Nac Exception List; Add Or Edit An Exception List Entry - Cisco ROUTER-SDM-CD User Manual

User guide
Table of Contents

Advertisement

Chapter 30
Network Admission Control

NAC Exception List

IP Address/MAC Address/Device Type, Address/Device, and Policy Columns
Add, Edit, and Delete Buttons

Add or Edit an Exception List Entry

OL-4015-12
policies on the NAC policy server, and then reconfigure NAC on the router to
use Strict Validation, by changing the ACL applied to the interface to
deny ip any any using the Cisco SDM Firewall Policy feature.
You can identify hosts that must be allowed to bypass the NAC validation process.
Typically, hosts such as printers, IP phones, and hosts without NAC posture agent
software installed are added to the exception list.
If there are hosts without static addresses on your network it is recommended that
they be entered in the agentless host policy, and not in the NAC exception list. The
NAC exception policy may not work properly if host IP addresses change.
If you are using the NAC wizard and you do not need to configure a NAC
exception list, you can click Next without entering information in this window.
As an alternative or as a complement to the NAC exception list, the wizard allows
you to configure an agentless host policy in another window.
These columns contain information about a host in the exception list. A host can
be identified by its IP address, MAC address, or the type of device it is. If it is
identified by an address, the IP address or MAC address is shown in the row along
with the name of the policy that governs the host access to the network.
Build the exception list by clicking Add and entering information about a host.
You can use the Add button as many times as you need to.
Choose a row and click Edit to change information about a host. Click Delete to
remove information about a host from this window. The Edit and Delete buttons
are disabled when there is no information in this list.
Add or edit the information in an exception list entry in this window.
Cisco Router and Security Device Manager 2.5 User's Guide
Create NAC Tab
30-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Router and security device manager 2.5

Table of Contents