Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco NAC, Cisco ACS and Cicso ASA

Status
Not open for further replies.

Daveyd123

MIS
Aug 25, 2004
413
US
Currently we have a failover pair of ASA 5510s. I am looking into a solution to provide AAA services to our SSL VPN users and well as some sort of Network Control..ie scanning the VPN computer for latest Windows updates, virus definitions, etc.

My question is, do I need to purchase both a NAC appliance and ACS software to do what I want...or will the ASA handle everything?

Hope I made sense
 
If I were to get a NAC appliance, would I also need to buy ACS sotware as well or would the NAC appliance give me AAA functionality with an ACS server?
 
You can purchase ACS as either software or server. You are much better off with the server. For NAC you will need a CLean Access Server and a Clean Access Manager.
 
Does the NAC appliance provide AAA? I do not want to buy an ACS server and a NAC server if the NAC does everything
 
Do you need ACS for a specific reason or will just a linux AAA server handle what you need?


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
I was just going to stick with all Cisco products since we are a Cisco shop...no other reason really
 
Unless you need other features ACS offers than you could use IAS on a Windows domain controller and utilize the same passwords.
 
I originally tried the IAS server and had a lot of difficulties with it. I have a lot of different SSL VPN users each with different ASA Group Policies. I couldn't get it to work
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top