Cisco Cisco IOS Software Release 12.4(6)T

Seite von 18
Network Admission Control: Agentless Host Support
  Prerequisites for Network Admission Control: Agentless Host Support
2
Cisco IOS Security Configuration Guide
Prerequisites for Network Admission Control:
Agentless Host Support
You must be running Cisco IOS Release 12.4(6)T or a later release.
You must be using a Cisco access control server (ACS) version 4.0 or a later version.
You must have a Cisco or third-party audit server setup.
Information About Network Admission Control:
Agentless Host Support
To configure the Network Admission Control: Agentless Host Support feature, you should understand 
the following concepts:
Network Admission Control
The Cisco Network Admission Control functionality enables the credentials of the endpoint device to be 
checked for compliance with the security policy before the device is granted access to network resources. 
This checking requires a security application called Cisco Trust Agent (CTA) to be installed on end 
devices that gather security state information and communicate it to access servers where policy 
decisions are made and eventually enforced on Cisco network access devices (such as routers and 
switches).
Agentless Hosts
End devices that do not run CTA cannot provide credentials when challenged by network access devices 
(NADs). Such hosts are termed “agentless” or “nonresponsive.” In the Phase l release of Network 
Admission Control, agentless hosts were supported by either a static configuration using exception lists 
(an identity profile) or by using “clientless” username and password authentication on an ACS. These 
methods are restrictive and do not convey any specific information about the host while making policy 
decisions.