Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

support for nac

Subject: support for nac
Date: Fri, 31 Mar 2006 17:10:14 -0600
hi, I have with the configuration in acs 4.0 for nac 2,

This is the conf in switch:

aaa new-model

aaa authentication login default group radius local

aaa authentication eou default group radius
aaa authorization auth-proxy default group radius

aaa accounting network default start-stop group radius
aaa accounting system default start-stop group radius
!
aaa session-id common

ip admission name nac eapoudp
ip admission name NAC-L2-IP eapoudp
ip admission name NAC-L2-IP-Bypass eapoudp bypass
ip admission name NAC-L3-IP eapoudp list EoU-ACL
!
ip dhcp snooping
ip device tracking
!
!
eou allow clientless
eou timeout hold-period 60
eou timeout status-query 60
eou timeout revalidation 60
eou logging

interface FastEthernet0/23
 switchport mode access
 ip access-group EoU-ACL in
 spanning-tree portfast
 ip admission NAC-L2-IP

ip access-list extended EoU-ACL
 permit udp any any eq 21862
 permit udp any eq bootpc any eq bootps
 permit udp any any eq domain
 permit icmp any any
 permit ip any host 10.0.0.6
 deny   ip any any

radius-server attribute 8 include-in-access-req
radius-server host 10.0.0.6 auth-port 1645 acct-port 1646 key cisco123
radius-server source-ports 1645-1646
radius-server vsa send authentication

But not happen nothing.... maybe problem with acs?

Juan Carlos Davila Ortiz
Networking Consultant
04433 3569 7294
jcdavila@xtreme-networks.com.mx
Móvil: 3335697294@rek2.com.mx

<Prev in Thread] Current Thread [Next in Thread>
  • support for nac, XTREME Juan Carlos Davila <=