Configuring Nac; Default Nac Configuration; Nac Layer 2 Ip Guidelines, Limitations, And Restrictions - Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents

Advertisement

Chapter 41
Configuring Network Admission Control
NAC Layer 2 IP Validation and RPR Redundancy
When RPR mode redundancy is configured, a switchover will lose all information regarding currently
postured hosts. When SSO mode redundancy is configured, a switchover will trigger a reposturing of all
currently postured hosts.
AAA Down Policy for NAC Layer 2 IP Validation
With the AAA down policy feature, the validation process operates in the following order:
1.
2.
3.
When the AAA server is down, the AAA down policy is applied only if there is no existing policy
Note
associated with the host. During revalidation when the AAA server goes down, the policies being used
for the host are retained.

Configuring NAC

This section contains this configuration information:

Default NAC Configuration

By default, NAC Layer 2 IP validation is disabled.

NAC Layer 2 IP Guidelines, Limitations, and Restrictions

When configuring NAC Layer 2 IP validation, follow these guidelines, limitations, and restrictions:
OL-11439-03
A new session is detected.
Before posture validation is triggered, and if the AAA server is unreachable, the AAA down policy
is applied and session state is maintained as AAA DOWN.
When the AAA server is once again available, a revalidation is retriggered for the host.
Default NAC Configuration, page 41-11
NAC Layer 2 IP Guidelines, Limitations, and Restrictions, page 41-11
Configuring NAC Layer 2 IP Validation, page 41-13
Configuring EAPoUDP, page 41-16
Configuring Identity Profiles and Policies, page 41-17
Configuring a NAC AAA Down Policy, page 41-17
You must configure Layer 3 routes from the switch to the host for the Layer 2 IP to operate correctly.
Layer 2 IP is not allowed if the parent VLAN of the port has VACL capture or Cisco IOS firewall
(CBAC) is configured.
LAN Port IP (LPIP) ARP traffic redirected to the CPU cannot be spanned using the SPAN feature.
NAC Layer 2 IP validation is not supported on trunk ports, tunnel ports, EtherChannel members, or
routed ports. The Catalyst 6500 series switches support Layer 2 IP on EtherChannels.
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
Configuring NAC
41-11

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents