NAC device into learning mode?

  • 0
  • 1
  • Question
  • Updated 2 years ago
  • Answered
Hi All! I heard that you can put your NAC device into learning mode to get an idea as to what comes onto the network but I am unsure how to do this? I would like to do this in my lab environment to see how it works. Can anyone give me instructions?
Photo of Jason

Jason

  • 110 Points 100 badge 2x thumb

Posted 2 years ago

  • 0
  • 1
Photo of Nico Willamowski

Nico Willamowski

  • 876 Points 500 badge 2x thumb
We do this by the following way. We activate MAC Auth at all ports via Policy Manager and create a Rule "Allow All". In NAC we create a Profile with Response of this Policy "Allow All". Then we create a rule and put in this Profile. So you can see all Clients behind you Switch Ports and in the first step they will be allowed to connect. In other steps you can create End-System Groups and other criteria and do an authentication.
Photo of Pala, Zdenek

Pala, Zdenek, Employee

  • 8,474 Points 5k badge 2x thumb
In rules use pass-through NAC Profile
Photo of Ronald Dvorak

Ronald Dvorak, Embassador

  • 45,286 Points 20k badge 2x thumb
You also should forward the client DHCP requests to the NAC as that messages are needed for fingerprinting.

-Ron