CANAC - Implementing NAC Appliance (formerly Cisco Clean Access)

Length Price Cisco Learning Credits
4 days $3,095.00 31

In this course, you'll learn how to design and implement a Cisco NAC Appliance solution to suit your network. You will learn basic configuration tasks such as NAM and NAS deployment modes, authentication (including Windows SSO), role-based access control, posture assessment, and remediation.

Is this NAC course right for you?

Cisco Systems offers two solutions for Network Admissions Control: NAC Appliance and NAC Framework. If the NAC solution you are planning includes the following elements, then this NAC Appliance course, CANAC v2.1, is right for you:

  • NAC Appliance Manager (NAM)
  • NAC Appliance Server (NAS)
  • Cisco Catalyst Switches using Out-of-Band (OOB) access
  • Cisco VPN Concentrators (without configuring NAC commands)
  • Cisco ASA/PIX Firewalls (without configuring NAC commands)

Prerequisites

  • Fundamental knowledge of implementing network security or CCSP or Cisco Security Qualified Specialist Certification
  • SNRS or working knowledge of digital certificates
  • BSCI or working knowledge of HSRP

What You'll Learn

  • Given client network security requirements, explain how a NAC Appliance deployment scenario will meet or exceed those expectations
  • Configure the common elements of a NAC Appliance solution
  • Configure Active Directory Single Sign-On (AD SSO)
  • Configure VPN Single Sign-On using an ASA with the standard IPSec client and the AnyConnect client (SSL)
  • Configure the NAC Appliance in-band and out-of-band implementation options
  • Implement the NAM and NAS High Availability to protect against downtime
  • Configure Network Scanning to audit clients and clientless hosts
  • Configure compliance checking using manual and automated settings in version 4.5 of code
  • Learn the elements of Code Signing applications needed for remediation
  • Create custom web page portals based on the location of clients
  • Allow Active Directory LDAP Authorization to map AD groups to NAC Appliance Roles
  • Walk through and configure three different network topologies, In-Band, VPN In-Band and OOB
  • Visually see for yourself the privilege rights needed for installation of the Cisco NAC Appliance Agent (NAA) and Stub Installer and how the two differ
  • Learn to monitor, maintain, and troubleshoot a NAC solution

Who Needs to Attend

  • Anyone responsible for the design, implementation, or support of a Cisco NAC Appliance installation and Cisco Channel Partners preparing for CCSP and NAC Specialist certification.

Course Outline

The Cisco NAC Appliance Solution

1. Cisco Self-Defending Networks

  • The Changing Landscape of Security
  • The Cisco Host-Protection Strategy
  • The Cisco SDN Initiative
  • Trust & Identity
  • Cisco NAC Products

2. Cisco NAC Appliance

  • Cisco NAC Appliance Solution
  • Cisco NAC Appliance Features
  • Cisco NAC Appliance Components
  • Compliance Scenarios
  • Deployment Options
  • Configuration Overview
  • User Interface

3. Cisco NAC Appliance Deployment Options

  • Cisco NAC Appliance Out-of-Band (OOB) Deployment
  • Cisco NAC Appliance In-Band Deployment
  • Compare Cisco NAC Appliance Deployment Options
  • Cisco NAS Operating Modes
  • Virtual Gateway vs. Real-IP Gateway
  • Layer 2 vs. Layer 3

4. Configure User Roles

  • What is a User Role?
  • Create User Roles
  • Define Traffic Policies for User Roles
  • Configure Traffic Policies for User Roles
  • Create Local User Accounts

5. Configure External Authentication

  • Configure External Authentication Providers
  • Authenticate Cisco NAC Appliance Users with Kerberos
  • Authenticate Cisco NAC Appliance Users with RADIUS
  • Authenticate Cisco NAC Appliance Users with LDAP
  • Authenticate Cisco NAC Appliance Users with NT Domain
  • Map Users to User Roles
  • Test User Authentication
  • Configure RADIUS Accounting for Users
  • Adding Custom RADIUS Attributes

6. Configure DHCP

  • Cisco NAS DHCP Modes
  • Enable the DHCP Module
  • Configure IP Ranges (IP Address Pools)
  • Work with Subnets
  • Reserve IP Addresses
  • Configure User-Specified DHCP Options

