NAC with dialup

Hi.
Has anyone set up NAC on IOS for dialup?
I am trying to authenticate users via PPP then do posture validation.
Have set up 3 profiles, trying to filter on aaa:service=ip-admission and service-type!=10
This works fine with ACS but not with IOS.
Any ideas would be appreciated

Hi Danielnunes,
Thank you for your suggestion.
@Faisal,
I need to configure severity instead of cisco rules but having performance issue. I did as per the blog but nothing happened. Could you please suggest me what should I do for better performance?
Thank you
Laxman

Similar Messages

  • Firefox browser is very slow, I delete history and Cache often, I like Firefox better than IE but need it faster as I am stuck with Dialup.

    I empty Cache and all recent history except passwords to get about 4kbs and at most I can get about 6.7kbs. Firefox is a lot better than IE but I am stuck with Dialup or a high price for DSL from our Local Telephone company. I have Windows Vista and IE9 and 7 as this is a 64 system so I have to download both 32 and 64 to run. Firefox is bright and clear. I see that instead of Java which is disabled for Firefox it uses Jagermonkey, I tried to find some info on this but couldn't. I downloaded Firefox7 just 2 weeks ago.

    Your Shockwave Flash is not current, do not install additional "crapware" which will likely be offered when installing an Adobe product
    :http://www.adobe.com/software/flash/about/
    :also check all plugins through the '''about:plugins''' link
    :to http://www.mozilla.com/plugincheck/
    There is little point is running the 64bit version of Firefox, it is really for testing.
    You can clear cache automatically when you shutdown Firefox (see image)
    * http://img232.imageshack.us/img232/4928/clearcachew.png
    :REM Clear your temporary internet files when Firefox is down with a .bat file
    :rem S Delete specified files from all subdirectories
    :rem Q Quiet mode, do not ask if ok to delete on global wildcard
    :rem F Force deletion of read only files
    :del C:\Users\'''''myuserid'''''\AppData\Local\Temp\*.* /s /q /f
    :del c:\"Documents and Settings\'''''myuserid'''''\Local Settings\Temp"\*.* /s /q
    Stop ghostly indexing, autoplay
    * http://dmcritchie.mvps.org/windows-7/win7.htm#ghosts
    Use "Adblock Plus" to block advertisements, etc consumes a lot of time/transmissions
    * Adblock Plus :: Add-ons for Firefox<br>https://addons.mozilla.org/firefox/addon/adblock-plus/
    * Adblock - MozillaZine Knowledge Base<br>http://kb.mozillazine.org/Adblock
    Install a "hosts" file as well, see link in the MozillaZine article above
    This seems to have helped, to early to tell, I ran all options individually of the add-on then uninstalled it, see
    : http://blog.bonardo.net/2011/09/30/is-your-firefor-freezing-at-regular-intervals
    I would install the second one will show if you got disconnected
    * Restartless Restart :: Add-ons for Firefox<br>https://addons.mozilla.org/firefox/addon/restartless-restart/
    * Work Offline :: Add-ons for Firefox<br>https://addons.mozilla.org/firefox/addon/work-offline/

  • NAC with Linux client

    Hi,
    I have some Linux clients. When they connects to the trusted network in the first time, they are redirected to NAC login page and are required to download java runtime. I set policies so that linux client can download java and install it, but after that, the web browers (firefox) on linux client still not allow NAC login page to be loaded.
    What is the root cause in this case ?
    Any guy can help me!
    Best regards,
    NamNT

    Folks, the problem is due to the fact that there are no web agents available for linux at this time. You need to create a new user page for linux with all java options disabled ( such as the one for mac address checking , ip address refresh etc ) . Make this user page on the top of the list. Also, under clean access requirements, make sure 'require use of web agent' is disabled for linux. This way, there will be web redirection and authentication only for linux clients ( no posture possible for linux ).
    Thanks,
    Mani

  • NAC with OOB and Wireless 802.1x

    Had Anybody any experience with
    integration NAC OOB and 802.1x?
    I have seen that there are some issues about it.

    Working pretty well.
    Check this out:
    http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a138cc.shtml

  • Updating system with dialup

    Since I am on 26.4 kbs dialup and the first time I tried Su my dialup died and I had to try again, but was locked out. So then I tried pacman -U on one file at a time I started with db-4.6.21-, this went fine but when it finished and updated the system I lost wvdial so no modem. I used the boot disk and copied the db4.5 over and got my modem back. But now I am leary and do not know if there is a certain order to update so as not to cause conflicts with the current system till everything is downloaded. Trying to download over 850MB will take me over 2 weeks to do so I must be careful or I will be right back to the beginning again. Any Ideas as to the order of the files or is there a way to download parts of packets and combine them ?? Thanks

