ivrchat.html

  • NAC L2 and L3 Inband simultaneously does not work

    Dear all,

    I have a problem with the simultaneous deployment of L2 and L3 of the NAC.

    I have a CASE that is configured as a real IP gateway, broadband. Previosly, I can have the NAC working on L3 deployment using PBR. I configured the ACB on distribution switch in order to intercept the traffic of untrusted user NAC.

    Now our society tries to add wireless, using WLC, who have the interface vlan configured in CASES not reliable (using the section "managed subnet" on cam). the wireless run perfectly, they able to authenticate to the NAC and able to connect to the network after the authentication of the NAC.

    But now users of L3 cannot reach the unreliable for performing authentication of the NAC. The CASE cannot ping even L3 user which was previosly correct.

    Is there a limitation on Cisco NAC for the deployment of L2 and L3? I read Cisco that a single CASE can be configured to L3 and L2 UNLIMITED so I should work

    TQ
    Imad

    Imad,

    The way you described work is pretty close to the way in which we would have put in place.

    Glad it works for you now!

    My ' salam.

    Faisal

  • would this work?

    Hi guys

    After lurking here a few weeks ive finally decided to post

    I say more than all of the forums ive looked at it's most well informed and helpful

    IM interested especially in the shop photo CS5 but ive a canon 7 d could then do the weird video

    I know that this Ps is not your Forte guys but I would like some advice

    Ive been ofered this computer at a very reasonable price of new 550euros. would this PS handle and some hobby first

    I7-870 Lynnfield
    4, 00GB RAM DDR3 PC1600MHz
    Card mother Gigabyte H55M-USB3
    500 GB drive HARD SATA-2 7200 RPM
    24 x DL DVD burner Multi Format drive
    PSU 600 Watt
    ATI HD5770 1024 MB

    I'll add an ssd for the OS, programs etc.

    2x1To HD

    more RAM

    RAM is where im stuck the mobo has 4 slots, it comes with 2 sticks of 2 GB

    I can mix them, do I have to buy 4 matched sticks or can I use a series of 3 (3 x 4)

    Concerning

    Ian

    For the work of the PS, you are fine with these specifications.

  • After a defective boot drive had to be replaced on my XP PRO, he asked me to activity and my active code will not work. indicates an invalid sound. I just replaced the hard drive

    I just had to REPLACE a HARD DISK broke ON MY WINDOWS XP PRO AND WHEN I REINSTALLED operating SYS ASKED FOR the activation CODE, THEN SAYS MY CODE WAS INVALID AND WONT turn ON. ANITA PHONE TALKED TO A COMPUTER AND NO HELP. I HAVE THE SAME PC. JUST REPLACED HARD DRIVE.  IN ANY CASE TO ACTIVATE. I BOUGHT THIS NUMBER OUT OF MICROSOFT FOR 145.  LARRY BLAKE

    Hi beenabean,

    Refer to the article below and try the mentioned step, check to see if it helps.

    You receive an error message after you enter the product key when you try to install Windows XP

    http://support.Microsoft.com/kb/310637

    You are prompted to activate Windows XP or Windows Server 2003 every time that you start the computer

    http://support.Microsoft.com/kb/312295

    How to find a phone number for a Microsoft Product Activation Center

    http://support.Microsoft.com/kb/950929

  • ASA - added a public server and it is limited to this traffic

    I added an internal e-mail server to a whole new ASA5510 today.  I used the GUI because it is a fairly simple installation.  In any case, I added a mail server to allow the port 25 inbound on an address static nat dedicated to this server.  But now, this server can not do anything on the internet: the navigation or search DNS, etc..  The server is also the internal DNS server.  I'm probably missing?

    Hello

    It not on MAC address about proxy arp

    • Addresses on the same network as the interface is mapped.

