Changing Advanced Settings - Cisco FirePOWER ASA 5500 series Configuration Manual

Security appliance command line
Hide thumbs Also See for FirePOWER ASA 5500 series:
Table of Contents

Advertisement

Chapter 33
Configuring Network Admission Control
For example, enter the following command to remove the entry with Windows 98 and acl-1 from the
exemption list, regardless of whether it is disabled:
hostname(config-group-policy)# no vpn-nac-exempt os "Windows 98" filter acl-1
hostname(config-group-policy)
To remove all entries from the exemption list associated with this group policy and inherit the list from
the default group policy, enter the following command without specifying additional keywords:
For example:
hostname(config-group-policy)# no vpn-nac-exempt
hostname(config-group-policy)

Changing Advanced Settings

The security appliance provides default settings for NAC. Use the instructions in this section to adjust
these settings for adherence to the policies in force in your network.
Changing Clientless Authentication Settings
NAC support for clientless authentication is configurable. It applies to hosts that do not have a posture
agent, such as the Cisco Trust Agent. The security appliance applies the default access policy, sends the
EAP over UDP request for posture validation, and the request times out. If the security appliance is not
configured to request a policy for clientless hosts from the Access Control Server, it retains the default
access policy already in use for the clientless host. If the security appliance is configured to request a
policy for clientless hosts from the Access Control Server, it does so and the Access Control Server
downloads the access policy to be enforced by the security appliance.
Enabling and Disabling Clientless Authentication
Enter the following command in global configuration mode to enable clientless authentication:
For example:
hostname(config)# eou allow clientless
hostname(config)#
The eou clientless command is meaningful only if NAC is enabled.
Note
Clientless authentication is enabled by default.
Enter the following command in global configuration mode to disable clientless authentication:
OL-10088-01
no vpn-nac-exempt
eou allow clientless
no eou allow clientless
Cisco Security Appliance Command Line Configuration Guide
Changing Advanced Settings
33-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Pix 500 seriesCisco asa 5500 series

Table of Contents