    I successfully ran Arch on dialup for a couple years. I'm not certain what problem you have exactly, but here's some tips:
    * pacman -Suw will download all the packages without installing them. pacman -Sw packagename will download a specific package without installing it
    * pacman supports download resume, so if your connection crashes you should be able to start over where you left off.
            - if this doesn't work: try a different mirror OR try using wget as your downloader
    * trickle is a neat program that allows you to limit pacman to 1k per second so it runs in the background while you browse. This still takes up a 3rd of your bandwidth, but it does allow you to be semi functional.
    Dusty

  • AirPort Extreme with dialup

    Just purchased a new 17" iMac core duo and a Airport Extreme base station that had a modem port on it. I'm new to this wireless thing and cannot get it to connect via the 56k modem that's suppost to be in the Airport. I was told at the Apple store that it was what I needed to still use my dialup connection.
    I get a message that says I'm connected to the network via the ethernet but, I'm still not on the internet. The only place I see where I can put in a phone for my ISP is on the Bluetooth pref but that doesn't get me there either. Thanks if anyone has the answer.
    Barry

    Thanks Charles,
    Found that and also found I had some wrong info in the set up.
    Now to get my 333 mhz Lombard to working with Belkin Wireless notebook card to get on the internet with it and both computers talking to each other. I had bought it at the Apple Store the same time I bought the iMac and AirPort and the salesman said it would work.
    It says the base station is not availiable.
    I noticed that in the Internet connect on the new iMac, it had a 802.1X botton at the top and on the PowerBook after I installed the the Airport software it didn't have the 802.1X button at the top of the internet connect.
    The instructions that came with the card says to install the latest AirPort software and I did install the software that came with the base staton. The software that came with the card is only good for Windows.
    Thanks again for your help,
    Barry

  • Cisco NAC with VPN Concentrators

    Looking at the deployment guidelines for NAC integration with VPN Concentrators:
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/412/cas/s_vpncon.html
    Is it possible to define traffic which is exempt from NAC enforcement, for example traffic associated for LAN-to-LAN VPNs?

    NAC enforcements do not work for traffic types. Following links may help you
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/412/cam/m_addSrv.html
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_cca.html

  • Installing Nano and iTunes with dialup - how long should it take?

    I got a nano for Christmas and am just now trying to use it. When I try to download iTunes it says that it will take upwards of 5 hours! I have dialup, living in a rural area, so I know it'll take longer, but can this be right? Also, when I download iTunes, what will happen to the music I have in Windows Media Player? Sorry, but I ma very new to iTunes & Nano!

    It depends on a number of things?
    1 - the amount of RAM installed.
    2 - amount of free space on the boot drive. It's strongly recommended to have a minimum of 20-25 GB free space.
    3 - the total playing time of the DVD.
    4 - the encoding process selected.  Professional Quality is a 2 pass process so will take more time than any of the other options.
    5 - CPU speed of your Mac.
    6 - if you're using a SL or DL disk.
    Follow this workflow to help assure the best qualty video DVD:
    Once you have the project as you want it save it as a disk image via the File ➙ Save as Disk Image  menu option. This will separate the encoding process from the burn process.
    To check the encoding mount the disk image, launch DVD Player and play it.  If it plays OK with DVD Player the encoding is good.
    Then burn to disk with Disk Utility or Toast at the slowest speed available (2x-4x) to assure the best burn quality.  Always use top quality media:  Verbatim, Maxell or Taiyo Yuden DVD-R are the most recommended in these forums.

  • NAC with NON-cisco wireless

    Hi there,
    I know that with WLC 5.1 and NAC 4.5 Cisco started to support OOB, NAC implementation. Now here is my question:
    A customer has CISCO environment except for the wireless which is another vendor. What are the options to bring wireless traffic into NAC server? Is OOB deployment possible?
    Thanks,
    rdianat

    So what is the solution for this scenario?
    remote site has non-cisco autonomous wireless AP. NAC is centralized. I can not use OOB since there is no support for non-cisco AP in OOB mode. As a result I use InBand mode. This means that local wireless trffic in remote site must travel to central site, go through NAC Server and go back to remote site. Is this correct?

  • Can firefox be used with dialup

    I would like to use firefox as my dialup instead of AOL cause of the problems that I have using AOL. Is that possible and if so how do I do that?

    I recall a few years ago having minor problems but being able to use a standard browser to connect to AOL, however AOL was designed as a portal using their own flavour of IE, and I imagine you may at least loose some features if you try connecting with firefox.
    I am sure the subject is covered in depth, if not on this forum then somewhere else.

