Cisco Cisco ASA 5585-X Adaptive Security Appliance 기술 매뉴얼

다운로드
페이지 34
NAC Appliance (Cisco Clean Access) In−Band
Virtual Gateway for Remote Access VPN
Configuration Example
Document ID: 71573
Contents
Introduction
 Prerequisites
      Requirements
      Components Used
      Network Diagram
      Conventions
NAC Appliance (Cisco Clean Access) Configuration
Cisco ASA Configuration
      ASA CLI Configuration
 Verify
 Troubleshoot
 Related Information
Introduction
This document provides a step−by−step guide on how to configure the Cisco Network Admission Control
(NAC) Appliance (formerly Cisco Clean Access) for remote access VPN in In−band Virtual Gateway mode.
The Cisco NAC Appliance is an easily deployed NAC product that uses the network infrastructure to enforce
security policy compliance on all devices that seek to access network computing resources. With the NAC
Appliance, network administrators can authenticate, authorize, evaluate, and remediate wired, wireless, and
remote users and their machines prior to network access. It identifies whether networked devices such as
laptops, IP phones, or game consoles are compliant with the security policies of your network and repairs any
vulnerabilities before access to the network is permitted.
Prerequisites
Requirements
There are no specific requirements for this document.
Components Used
The information in this document is based on these software and hardware versions:
Cisco Clean Access version 4.0.3
• 
Cisco Adaptive Security Appliance (ASA) version 7.2
• 
The information in this document was created from the devices in a specific lab environment. All of the
devices used in this document started with a cleared (default) configuration. If your network is live, make sure
that you understand the potential impact of any command.