NAC: A solution on a shoe-string ?

Hi,
I am trying to put forward a NAC solution for our <very> small office - around 30 users. I think NAC's a great solution to enforce a tight security policy, and I want to ensure users connecting to our Data Centre have been properly (de)wormed :)
I am therfore trying to justify "NAC" to my peers, BUT I will need to keep to an ultra tight budget. As far as I can see, the "minimum" NAC solution by Cisco compromises of the following four items :
1) NACMGR-3-K9: Cisco Clean Access Lite Manager for 3 servers
2) NME-NAC-K9: Cisco NAC Network Module for ISR
3) NACNM-50-K9: NAC Network Module Server License -max 50 users
4) NACMGR-3-K9: NAC Appliance 3310
Does this sound right ? Any ideas to reduce the overall cost of NAC would be appreciate. (the cost on this is around £12k which is not feasable for us)
can I slim this ? Help appreciated.
Thank you.
matt

Hi Matt,
You shouldn't need item number 4 - The NAC Manager Lite is an Appliance (CCA-MGR-LT-K9) and includes licensing, I'm not too familiar with the Network Modules & how the licensing works for them but that brings things to about $8,500 list.
HTH,
Denis

Similar Messages

  • My failed solutions to print a string. Some ideas, however...

    Dear,
    I do need to print some basic string out of a collection from Siena.
    Now, being the print task not supported, I thought on four solutions:
    1) launch the mail app with the string, then print the mail;
    2) generate a data-uri, then launch within the browser. But IE does not seem to support it and Siena won't launch anything without a protocol like HTTP or mailto;
    3) open the app in Visual Studio for Windows and add a print function in JS. But I didn't understand where the HTML is formed (Siena should be html+css+js) and where the element <button> is defined
    4) take a screenshot and print from the images gallery
    Now, the solution 1 and 4 are not really great... while 2) and 3) do not help me. Maybe the solution 3) would be doable.
    I am going to investigate Google Cloud Print (they have web services) or ePrint from HP (although they seem to allow Printing of attached files and not email body).
    But, however, seeing all the files of my project, having access to the code, could you address me where to change, for instance, the action of a button, just to change it to a function to print a string, later in VS?
    Or, simply, has anyone a workaround to print a string, or to open a browser with a in-Siena-created string as content (like data-uri should do)?
    Obviosuly I could write a PHP/ASP web service of my own, but I would like that the app does not require the internet connection to work.
    Thank you very much!
    Fabio

    I'm curious about this, too -
    In addition, I'm hoping to add a File Picker because I don't believe this is yet availabe in Siena.
    Thor

  • Disk Layout for a RAC deployment on a shoe string

    Hi, not sure if this is better placed under RAC or Linux group.
    I am planning a demo RAC system using 2 linux servers and due to stingy managers, the smallest budget ever imagined !
    I will have the 2 servers networked but am looking at a cheapo disk setup ( excluding virtualisation and SAN/NAS ). I currently have
    Server A and Server B
    Each has an Internal disk of 250 Gb – I am going to place the linux OS on here, the 11gR2 Oracle Grid Infrastructure Home and the 11gR2 Enterprise Edition Oracle Home
    Q1. Since the local server is where the Oracle Instance runs – would I be correct in assuming this is where the SPFILE for the instance goes as well i.e. Server A and B will both hold an SPFILE in the 11gR2 ORACLE_HOME ?
    Q2. What else should be stored on the local server – all the usual logs etc ( eg the instance alert log etc ) ? Is it normal to put a copy of the database control file on each local server ?
    My plan was to carve up the 250 Gb disk into a root partition ( for Linux ) and a /u01 partition for the Oracle Grid Infrastructure Home and the Database Oracle Home
    I was then going to use the remainder of the 250 Gb Disk in Server A as the shared disk ( for RAC ) between the Servers.  I am going to attempt to NFS mount the remainder of the 250 Gb disk on Server A ( disgusted I have no budget for NAS ! ), so Server B will have access to it.
    What I was not sure about is –
    Q3. in regards to ASM Disk Groups, I wasn’t sure if ASM can discover disk space for use, once it has been mounted as a standard file system ( or in my case as an NFS mount ) ?
    Q4. How does ASM interact with standard file system mounts ( if at all ) ?
    Q5. If a physical disk has some standard filesystems mounted on it, can ASM use / discover any remaining part of a disk that has not been configured as a filesystem ?
    Q6. I am assuming the FRA is better placed on the Shared Disk ( so both nodes have access to it ) ?
    Any guidance would be appreciated,
    Jim

