
1-12
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Network Admission Control
Configuring a NAC Policy
Detailed Steps
Note
When the command specifies an operating system, it does not overwrite the previously added entry to
the exception list; enter the command once for each operating system and ACL you want to exempt.
Command
Purpose
Step 1
nac-policy-nac-framework
Switches to nac-policy-nac-framework
configuration mode.
Step 2
exempt-list os
"
os-name
" [
disable
|
filter
acl-name
[
disable
]
Example:
hostname(config-group-policy)#
exempt-list os
"Windows XP"
hostname(config-group-policy)
hostname(config-nac-policy-nac-framework)#
exempt-list os "Windows XP" filter acl-2
hostname(config-nac-policy-nac-framework)
hostname(config-nac-policy-nac-framework)#
no
exempt-list os "Windows XP" filter acl-2
hostname(config-nac-policy-nac-framework)
Adds an entry to the list of remote computer types
that are exempt from NAC posture validation.
•
os-name
is the operating system name. Use
quotation marks if the name includes a space
(for example, “Windows XP”).
•
filter
applies an ACL to filter the traffic if the
computer’s operating system matches the
os
name
. The
filter
/
acl-name
pair is optional.
•
disable
performs one of two functions, as
follows:
–
If you enter it after the "os-name," the ASA
ignores the exemption, and applies NAC
posture validation to the remote hosts that
are running that operating system.
–
If you enter it after the
acl-name
, ASA
exempts the operating system, but does not
apply the ACL to the associated traffic.
•
acl-name
is the name of the ACL present in the
ASA configuration. When specified, it must
follow the
filter
keyword.
Adds all hosts running Windows XP to the list of
computers that are exempt from posture validation.
Exempts all hosts running Windows XP and applies
the ACL acl-2 to traffic from those hosts
Removes the same entry from the exemption list.
Step 3
(Optional)
[
no
]
exempt-list os
"
os-name
" [
disable
|
filter
acl-name
[
disable
] ]
Example:
hostname(config-nac-policy-nac-framework)#
no
exempt-list
hostname(config-nac-policy-nac-framework)
Removes all exemptions from the NAC framework
policy. Specifying an entry when issuing the no form
of the command removes the entry from the
exemption list.
Removes all entries from the exemption list.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......