Cisco Systems OL-16066-01 Network Router User Manual


 
Appendix K Router Platform User Interface Reference
Network Admission Control Policy Page
K-184
User Guide for Cisco Security Manager 3.2
OL-16066-01
Navigation Path
Go to the Network Admission Control Policy Page, page K-183, then click the
Setup tab.
Related Topics
Defining NAC Setup Parameters, page 15-138
Network Admission Control Page—Interfaces Tab, page K-186
Network Admission Control Page—Identities Tab, page K-189
Understanding AAA Server Group Objects, page 9-15
Field Reference
Table K-80 Network Admission Control Setup Tab
Element Description
AAA Server Group The AAA server group used for NAC authentication. You must select a
server group consisting of Cisco Secure Access Control Server (ACS)
devices running the RADIUS protocol. Enter the name of a AAA server
group object, or click Select to display an Object Selectors, page F-593.
If the AAA server group you want is not listed, click the Create button in the
selector to display the AAA Server Group Dialog Box, page F-12. From here
you can define a AAA server group object.
Note Each AAA server in the selected group must be configured to
communicate with an interface that exists on the router; otherwise,
validation fails.
Backup AAA Server
Group 1
The backup AAA server group in case the AAA servers in the main group
are down.
Backup AAA Server
Group 2
The secondary backup AAA server group in case the AAA servers in the
main group and the first backup group are down.
EAP over UDP (EoU) settings
Allow IP Station ID When selected, enables an IP address to be included in the calling-station-id
field of RADIUS requests sent to the ACS.
When deselected, IP addresses are not included in the calling-station-id field
of RADIUS requests sent to the ACS.