    This won't be a RAC, Jim.
    What are you going to use as Interconnect? Do these machines have a 2nd physical NIC? You realise that crossover Ethernet cables are not supported. Is this Gigabit Ethernet? RAC Interconnect over a 10 or even 100 Mb/s  Ethernet, is significantly below par.
    Where are the OCR and Voting Disks going to reside?
    ASM is in my view, mandatory. It makes no sense not using ASM for RAC. ASM needs raw devices to use. It does not run on cooked file systems. NFS shares the latter.
    If NFS is used, over what IP layer is it going to run? The same as the Interconnect? Which would be  an irony as the the RAC db cache is now using the same transport layer as it does for physical I/O - both are over slow Ethernet vying for the same bandwidth.
    RAC is only as sound and as robust as the h/w it is build on. Stuff up with the hardware and you WILL have an inferior and unstable RAC. Accompanied with utter frustration as it will not work the way it should.
    IMO - the ONLY way one can build a 2 server RAC without a SAN or NAS, is with Firewire. Using a shared Firewire 800 disk that supports 2 separate servers at the same time. And then use this Firewire disk as shared storage. This is not supported by Oracle for production use - but past support notes did say that this is a config that can be considered for a dev type RAC. 
    If the 2 servers do not support Firewire 800, then 2 x Firewire 800 PCI cards (and cables) are needed, in addition to the Firewire drive.

  • NAC/AAA solution basic requirements?

    Experts,
    Network with almost 50-60 cisco devices (router/switches/fw). All the gear currently using local user authentication. Wondering what is the minimum required s/w to manage the gear thru ACS (TACACS) considering we have the server (primary/backup) hardware. Need to control network admins access to the gear thru ACS/basic password management/accounting etc. Nothing to do anything with regular user community.
    What would be the approx $ cost for this?
    Thanks in advance.
    MS

    Hi Gautam,
    The network in your design will still be operational if the MPLS link or router goes down. In other words, when traffic stops being directed to the CAS module in your 2811, end users will still be able to reach your network via the ISDN link.
    Hope this helps.
    Paul

  • Converting SQL Server text field containing XML string to XI XML via JDBC

    Hello
    My client has a SQL Server database containing a field of type Text which contains an XML string e.g.
    <DispatchJob> <DispatchDateTime>2003-09-29T13:29:15</DispatchDateTime> <AssignedFSE>F118</AssignedFSE> <DispatchJobPurchase> <DealerID>14C5</DealerID> <DateOfPurchase>1997-10-01T00:00:00</DateOfPurchase> </DispatchJob>
    I am using JDBC to access this but could someone please recommend the best and easiest solution for converting this string to XI XML for subsequent mapping to BAPI or IDOC or ABAP Proxy and transmission to SAP. There are other fields as well in the database table so thoughts at the moment are to use a normal graphical message mapping followed by an XSL mapping. Will an XSL mapping be able to do this and if so is that the best solution?
    Also I need to do the reverse of this and take fields coming from SAP via BAPI,IDOC etc. and convert them to a single database table field as an XML string also via the JDBC adapter. What is the best way to do this. Could it be done simply with functions in the graphical mapping e.g. concatenate?
    Thank you in advance.
    Trevor

    Hi Michal
    Thanks for the prompt reply.
    I was anticipating XSLT for reading from the SQL Server database and converting the XML string.
    But how would you convert the individual fields from SAP into a single field as an XML string for storing in the SQL Server database? What approach would you use?
    Regards
    Trevor

  • How to store multiline string literal in to java bean shell variable

    Hello Experts
    How to store multiline string literals in java bean shell like we use triple quote for jython variable
    Using Jython
    str=""" helllo
    welcome to my world"""
    above syntax is working but not for java bean shell like below
    String str=""" hello
    welcome to my world""";
    So how to do this in java bean shell. I came to this scenario while storing logs to a variable. I believe there is no solution for storing multiline strings to java bean shell variable.
    <@
    String str="<%=odiRef.getPrevStepLog("MESSAGE")%>";
    @>
    Any suggestion will be highly appreciated.
    Thank You.

    maddythehunk wrote:
    Im trying this but its not working...
    while(billingQueryParamsItr.hasNext()) {
         billingQueryParam = (BillingQueryParam) billingQueryParamsItr.next();
         System.out.println("****** Param Name-->"+billingQueryParam.getParamName());
         String[0] name = billingQueryParam.getParamName(); // giving error ; expected
         //billingItemActionForm.setParamName(billingQueryParam.getParamName());
    Declare the array outside of the loop. Fill the array as you iterate. And stop putting your error messages inside of comments in the code.

