33-9
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 33 Configuring Network Admission Control
Changing Global NAC Framework Settings
Enabling and Disabling Clientless Authentication
Enter the following command in global configuration mode to enable clientless authentication for a NAC
Framework configuration:
[no] eou allow {audit | clientless | none}
audit
uses an audit server to perform clientless authentication.
clientless
uses a Cisco Access Control Server to perform clientless authentication.
no
removes the command from the configuration.
none
disables clientless authentication.
The default configuration contains the
eou allow clientless
configuration.
Note
The
eou
commands apply
only
to NAC Framework sessions.
Clientless authentication is enabled by default.
The following example shows how to configure the security appliance to use an audit server to perform
clientless authentication:
hostname(config)#
eou allow audit
hostname(config)#
The following example shows how to disable the use of an audit server:
hostname(config)#
no eou allow audit
hostname(config)#
Changing the Login Credentials Used for Clientless Authentication
When clientless authentication is enabled, and the security appliance fails to receive a response to a
validation request from the remote host, it sends a clientless authentication request on behalf of the
remote host to the Access Control Server. The request includes the login credentials that match those
configured for clientless authentication on the Access Control Server. The default username and
password for clientless authentication on the security appliance matches the default username and
password on the Access Control Server; the default username and password are both “clientless”. If you
change these values on the Access Control Server, you must also do so on the security appliance.
Enter the following command in global configuration mode to change the username used for clientless
authentication:
eou clientless username
username
username
must match the username configured on the Access Control Server to support clientless hosts.
Enter 1 to 64 ASCII characters, excluding leading and trailing spaces, pound signs (#), question marks
(?), quotation marks ("), asterisks (*), and angle brackets (< and >).
Enter the following command in global configuration mode to change the password used for clientless
authentication:
eou clientless password
password
password
must match the password configured on the Access Control Server to support clientless hosts.
Enter 4 – 32 ASCII characters.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......