33-4
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 33 Configuring Network Admission Control
Adding, Accessing, or Removing a NAC Policy
Refer to the following sections to create a NAC policy or modify one that is already present.
Adding, Accessing, or Removing a NAC Policy
Enter the following command in global configuration mode to add or modify a NAC policy:
[
no
]
nac-policy
nac-policy-name
nac-framework
Use the
no
version of the command to remove a NAC policy from the configuration. Alternatively, you
can enter the
clear configure nac-policy
command to remove all NAC policies from the configuration
except for those that are assigned to group policies. When entering the command to remove or prepare
to modify a NAC policy, you must specify both the name and type of the policy.
nac-policy-name
is the name of a new NAC policy or one that is already present. The name is a string of
up to 64 characters. The
show running-config nac-policy
command displays the name and
configuration of each NAC policy already present on the security appliance.
nac-framework
specifies that a NAC Framework configuration will provide a network access policy for
remote hosts. A Cisco Access Control Server must be present on the network to provide NAC Framework
services for the security appliance. When you specify this type, the prompt indicates you are in
nac-policy-nac-framework
configuration mode. This mode lets you configure the NAC Framework
policy.
You can create more than one NAC Framework policy, but you can assign no more than one to a group
policy.
For example, the following command creates and accesses a NAC Framework policy named
nac-framework1:
hostname(config)#
nac-policy nac-framework1 nac-framework
hostname(config-nac-policy-nac-framework)
Table 2
show nac-policy Command Fields
Field
Description
applied session count
Cumulative number of VPN sessions to which this security appliance
applied the NAC policy.
applied group-policy count
Cumulative number of group polices to which this security appliance
applied the NAC policy.
group-policy list
List of group policies to which this NAC policy is assigned. In this
case, the usage of a group policy does not determine whether it
appears in this list; if the NAC policy is assigned to a group policy in
the running configuration, then the group policy appears in this list.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......