Cisco Systems 4.2 Server User Manual


 
2-15
Configuration Guide for Cisco Secure ACS 4.2
OL-14390-02
Chapter 2 Deploy the Access Control Servers
Deploying ACS in a NAC/NAP Environment
Deploying ACS in a NAC/NAP Environment
You can deploy ACS in a Cisco Network Admission Control and Microsoft Network Access Protection
(NAC/NAP) environment. In the NAC/NAP environment, NAP client computers authorize with ACS by
using EAP over UDP (EoU) or EAP over 802.1x.
Table 2-1 describes the components of a NAC/NAP deployment.
When a NAP client connects, it uses a NAP agent to send ACS one of the following:
A list of SoHs.
A certificate that the client has received from a Microsoft Health Registration Authority (HRA).
The ACS host validates the client credentials. If the NAP agent sends a:
List of SoHs, the ACS sends the list to a Microsoft NPS by using the Cisco Host Credentials
Authorization Protocol (HCAP). The NPS evaluates the SoHs. The ACS then sends an appropriate
NAP to the network access device (switch, router, VPN, and so on) to grant the authorized level of
access to the client.
Health certificate rather than a list of SoHs, then ACS validates the certificate as the EAP-FAST
session is established to determine the overall health of the client. The ACS then sends the
appropriate NAP to the network to grant the authorized level of access to the client.
Ta b l e 2-1 Components of a NAC/NAP Deployment
Component Description
NAP client A computer running Windows Vista or Windows Server 2008. NAP
clients send their health credentials as Statements of Health (SoHs) or
as a health certificate.
NAP agent A process running on a NAP client that sends SoHs or health
certificates to ACS.
Network access devices Cisco devices through which you can access the network, such as
routers, switches, wireless access points, and VPN concentrators.
ACS Cisco AAA server product.
Network Policy Server (NPS) A Microsoft server that validates health certificates from NAP clients
and provides remediation instructions if needed.
Health Registration Authority A Microsoft certificate server that obtains health certificates on
behalf of NAP clients from a public key infrastructure (PKI).
Policy Servers Servers that provide current system health state for Microsoft NPSs.