  • Remove Duplicates in a String

    I have a column that contains a list of users all pipe separated. I am writing a script to rebuild this field and need to find a way to remove any duplicate user entries that might be contained in the string. Can someone please help me with the sql to remove the duplicates from the string and update the field?
    Example:
    Table: REPORTCONFIG
    Column: EMAILNAMES
    'A.Anderson||B.Dawkins||D.Cowen||A.Anderson||J.Rowling'
    Also I have to include in my script a way to remove pipes that might be at the end of the string. If someone could help me on that front I would appreciate it as well.
    Edited by: 943224 on Jun 27, 2012 10:41 AM

    It looks like Tom's solution will convert one string. And it looks a little complicated:
    with data as
      ( select  token, rownum rn
          from  ( select  distinct
                          trim( substr (txt, instr (txt, ',', 1, level  ) + 1
                              , instr (txt, ',', 1, level+1)
                              - instr (txt, ',', 1, level) -1 )
                              )  as token
                    from  ( select  ',' || ltrim(rtrim('two,one,three,one,two,three,two,one,one,four',','),',') || ',' txt
                              from  dual
                          )   connect by level <= length(txt)-length(replace(txt,',',''))-1
    select  ltrim( max( sys_connect_by_path(token,',') ), ',' ) || ','  str
      from  data
    start with rn = 1
    connect by prior rn = rn-1 ;It would be nice to have it work on a whole table of data.
    I came up with this, but there's one thing I don't like. The "999" hard-coded in the query. It actually only needs to be bigger than the most entries in a string. I'm not sure how to calculate that value dynamically and still keep the query relatively simple.
    with smpl_data  as
      ( select  1 id, 'sam,rob,rob,joe,rob,sam'  as txt               from dual union all
        select  2   , 'two,one,three,one,two,three,two,one,one,four'  from dual union all
        select  3   , 'a,s,g,d,s,d,s,a,d,s,g,d,s,a,g,a,s,d,f'         from dual
    select  id
         ,  listagg(sngl_val, ', ') within group (order by sngl_val)  as no_dup_list
      from  ( select  distinct id,  lower(trim(regexp_substr( txt, '[^,]+', 1, seq )))  as sngl_val
                from  ( select  a.id,  b.seq,  a.txt
                          from  ( select id, txt, regexp_count(txt,',')+1 as n from smpl_data )  a
                          join  ( select level as seq from dual connect by level <= 999 )  b  on ( a.n >= b.seq )
    group  by  id
    order  by  id
    ;Edited by: SK1 on Jun 27, 2012 1:13 PM

  • String conversion to

    hi to every one
    my Q is :
    is there any function that convert the following string into number
    "$GPGGA,111659.148,3350.8959,N,07243.9143,E,1,03,3.4,39.4,M,-39.4,M,,0000*46"
    iam using Labview 8.5
    there is some funtion available that convert string to number but they does not convert charcter equivalent achii number
    they put 0 whenever string is containing character A to Z
    as in above sentence .. there is some character like
    $GPGGA N E etc ...i also need its achii code to fullfill my requirments
    i dont want to lose this ,as putting 0 instead of its achii equivalent ,
    THX in advance
    plz its very urgent iam waiting for any solution plzzzzzzzzz
    Solved!
    Go to Solution.

    Working with small strings I often parse them like this
    Message Edited by t06afre on 02-19-2009 10:22 AM
    Besides which, my opinion is that Express VIs Carthage must be destroyed deleted
    (Sorry no Labview "brag list" so far)
    Attachments:
    sample.PNG ‏15 KB

  • BareCode reader and insert String into actual selected JTextField

    Hi everyone,
    I can't invent anything appropriate about my concept. I would like to write a program for BareCode reading. I have working code witch gets a text string from reader which is connected over RS232. But I have to send this String to actual selected JTextField in other java program. I think to use clipboard to overcome this problem but I'm not sure if it's a good solution. Copy this String to clipboard and auto Paste... Any ideas ?
    Please help me!
    Many thanks for any advices :)