    If you are using addresses on the same network that the mapped interface, the ASA uses proxy ARP to respond to all ARP requests for mapped addresses, thus intercepting traffic destined to a mapped address. This solution simplifies the delivery because the ASA is not to be the gateway for all additional networks. This solution is ideal if the external network contains a sufficient number of free addresses, a consideration if you are using a 1:1 translation as dynamic NAT or static dynamic NAT PAT greatly expands the number of translations, which you can use with a small number of addresses, so even if the addresses available on the external network is small, this method can be used. For PAT, you can even use the IP address of the mapped interface.

    Note If you configure the mapped interface to be any interface and you specify an address that is mapped to the same network as one interfaces mapped, then address topographiee in an ARP request for who arrives on a different interface, then you must manually configure an ARP entry for this network on the interface of penetration, by specifying its MAC address (see the arp command). Normally, if you specify an interface for the mapped interface, then you are using a single network for addresses mapped, so that this situation would not occur.

    • Addresses on a single network.

    If you need more addresses available on the mapped interface network, you can identify the address on a different subnet. The upstream router needs a static route for mapped addresses that points to the ASA. Otherwise for routed mode, you can configure a static route on the SAA for mapped addresses and then redistribute the route using your routing protocol. For transparent, if the real host is directly connected, configure the static route on the router upstream to point to the ASA: specify the IP address of the bridge group. For remote hosts in transparent mode, in the static route on the router upstream, you can also specify the IP address of router downstream.

    Mapped addresses and routing

    http://www.Cisco.com/c/en/us/TD/docs/security/ASA/asa91/configuration/firewall/asa_91_firewall_config/nat_overview.html

    HTH

    Sandy

  • I try to get lightroom on my new mac and the serial number does not work

    I have lightroom 5 on my computer mac laptop.  In lightroom I had last year.  I am now looking to get on my new iMac and he always tells me that I am using the serial number is incorrect.  How can I get lightroom on my new iMac?

    For more information on the location or the registration of serial numbers please see these links for assistance:

    Quickly find your serial number

    Please check that you enter the correct number. Special attention to 0 vs O and 1 l vs.

    If you get any type of error, please let us know.

    You can also check these links:

    Error failed to validate the serial number | CS6

    Error "serial number is not valid for this product". Creative Suite

    https://helpx.Adobe.com/x-productkb/policy-pricing/activation-network-issues.html

  • Download new mac and the serial number does not work.

    Is switched from Windows to mac and trying to download previously purchased Lightroom and it won't take serial number.

    If it's 6 of Lightroom, which is very likely.  Older versions of Lightroom came with a license that could be used for different operating systems, but the current version does not work.

    You should still be able to Exchange languages/platforms for a newer version product if you follow the instructions on the following link:

    l http://helpx.adobe.com/x-productkb/Policy-Pricing/Order-Product-Platform-Language-swap.htm

  • You just buy photoshop elements 14 and the serial number does not work

    Tried several things but the serial number just doesn't work.

    Helpdesk gives me no answer and said that it is a technical question and I will be contacted... wait... and wait.

    Please wait until we connect with a representative for the 5th time today.

    You have a serial number, or a redemption code?

    Redemption Code http://helpx.adobe.com/x-productkb/global/redemption-code-help.html

    - and https://forums.adobe.com/thread/1572504

  • Why am I not able to update the latest version of Firefox when it tells me that it is ready to download. It seems "stuck" on the connection to the update server and goes no further. This happens everytime I try for several months now.

    I think that the version he is trying to download is 10.something, and it seems to freeze on the window of 'progress' for quite awhile before I get it close. I've sometimes minimized the window while I did other things, coming to him perhaps 30 minutes later and the window is exactly the same as when I left it.

    You can try the alternative and easier way by downloading from here

  • Check the number of consecutive working days of Absence from a list of dates (F

    Hi all

    We have Oracle 11.5.7 Application human resources and I have a request to create an Absence report (using sql * more coding, which can be downloaded on the discoverer to run the report by the user) as follows:

    Columns of the sample:
    ABSENCE_CATEGORY
    ABSENCE_TYPE
    ABSENCE_START_DATE
    ABSENCE_END_DATE
    ABSENCE_DAYS

    Sample data:
    EMPLOYEE A (FOR LACK OF PERIOD 2009)
    ABSENCE_CATEGORY ABSENCE_TYPE ABSENCE_START_DATE ABSENCE_END_DATE ABSENCE_DAYS
    Annual leave, April 27, 2009 April 30, 2009 4
    May 4, 2009 educational leave may 4, 2009 1
    Leave annual P 5 May 2009 may 12, 2009 6
    ...

    TOTAL: 11 DAYS OF CONTINUOUS WORK ON LEAVE
    NOTES:
    MAY 1, 2009 HOLIDAY
    May 2, 2009 weekend & may 3, 2009
    Weekend May 9, 2009 & may 10, 2009

    B EMPLOYEE (FOR ABSENCE PERIOD 2009)
    ABSENCE_CATEGORY ABSENCE_TYPE ABSENCE_START_DATE ABSENCE_END_DATE ABSENCE_DAYS
    Annual leave, may 18, 2009 may 29, 2009-10
    ...
    TOTAL: 10 DAYS OF CONTINUOUS WORK ON LEAVE


    C EMPLOYEE (FOR ABSENCE PERIOD 2009)
    ABSENCE_CATEGORY ABSENCE_TYPE ABSENCE_START_DATE ABSENCE_END_DATE ABSENCE_DAYS
    8 June 2009 annual leave June 17, 2009 8
    ...
    TOTAL: 8 DAYS OF CONTINUOUS WORK ON LEAVE

    IF AN EMPLOYEE HAS TAKEN MORE CONSECUTIVE OR 10 WORKING DAYS SHOULD BE EXCLUDED FROM THE STATE.
    THAT IS WHY IN THE EXAMPLE ABOVE ONLY USED C MUST BE RETURNED BY THE QUERY.

    Ideas/comments if and how to achieve the highest performance will be much appreciated.
    Thanking you in advance,
    Best regards
    Elena

    Hello

    Cannot start a command with the keyword WITH in SQL * Plus 8 (or earlier).

    The best thing to do is to install a later version of SQL * Plus or SQL Developer. (You can have several versions, if you need. SQL * Plus 10 and more will not work with an Oracle database 8)

    Otherwise, you can re-write the query so that the command does not begin with the keyword WITH.
    For example:

    SELECT  *
    FROM    (  WITH A AS ...
            );
    

Maybe you are looking for

  • VMware 6.0 runs Satellite L300-14 X?

    Can someone tell me if VMware 6.0 will run on a toshiba Satellite L300-14 x, intel celeron 2.13 ghz processor and 4 GB of memory? I need to install 2 Windows Server 2003 and of Windows XP 1 client on the virtual computer? Please notify

  • DAQmxErrChk gives problem (the specified resource is reserved)

    Hello I'm new to programming. I have a four channel USB DAQ. I use CVI to program the channels. One of the channels gives a simple output of a voltage signal while the other generates a square wave. I used the example programs for my code. I use the

  • Missing entry: run DLL entry

    Each start up, I get this error message: X error in C:\Windows\System 32\spool\Drivers\W32X86\3\DLCF time.dll entry missing: Run DLL entry Please help if you can.  How can I get rid of him. TX, krg.fxrs

  • (Redirected) Cannot get the compatibility to windows 10 update

    I have dell Inspiron N4010, which shows an error while cheking for compatibility for windows 10 as driver broadcom wireless nd give me a message that the manufacturer did not have this pc compatible Windows 10 and my wireless connection does not work

  • Linksys SPA92 CUCM8.5 registration

    Team, Liksys SPA92 - Line can be registered to Cisco Unified Communications Manager v8.5 and if yes to the CSPC or SIP? Thank you very much in advance for your comments. George