NAC Appliance Implementation

7. Implement Cisco NAC Appliance In-Band Deployment

  • In-Band Process Flow
  • In-Band Deployment Configurations
  • Configure the Cisco NAS for In-Band Deployment
  • Add the Cisco NAS to the Managed Domain
  • Configure the Cisco NAS Interfaces
  • Add Managed Subnets
  • Configure Cisco NAS VLAN Settings

8. Implement Windows Active Directory Single Sign-On (AD SSO)

  • Kerberos Ticket Exchange
  • Confirming a NAS Ticket
  • Communications between the NAS and Active Directory
  • AD SSO Configuration Checklist
  • TCP & UDP Ports Required for AD SSO
  • Configure the NAS for AD SSO
  • Install Support Tools for Windows 2000 or 2003 Server
  • Configure the Domain Controller with ktpass.exe

9. Implement Virtual Private Network Single Sign-On (VPN SSO)

  • Configuration Checklist
  • Configure a Traffic Filter
  • Add VPN Authentication Server to NAM
  • Map VPN Users to Roles on NAM
  • Enable VPN SSO on the NAS
  • Adding a VPN Device to the NAS
  • Configure RADIUS Accounting
  • Configure the VPN Gateway as a Floating Device
  • Test VPN SSO

10. Implement Cisco NAC Appliance Out-of-Band Deployment

  • OOB Process Flow
  • OOB Deployment Considerations
  • Layer 2 Central & Edge Deployment
  • Layer 3 Virtual Gateway & Real-IP Gateway
  • Layer 2 & 3 Clientless Host Options
  • Differences between Cisco NAC Appliance OOB Setup and In-Band Setup
  • Implement Cisco NAS OOB Operating Modes

11. Manage Switches

  • Implement Switch Management
  • Configure the Network for OOB Deployment
  • Configure Group, Switch, and Port Profiles
  • Configure Port Profiles Adding Switches to the Managed Domain
  • Configuring SNMP Advanced Settings
  • Configure Switch Ports to Use Port Profiles
  • Manage Switch Configuration Settings

NAC Appliance Implementation Options

12. Implement Cisco NAC Appliance on a Network

  • Implement Cisco NAC Appliance
  • General Setup Tab
  • User Pages
  • Configure Cisco NAA Support
  • Manage Certified Devices
  • Device Exemption
  • Viewing User Reports

13. Implement Network Scanning

  • Configure the Quarantine Role
  • Implement Nessus Plug-Ins
  • Test a Scanning Configuration
  • Customize the User Agreement Page
  • View Scan Reports

14. Configure the NAM to Implement Cisco NAC Appliance Agent on User Devices

  • Configure the Cisco NAM to Implement the Cisco NAC Appliance Agent (NAA)
  • Retrieve Updates
  • Require the Use of the Cisco NAA
  • Configure the Cisco NAA Temporary Role
  • Introduce Checks, Rules, and Requirements
  • Create a Check, Rules, and Requirements
  • Map Requirements to Rules and Roles

15. Configure NAM High Availability (HA)

  • Introduce HA for Cisco NAMs
  • Establish a Serial Connection Between Managers
  • Digital Certificate Requirements
  • Configure the Primary Cisco NAM
  • Configure the Standby Cisco NAM

16. Configure Cisco NAC Appliance Server (NAS) HA

  • Introduce HA for NASs
  • Implementation Considerations
  • Digital Certificate Requirements
  • Configure the Primary and Standby NAS
  • Complete the Standby NAS HA Configuration
  • Test the NAS HA Configuration
  • Configure DHCP Failover

NAC Appliance Monitoring and Administration

17. Monitor a Cisco NAC Appliance Deployment

  • Cisco NAC Appliance Monitoring
  • Monitor Online Users
  • Monitor NAS Health Event Logs
  • Configure Basic SNMP Support
  • Configure Syslog Support

18. Administer Cisco NAM

  • Define the Cisco NAM Administration Module
  • Set Network and Failover Parameters
  • Manage Administration Groups
  • Manage Administration Users
  • Manage User Passwords
  • Administer the System Time
  • Manage SSL Certificates
  • Manage the Cisco NAC Appliance Software
  • Protect Your NAM Configuration

Labs

Lab 1: Bootstrap Primary NAM & NAS

  • Run setup scripts on NAM and NAS
  • Log in to the Web Administration Environment
  • View a Common Routing Issue for the Hosts on the Same Subnet as the NAS
  • See some newer password enhancements in 4.5 software code

