Version User Scope of changes
Feb 12 2008, 11:04 AM EST JimmyRay10acn 244 words added
Feb 11 2008, 12:57 PM EST robboyd 51 words added

Changes

Key:  Additions   Deletions
Segment 3: Topology and Design

Robb, Jimmy Ray and Alok - NAC Server Blade for the ISRVPN and Wireless mean at least one thing for sure; Inband mode. Do we have to use ONLY Cisco wireless stuff to have a solid NAC solution?

No of course not. NAC is very flexible and
all wireless users can be subject to NAC Appliance compliance (that sounds like the start of a SchoolHouse Rock Video... "Appliance Compliance without Defiance..." Hey Robb...

Anyway...when connecting through any Wi-Fi access point we can enforce our will and power upon all the users <insert/ evil laugh here>. The following wireless products are supported by NAC Appliance:
• Any 802.11 Wi-Fi access point including: –Cisco Aironet access points deployed in stand alone mode-Cisco Aironet 350, 1100, 1130AG, 1200, 1230AG, 1240AG, and 1300 series access points. –Cisco Aironet lightweight access points deployed with a Cisco Wireless LAN Controller (Access points-Cisco Aironet 1000, 1130AG, 12001, 1230AG, 1240AG and 1500 series access points and Cisco-2000 or 4400 series wireless LAN controllers as well as the Cisco Catalyst 6500 Series Wireless Services Module (WiSM), the Cisco Catalyst 3750G Integrated Wireless LAN Controller and the Cisco Wireless LAN Controller Module for Integrated Services Routers). Cisco Aironet lightweight access points are configured for NAC Appliance compliance via Web-based setup on the wireless LAN controller. • Any 802.11 Wi-Fi client device including: –Cisco Aironet client devices –Cisco Compatible client devices
So lots of options here.
What really makes NAC Appliance an awesome solution is






  • VPN
  • Wireless
  • Remote Sites
  • Campus

Blogger:
Jamie Sanbower from Force3 maintains a nice Cisco NAC Blog
We brought up a question he left for us here on the wiki:
"I would like to get a better explanation for the Pro/Cons around the different deployment options for deploying L3 OOB in a campus environment. [specifically] Why chose ACLs/VRF/PBR for your deployments and why? What are the deciding factors?"