    Hmm... I missed that bit about having to poke it into
    another Java program. In that case I would
    look into modifying the other Java program instead of
    trying to write a separate program to deal with it.
    Otherwise you run into management issues like making
    sure the other program is running, and not minimized,
    and located at the right place on the screen, and has
    the JTextField in question in focus, and so on.In most cases, I would agree. But if his java program is header-less and just responds to the serial events and calls Robot.keyPress() and Robot.keyRelease() he will just be imitating the keyboard, which is exactly what most barcode readers can already do. And this would work in any program that can get keyboard input, no matter what the language was written in.
    We are currently doing this with a web-based application. The web page just has a text field and when they scan the barcode it submits the page. Of course the barcode reader we are using just imitates the keyboard, no mucking around converting serial data into keyboard events.
    I bet if the OP looks around he could find software that will already convert the barcode RS232 data into keyboard events.

  • Time String to Timestamp Conversion Problem

    Hi,
    I attempted to convert time string to timestamp but I failed. What is the wrong with it? I need a timestamp to create waveforms.
    Egemen
    Solved!
    Go to Solution.
    Attachments:
    Time String to Timestamp.png ‏18 KB

    You are right Gogineni, when I got the error, I was using %S in the format string for Format Date/Time String function and %3u in the format string for Scan From String.
    I found the solution in this thread - use %S%3u in both places.
    Help the forum when you get help. Click the "Solution?" icon on the reply that answers your
    question. Give "Kudos" to replies that help.

  • Match Certain word in a String

    Hi all,
    I'm actually doing a project regrading e-learning. And i'm suppose to create a set of questions for each topics using labview. So Is there any way that i can match certain word in the string to make sure that answer is correct? Cause i'm sure that every user that input answer will be different. Thus, I want to pick out main point as an answer. Is there anyway i can do it?? 
    Really appreciate your help!!! 
    Thank you!! 
    Solved!
    Go to Solution.
    Attachments:
    Match Strings.vi ‏8 KB
    Match Strings.vi ‏8 KB

    Here's another option (building on Jeff's code).  Turn on the Conditional Terminal on the FOR loop and change it to "Continue if TRUE".  This way, the loop will exit as soon as a failure is found.  Just pass the result straight out of the loop.  If none fail, then the FOR loop will exit on its own (from the auto-indexing) and a pass is passed out.
    There are only two ways to tell somebody thanks: Kudos and Marked Solutions
    Unofficial Forum Rules and Guidelines
    Attachments:
    Match String.png ‏19 KB

  • Save string/numeric value

    Hello!
    How can i do for save a value of a variable so i can use it in future? I have an output string from a case structure moved by an OK botton. I want to save the string value when i press the ok botton...
    Thanks in advance
    GM
    Solved!
    Go to Solution.

    Just write the string to a text file.  When you want to use it later, read the text file.
    There are only two ways to tell somebody thanks: Kudos and Marked Solutions
    Unofficial Forum Rules and Guidelines

  • CSV string to list of number for IN() statement

    Here is the problematic part of my function:
    <blockquote>cr.client_id in (to_number(:ClientId)</blockquote>
    I want my SQL*Plus function to handle a list of ClientIds supplied by the user, but if I enter "20006336, 27340036" I get the following error:
    <blockquote>ORA-01722: invalid number
    01722. 00000 - "invalid number"</blockquote>
    Seems like there should be an easy solution to conversting a string to a list of numbers...
    Running 10g. Also, the function works with &ClientId but I would prefer to keep it as a bind variable if possible (large query)
    Thanks for the help!
    Edited by: 791028 on Aug 26, 2010 8:58 AM

    Something like:
    SQL> ed
    Wrote file afiedt.buf
      1  select *
      2  from emp
      3  where ename in (
      4    with t as (select '&input_string' as txt from dual)
      5    select REGEXP_SUBSTR (txt, '[^,]+', 1, level)
      6    from t
      7    connect by level <= length(regexp_replace(txt,'[^,]*'))+1
      8*   )
    SQL> /
    Enter value for input_string: SCOTT,JAMES
    old   4:   with t as (select '&input_string' as txt from dual)
    new   4:   with t as (select 'SCOTT,JAMES' as txt from dual)
         EMPNO ENAME      JOB              MGR HIREDATE                   SAL       COMM     DEPTNO
          7788 SCOTT      ANALYST         7566 19-04-1987 00:00:00       3000                    20
          7900 JAMES      CLERK           7698 03-12-1981 00:00:00        950                    30
    SQL>

  • NAC agent-multiple antivirus version

    Hi,
    customer has two version of McAfee antivirus. What I need is - user get the same role when login to PC with version X or PC with version Y. Is it possible to create AV install rule with OR logic? Something like if on PC is installed version X OR version Y pass check and give user Role USER.
    Thanks for help.