  • NAC with CA

    Is it necessary to use the CA with NAC.
    if we donot use it what is the impact on the users.
    Can we deply without CA without any problems

    Talha,
    Yes, it's possible to deploy NAC without CA. You can use the self-signed certs, or get a cert from a third party vendor (Verisign or Godaddy etc)
    HTH,
    Faisal

  • NAC with security rtr

    hello
    we want to implement a NAC solution for people dialing from home to HO then going to internet via our internet router.
    this router contains the security feature and is NAC enabled (we can see this from web interface)
    however, one cisco partner suggests to use clean access server and not the security router.
    is there any advantage of using clean access servers or limitation for security rtr.
    note: we only need to check for windows updates and antivirus updates when computers access internet

    Well, both NAC Framework (NAC on your router) and NAC Appliance (Clean Access Server) will work. You can dial via PSTN/ISDN or via VPN using Cisco VPN Client. Also, you can purchase NME-NAC-K9 module for your router and it will work like Clean Access Server.
    To use NAC Framework you'll also need Cisco Secure Access Control Server (CS ACS) 4.0+ (4.1). This is commercial RADIUS server and isn't cheap.
    Also, to check for antivirus updates your antivirus product must be supported by either NAC Framework or Appliance. For a list of supported products take a look at:
    http://www.cisco.com/go/nac
    http://www.cisco.com/web/partners/pr46/nac/partners.html (NAC Framework)
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/416/416rn.html (NAC Appliance)
    For NAC Framework you'll need to integrate vendor .dlls into the Cisco Trust Agent (for all of your antivirus vendors!), then distribute CTA to all user PCs using some out-of-band mechanism (not an easy task). CTA is a must for NAC Framework.
    NAC Appliance automates this. This is a self-contained product (no .dlls). Clean Access Agent can check supported antivirus products by itself. It can be installed onto PCs via some out-of-band mechanism or downloaded from the Web Login page. Also, Java / ActiveX agent is supported and can check your PC for compliance as well.
    Checking for Service Pack number isn't
    difficult in both products. However, to check for Windows Hotfixes you'll have to create complex rules in NAC Framework. When a new hotfix is released by Microsoft you'll have to change your rules manually (not easy). NAC Appliance automates this. It can download rules from the Cisco website. But you'll have to buy tech support for this.
    In general, configuring and maintaining NAC Framework is not an easy task. However, you can buy additional products, integrate them into the Framework and they will automate many things for you. This is not cheap and easy. NAC Appliance is self-contained. You'll not need anything else.
    HTH

  • NAC with Wireless LAN controller

    There are 10 VLANs coming out of wireless controller (trunk to L2 Switch).
    How do we implement NAC so that clients are forced to go to NAC instead of the L3 gateway?
    Thanks!
    Prasanna

    The CAS configurtaion guide will provide you more data related to your queries.Try configuring CAS which will resolve the issue.
    Refer the Clean Access Manager Installation and Configuration Guide present in the following url:
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/413_cam_book.html
    Refer the Clean Access Server Installation and Configuration Guide present in the following url:
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cas/413_cas.html

  • NAC with 6509

    Hi All,
    I've setup mac-notif on 6509 chassis, but it doesn't send mac-notif to the NAC. in agent, I got:
    "OOB Error; connected device MAC not found".
    here is config of 6509:
    snmp-server community privatecw121! RW
    snmp-server community publiccw121! RO
    snmp-server trap-source Vlan5
    snmp-server enable traps snmp linkdown
    snmp-server enable traps MAC-Notification move threshold
    snmp-server host 192.168.12.250 publiccw121!
    any suggestion would be appreciated. it's kind of urgent.
    thanks
    Alex

    thanks Faisal,
    finally i have someone to connect to console port and fixed it.
    I notice when I add static route to CAS through GUI, then run the command "route" in CAS, it doesn't show that static route. is it normal? do I need to enter static route through CLI instead of GUI?
    thanks alot
    Alex

  • NAC with EV SSL certs

    Does anyone know if the NAC appliance supports EV SSL certs; especially version v4.7.x.
    Any insight into older versions (4.1.3 and higher) for compatibility would be appreciated. Thanks!
    ben

    Hello! The higher key length is a problem on an older version (4.1.3), not 4.7.x; etc where you can specify it. 4.1.3 you cannot specify it and it's not strong enough.
    Ben

Maybe you are looking for

  • Cannot work on more than one page and menu shifting problems

    I downloaded Muse CC 2014 when it first came out, and now I find myself no longer able to edit more than one page without having to completely shut down the application and start it again. Here's what happens: I open a page to edit, and then anything

  • DVD to hard drive? and then to... iPod?

    I'm pretty new to a lot. I know it's possible I'm just not certain if I need to buy applications to convert the forat or anything But, I'm trying to get a movie from a DVD to my computers hard drive and then from the hard drive to my 5th gen iPod. An

  • "unable to send or receive files"   .... PLEASE HELP!!

    i put in a cd and copy the songs on it to my library. they take a minute or two to download. then i try to autofill my ipod shuffle, and i keep getting the message that it is "unable to send or receive files" what do i do??? please help me!!!

  • Who can explain me why my credit card is rejected  ?

    I have just changed my IPhone 3GS for a 4S. And now, my credit card (in force for a few months remaining) is rejected, Apple store telling me that my credit card is nor valid in France (Visa) , nor my number ....... although I can buy everything evew

  • Premiere pro and after effects linked comp saving ?????

    hi guys ive still not sorted this issue out, im thinking its a simple fix but i just cant get it right . im using cs 5.5 . i work on a project in premiere pro and do a right click on the footage , then select , replace with after effects composition.