84
Building a Network Access Control Solution with IBM Tivoli and Cisco Systems
Figure 4-3 Armando Banking Brothers network environment for NAC Appliance
When a user connects to the network controlled by NAC Appliance, the CAM is
advised of a linkup notification sent by the user’s switch. The CAM checks its
certified user list. If the MAC address is already present on the CAM as a
certified user, and the credentials supplied at login are authenticated by the
CAM, the user will be granted access to the network on their Access VLAN,
which in this case is VLAN 20. If the MAC address is not present, or the
credentials supplied are incorrect, the CAM will send an SNMP-write string to the
user’s switch, changing the switchport membership from VLAN 20 to VLAN 120.
The user’s IP address will remain the same, but he will be forced to go through
the CAS. The CAS checks policy compliance and remediation. Once the CAS
advises the CAM that the client is compliant, the CAM sends another
SNMP-write to the user’s switch, changing the switch membership from VLAN
120 back to VLAN 20. The user, now compliant, has access to the core network,
bypassing the CAS.
Summary of Contents for Tivoli and Cisco
Page 2: ......
Page 16: ...xiv Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 18: ...xvi Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 20: ...2 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 30: ...12 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 56: ...38 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 94: ...76 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 110: ...92 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 142: ...124 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 225: ...Chapter 6 Compliance subsystem implementation 207 Figure 6 77 Client connection window...
Page 456: ...438 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 458: ...440 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 504: ...486 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 513: ...Building a Network Access Control Solution with IBM Tivoli and Cisco Systems...
Page 514: ......
Page 515: ......