    1] What are the different category checks that NAC can implement? (for example, anti-virus, operating system, registry check, …)
    Faisal: All of the above. It would take a good sized chapter to detail all you're asking for above in Q1, so I would therefore suggest a book for you to pick up and read. The title is "Cisco NAC Appliance: Enforcing Host Security with Clean Access (Paperback)" ISBN for this book is 1587053063.
    Also see the Video-On-Demand which explains all the requirement/rules etc. VODs are located here: http://tinyurl.com/d74t9u and you're looking for VOD 5
    2] Service/Warranty: how much is it to renew the software licenses after the warranty expires?
    Also, how much is it for the Yearly Subscription/maintenance of Licenses?
    Suppose if we didn't renew the service, will our NAC work without updates?
    Faisal: Your account team is the best resource for this. I don't know the pricing. NAC will continue to work without renewal of service - you just won't get support for it.
    3] Can we enforce updates using a PC placed in quarantine/inside/trusted area instead of using the internet (remediation server)?
    Faisal: Yes, you can have your internal remediation servers you can point your clients to.
    4] Application check of end point: does it check for Evaluation, trail, licensed, or un-licensed version of any application (for example, anti virus, OS, …)?
    Faisal: Yes to all. The rule/requirement capabilities of CCA are very flexible and you can get quite creative
    5] Let's say we configured the appliance to be VPN, thereafter is it possible to change it to wireless? If yes, how difficult it is?
    Faisal: Same CAS can work for both wireless and VPN. How difficult? Depends on your network. Your account team again would be the best resource to get you a design
    6] After implementing the NAC VPN solution in a single-sign-on, how much time delay will it add to authenticating a remote user? In other words, will there be a considerable delay?
    Faisal: Delay for authentication is minimal (two seconds to five seconds) If you client however needs rememdiation, that delay is separate.

  • How to qualify for NAC Framework?

    Hi, we have been considering NAC for a while and have evaluated NAC Appliance. However, we have a requirement to use 802.1x for posture validation, authentication etc. I have looked at cisco trust agent and there is a statement about needing to be 'approved' to deploy CTA? Any one have any ideas about how to go about this and to be able to deploy NAC framework? We feel framework fits our situation much better than appliance. Many thanks for your time.

    Exact statement would be
    "The Cisco Trust Agent is available for download only by customers approved to deploy the NAC Framework solution. If you are not approved, please contact your Cisco account team about Cisco NAC solutions. Deprecated versions of Cisco Trust Agent - CLITE client may be found at http://www.cisco.com/cgi-bin/tablebuild.pl/cta-deprecated "
    From the URL http://www.cisco.com/cgi-bin/tablebuild.pl/cta

Maybe you are looking for

  • Java 1.7.0.11 works just fine in IE, but, Firefox 18.0 tells me that java is not on my system

    Cannot get java 1.7.0.11 to be recognized in Firefox 18.0. Have completely wiped older versions of Java from system and installed latest several times and in addons get message that firefox has blocked older version of java and when I test in firefox

  • The account setted for depreciation don't be updated to TABLE 'T095B'

    Hi all,     When i runed TCODE 'AFAB', it show the error message as below: In area 01, acc. allocation is missing for account group 1050000 Message no. AA 719 Diagnosis Inconsistent account assignment rules for depreciation posting have been determin

  • Unidentifi​ed Subscriber and number not recognised voice message

    I have read a few theories on the above. I have one number that today started showing the red cross and unidentified subscriber message. Earlier I had called the number and it said "number not recognised" yet it was contactable previously. Very frust

  • DLSw - Backup Delay

    I have DLSw redundancy configured. My circuits often drop from the primary dlsw peer and connect to the backup. I assume it's missing a certain number of responses back from the primary peer. Is there a way to change the timers and cause the router t

  • Has anyone successfully installed Magic the Gathering Online?

    Well I recently got my second macbook (first one was declared dead due to Random Shutdowns) I tried to install MTGO after I installed bootcamp. But I could never get it to fully install. I keep having problems downloading all the files that were requ