Lab 2: Configuring User Roles and Traffic Policies

  • Configure Default User Web Pages Based Upon Where a User is Coming From
  • Create User Roles on the NAM
  • Create Traffic Policies that Map to Each User Role
  • Configure New Users in the Local Database

Lab 3: Configure NAS In-Band Virtual Gateway

  • Connect an In-Band NAS to the NAM
  • Configure NAS as Virtual Gateway
  • Configure VLAN Mapping
  • Install the NAA for the First Time and Determine the Rights Needed
  • Install the Stub Installed
  • Use the Web Agent to Scan an Outside User's PC Who Does Not Have Local Admin Rights

Lab 4: Create a High Availability NAM Cluster

  • Configure the Secondary NAM
  • Confirm Connectivity between Primary & Secondary NAM
  • Export the Private Key and SSL Certificate of the Primary NAM
  • Import the Private Key and SSL Certificate into the Secondary NAM
  • Configure Network and Failover Settings on Primary & Secondary NAM
  • Verify NAM Database Synchronization
  • Test Failover

Lab 5: Configuring Active Directory Single Sign-On (AD SSO)

  • Add AD SSO Authentication Server
  • Configure Traffic Policies for the Unauthenticated Role
  • Enable the NAS to Use AD SSO
  • Use ktpass.exe to Prepare the Domain Controller
  • Enable and Test Agent-Based AD SSO

Lab 6: Configuring VPN Remote Access

  • Configure the ASA as a Filter Device
  • Configure NAC Appliance to use an ASA 5520 as a Floating Device
  • Add VPN Authentication Server to the NAM
  • Map VPN Users to Roles for SSO
  • Add a RADIUS Accounting Server to the NAS
  • Map the ASA 5520 to the Accounting Server
  • Configure VLAN Mappings to allow Internet Access through the NAS
  • Modify IP Filters to allow Returning Internet Traffic Back Through
  • Test VPN SSO

Lab 7: Configuring NAC VPN SSO

  • Configure the ASA to Communicate with the RADIUS and Accounting Server
  • Adjust Traffic Filters for Additional VPN Address Pools
  • Use Framed-IP-Address Fields in the Accounting Packet to Map VPN Users to NAC Appliance Roles
  • Use Kiwi CatTools to load ASA Version 8.x Code and the AnyConnect Client Config
  • Test VPN SSO

Lab 8: Configure Switch for Out-Of-Band Operation

  • Delete the In-Band NAS from the NAM
  • Reconfigure the NAS as OOB Virtual Gateway
  • Configure VLAN Mapping
  • Verify Switch SNMP Configuration
  • Configure Group and Switch Profiles
  • Configure the NAM as an SNMP Trap Receiver
  • Add Switches and Configure Ports on the NAM
  • Test Your Configuration

Lab 9: Configuring the NAC Appliance Agent (NAA) for Specific Threats

  • Configure the General Setup for NAA
  • Allow DNS Packets to Your Network in the Temporary Role
  • Create Checks and Rules
  • Create a New Requirement for Users
  • Associate the Requirement to a Role
  • Remediation Types and Appropriate Rights for Each
    • AV Check and File Distribution
    • Local Application Launch
    • Code Signing Requirements
  • Compare Manual and Automatic Remediation
  • Verify the Configuration

Lab 10: Enhanced SSO with LDAP Group Authorization

  • Configure an LDAP Lookup Server
  • Configure Authorized Groups in Active Directory
  • Associate the Lookup Server with an Authentication Provider
  • Test the Solution

Class Dates:

Orlando, FL
Aug 03, 2010 - Aug 06, 2010
Register Now
New York City, NY
Aug 17, 2010 - Aug 20, 2010
Register Now
Houston, TX
Aug 31, 2010 - Sep 03, 2010
Register Now
Atlanta, GA
Sep 28, 2010 - Oct 01, 2010
Register Now
Chicago, IL
Oct 19, 2010 - Oct 22, 2010
Register Now
Washington, DC
Oct 26, 2010 - Oct 29, 2010
Register Now
Dallas, TX
Nov 09, 2010 - Nov 12, 2010
Register Now
San Jose, CA
Nov 16, 2010 - Nov 19, 2010
Register Now
Morristown, NJ
Nov 30, 2010 - Dec 03, 2010
Register Now
Raleigh, NC
Dec 07, 2010 - Dec 10, 2010
Register Now
New York City, NY
Dec 14, 2010 - Dec 17, 2010
Register Now