Specifications
9-3
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 9 Configuring Cisco NAC Appliance for Agent Login and Client Posture Assessment
Add Default Login Page
Agent Configuration Steps
The basic steps needed to configure Agent distribution, installation, and posture assessment are:
Step 1 Add Default Login Page, page 9-3
Step 2 Configure Agent Roles and User Profiles, page 9-3
Step 3 Require Agent Login for Client Machines, page 9-3
Step 4 Retrieving Cisco NAC Appliance Updates, page 9-12
Step 5 Setting Up Agent Distribution/Installation, page 9-17
Step 6 Configuring Agent-Based Posture Assessment, page 9-39
Add Default Login Page
In order for both web login users and Agent users to obtain the list of authentication providers, a login
page must be added and present in the system in order for user to authenticate via the Agent. See Add
Default Login Page, page 5-3 to quickly add the default user login page.
Note For L3 OOB deployments, you must also Enable Web Client for Login Page, page 5-5.
Configure Agent Roles and User Profiles
In order for Agent users to log in to Cisco NAC Appliance, you must ensure that user login roles and
user profiles are configured in the system. See Create User Roles, page 6-2 and Create Local User
Accounts, page 6-15 to add user roles and individual user login profiles in Cisco NAC Appliance.
Require Agent Login for Client Machines
Requiring the use of the Agent is configured per user role and operating system. When an Agent is
required for a role, users in that role are forwarded to the Agent download page (Figure 9-2) after
authenticating for the first time using web login. The user is then prompted to download and run the
Agent installation file or launch the Cisco NAC Web Agent. At the end of the installation, the user is
prompted to log into the network using the Agent. (Cisco NAC Web Agent users are automatically
connected to the network as long as their client machine meets Agent Requirements configured for the
user role.)
Step 1 Go to Device Management > Clean Access > General Setup > Agent Login (Figure 9-1).