33-3
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 33 Configuring Network Admission Control
Viewing the NAC Policies on the Security Appliance
default-acl acl-1
reval-period 36000
sq-period 300
exempt-list os "Windows XP" filter acl-2
hostname#
The first line of each NAC policy indicates its name and type (nac-framework).
Table 1
explains the
nac-framework attributes displayed in response to the
show running-config nac-policy
command.
To display the assignment of NAC policies to group policies, enter the following command in privileged
EXEC mode:
show nac-policy
In addition to listing the NAC policy-to-group policy assignments, the CLI shows which NAC policies
are unassigned and the usage count for each NAC policy, as follows:
asa2(config)#
show nac-policy
nac-policy framework1 nac-framework
applied session count = 0
applied group-policy count = 2
group-policy list: GroupPolicy2 GroupPolicy1
nac-policy framework2 nac-framework is not in use.
asa2(config)#
The CLI shows the text “is not in use” next to the policy type if the policy is not assigned to any group
policies. Otherwise, the CLI displays the policy name and type on the first line and the usage data for
the group policies in subsequent lines.
Table 2
explains the fields in the
show nac-policy
command.
Table 1
show running-config nac-policy Command Fields
Field
Description
default-acl
NAC default ACL applied before posture validation. Following
posture validation, the security appliance replaces the default ACL
with the one obtained from the Access Control Server for the remote
host. The security appliance retains the default ACL if posture
validation fails.
reval-period
Number of seconds between each successful posture validation in a
NAC Framework session.
sq-period
Number of seconds between each successful posture validation in a
NAC Framework session and the next query for changes in the host
posture
exempt-list
Operating system names that are exempt from posture validation.
Also shows an optional ACL to filter the traffic if the remote
computer’s operating system matches the name.
authentication-server-group
name of the of authentication server group to be used for NAC posture
validation.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......