Specifications

6-3
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 6 User Management: Configuring User Roles and Local Users
Create User Roles
Figure 6-1 Normal Login User Roles
User Role Types
The system puts a user in a role when the user attempts to log in. There are four default user role types
in the system: Unauthenticated Role, Normal Login role, Agent Temporary role, and Quarantine role.
Unauthenticated Role
There is only one Unauthenticated Role and it is the system default role. If a configured normal login
role is deleted, users in that role are reassigned to the Unauthenticated Role (see Delete Role, page 6-15).
You can configure traffic and other policies for the Unauthenticated Role, but the role itself cannot be
edited or removed from the system.
Users on the untrusted (managed) side of the Clean Access Server are in the Unauthenticated role prior
to the initial web login or Agent login. When using web login/network scanning only, users remain in
the Unauthenticated role until clients pass scanning (and are transferred to a normal login role), or fail
scanning (and are either blocked or transferred to the quarantine role).