44-32
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 44 Configuring Network Admission Control
Configuring Network Admission Control with LAN Port IP
ip helper-address 10.76.39.93
!
ip classless
ip route 10.76.0.0 255.255.0.0 Vlan12
no ip http server
!
!
!
line con 0
line vty 0 4
login
!
!
end
LAN Port IP Enhancements in Software Release 8.6(1) and Later Releases
These sections describe the enhancements for configuring NAC with LAN port IP in software
release 8.6(1) and later releases:
•
Configuring URL Redirect Support for LAN Port IP Exception Hosts, page 44-32
•
Configuring LAN Port IP on Private VLAN Ports, page 44-34
Configuring URL Redirect Support for LAN Port IP Exception Hosts
Exception hosts (such as printers and IP phones) cannot validate posture. The IP/MAC addresses of the
exception hosts are added to an exception list. When a host in the exception list is detected on an
interface, a preconfigured policy is installed.
For normal, nonexception hosts, URL redirection is accomplished through information that is received
from the RADIUS server after a successful posture validation. Because the RADIUS server is not
contacted, exception hosts must find a way to access a server, or you must provide a URL through which
the hosts can download software components (such as antivirus updates).
Configuration Guidelines and Restrictions
Follow these configuration guidelines and restrictions when configuring URL redirect for LAN port IP
exception hosts:
•
URL redirection is not supported on multiple-host and multiple-authentication ports.
•
URL redirection works only if there is a VACL with ARP inspection and DHCP snooping mapped
on the VLAN of the port.
•
Because Supervisor Engine 1 does not support ARP inspection, URL redirection is not supported on
Supervisor Engine 1.
Specifying the Policy Name and URL Redirect String
The
set policy name
policy-name
url-redirect
url-redirect-string
command maps a URL redirect string
to a policy name. URL strings of up to 255 characters are allowed. If the URL string exceeds 255
characters, the command fails.
To specify the policy name and URL redirect string, perform this task in privileged mode: