1-10
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Network Admission Control
Configuring a NAC Policy
Detailed Steps
Setting the Revalidation Timer
After each successful posture validation, the ASA starts a revalidation timer. The expiration of this timer
triggers the next unconditional posture validation. The ASA maintains the current access policy during
revalidation.
By default, the interval between each successful posture validation is 36000 seconds (10 hours). To
change it, enter the following command in nac-policy-nac-framework configuration mode:
Detailed Steps
Configuring the Default ACL for NAC
Each group policy points to a default ACL to be applied to hosts that match the policy and are eligible
for NAC. The ASA applies the NAC default ACL before posture validation. Following posture
validation, the ASA replaces the default ACL with the one obtained from the Access Control Server for
the remote host. The ASA retains the default ACL if posture validation fails.
The ASA also applies the NAC default ACL if clientless authentication is enabled (which is the default
setting).
Command
Purpose
Step 1
nac-policy-nac-framework
Switches to nac-policy-nac-framework
configuration mode.
Step 2
sq-period seconds
Example:
hostname(config-group-policy)#
sq-period 1800
hostname(config-group-policy)
Changes the status query interval.
seconds
must be in the range 30 to 1800 seconds (5
to 30 minutes).
Changes the query timer to 1800 seconds.
Step 3
(Optional)
[
no
]
sq-period
seconds
Turns off the status query timer.
Step 4
show running-config nac-policy
Displays a 0 next to the sq-period attribute, meaning
the timer is turned off.
Command
Purpose
Step 1
nac-policy-nac-framework
Switches to nac-policy-nac-framework.
Step 2
reval-period
seconds
Example:
hostname(config-nac-policy-nac-framework)#
reval-period 86400
hostname(config-nac-policy-nac-framework)
Changes the interval between each successful
posture validation.
seconds
must be in the range is 300 to 86400
seconds (5 minutes to 24 hours).
Step 3
(Optional)
[
no
]
reval-period
seconds
Turns off the status query timer.
Step 4
show running-config nac-policy
Displays a 0 next to the sq-period attribute, which
means the timer is turned off.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......