Installation
nac_v8.2.0
Search this version
Installation
Installation
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Cisco Layer 3 Switch Integration Script (2960X/XR)
Copy Markdown
Open in ChatGPT
Open in Claude
This document provides scripts required to complete the installation of the NAC Solution
NAC Router Integration Script
Powershell
x
conf t!flow record sc-record match ipv4 protocolmatch ipv4 source address match ipv4 destination address match transport source-portmatch transport destination-port!flow exporter sc-exporterdestination x.x.x.x (replace x.x.x.x with IP of NAC server and remove this comment)transport udp 50001export-protocol netflow-v5!flow monitor sc-monitor exporter sc-exporter record sc-record!sampler sc-samplermode deterministic 1 out-of 32!ip access-list extended impulse_block permit ip any host 198.31.193.211!ip access-list extended intranetremark allow DNS deny udp anyremark allow any eqDHCP domaindeny udp any any eq bootpsremark allow access to AD server deny ip any host x.x.x.x (Replace with IP of AD server and remove this comment)remark allow access to AV serverdeny ip any host x.x.x.x (Replace with IP of AV server and remove this comment)remark allow RDP access to blocked hosts deny tcp any eq 3389 any!route-map impulse permit 10match ip address intranet! route-map impulse permit 20match ip address impulse_blockset ip next-hop x.x.x.x (replace x.x.x.x with IP of NAC server and remove this comment)!interface X (Layer 3 interface(s) which is/are default gateway for subnet(s) to be placed under policy – recommend a test subnet first, remove this comment)ip policy route-map impulseip flow-monitor sc-monitor sampler sc-sampler inputip helper-address x.x.x.x (replace with IP of NAC appliance and remove this comment)!end*Note – Be sure to also allow the NAC Enforcer access to the router if a VTY/SSH access-list is present on the router.
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated on
Was this page helpful?
Next to read:
Cisco Layer 3 Switch Integration Script (3750X)Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message
