Network Access Control (NAC)
Configuration > Overlays & Security > Security > Network Access Control (NAC)
When Network Access Control (NAC) is enabled on an appliance, the appliance authenticates traffic that accesses the network over untrusted interfaces. The appliance interprets the protocol packets and builds a RADIUS packet to get the station (client) authenticated with an external RADIUS server.
By default, authentication for all interfaces is set to trusted. When authentication is set to trusted, no authentication is required to access the network. When NAC security is enabled, the appliance authenticates stations that are trying to access the network using the policy you assign to the interface. This feature supports the EAP-TLS, EAP-TTLS, and EAP-PEAP methods for 802.1x authentication and the PAP method for MAC authentication.
Use the Network Access Control (NAC) tab to:
-
Configure and modify NAC security for appliances using 802.1x and MAC authentication. There are two methods for enabling and managing NAC security: via templates or on a per-appliance basis.
-
Managing NAC security via templates is the recommended method. If you manage NAC authentication using templates, all settings are initially applied via the Network Access Control (NAC) configuration template for all appliances. Navigate to Configuration > Templates & Policies > Templates to display the Templates tab to add or edit a Network Access Control (NAC) template.
-
To enable or edit Network Access Control (NAC) on a per-appliance basis, see Enable or Edit Network Access Control (NAC).
-
-
View configuration settings for NAC security for all appliances whether NAC is enabled via templates or on a per-appliance basis.
- To refresh the NAC configuration table, click the Refresh button.
-
Monitor and troubleshoot NAC authentication, including failures.
-
To view information about active stations, click Active. For more information, see Active Stations.
-
To view cached stations, click Cache. For more information, see Cached Stations.
-
To view stations that have been temporarily denied access, click Deny list. For more information, see Deny List Stations.
-
-
View historical station data to track persistent authentication failures.
- To view historical station data, click History. For more information, see Stations History.
-
Download NAC security information from the NAC tab and subtabs by clicking Export.
Orchestrator supports the following maximum stations (MAC addresses), depending on the version you are running:
-
9.5.4 and earlier—Orchestrator supports authentication of up to 100 unique stations (MAC addresses) per interface, with 1024 unique MAC addresses allowed across all interfaces combined.
-
9.6.0 and later—Orchestrator supports 2048 unique stations (MAC addresses) per interface or across all interfaces combined.
The Configuration table on the Network Access Control (NAC) tab displays the following information.
| Field | Description |
|---|---|
| Appliance | Name of the appliance for the Network Access Control (NAC) security settings. |
| LAN interface | LAN interface of the appliance to which the NAC policies are applied. |
| AAA profile | AAA profile applied to the appliance. |
| Auth type | Authentication type applied to the appliance. |
| Enabled | Indicates if NAC is enabled for the appliance or not. |
| Actions | Hover to view available actions for this row (Edit). |
Active Stations
Use the NAC Active Stations subtab to review and monitor the authentication of all stations. To disconnect a station, select the entry for it in the table, and then click Disconnect. To select all entries in the table, click Select all. To refresh the table, click Auto refresh. To pause updates to the table, click Pause. By default, the table refreshes automatically.
| Field | Description |
|---|---|
| Appliance | Name of the appliance. |
| MAC address | The MAC address of the station. |
| Identity | Identity on which the port is learned. |
| Interface | Port on which the identity of the station is learned. |
| Auth type | Authentication method (802.1x or MAC) used to verify the identity of the station. |
| Status | Indicates whether the station was authenticated or not. |
| Details | Click the information icon to display a complete list of NAC status details for the station. |
Cached Stations
Use the NAC Cached Stations subtab to review and monitor MAC authenticated stations (clients) that are stored in the persistent local cache on an EdgeConnect appliance. Authentication survivability is enabled for the stations included in this table, which allows them to stay connected for a configured period of time in the event of a RADIUS server outage. After the survivability duration expires for a station it must reauthenticate. Authentication survivability is configured in the AAA profile. For more information, see AAA Profile.
NOTE: The Cached stations subtab only shows MAC authenticated stations. This feature is not available for 802.1x authentication.
The NAC Cached Stations table can have a maximum of 2048 entries. When the table reaches its capacity, new entries are discarded. To refresh the table, click Auto refresh. To pause updates to the table, click Pause. By default, the table refreshes automatically.
| Column | Description |
|---|---|
| Appliance | Name of the appliance. |
| MAC address | MAC address of the cached station. |
| Interface | Port on which the identity of the station is learned. |
| Auth type | Authentication method used to verify the identity of the station; only MAC authentication is supported for caching. |
| Cache expiry | Configured duration after which cached data becomes invalid and the station must reauthenticate. |
Deny List Stations
Use the NAC Deny List Stations subtab to review and monitor stations that are temporarily denied access due to excessive authentication failure. The NAC deny list is a temporary block list that prevents specific station MAC addresses from attempting authentication for a configurable period of time, and while on the deny list, any new authentication requests from the MAC address are silently dropped. You must enable the deny list in the AAA profile. For more information, see AAA Profile. A failure is defined as follows:
-
A RADIUS authentication rejection for a MAC-based authentication request.
-
A RADIUS response that indicates rejection due to policy, such as invalid credentials, an unknown device, or explicit deny rules.
The NAC Deny List Stations table can have a maximum of 2048 entries. When the table reaches its capacity, new entries are discarded. To unblock a station before the deny list duration expires for it, select the entry for it in the table, and then click Unblock. To select all entries in the table, click Select all. To refresh the table, click Auto refresh. To pause updates to the table, click Pause. By default, the table refreshes automatically.
| Column | Description |
|---|---|
| Appliance | Name of the appliance. |
| MAC address | MAC address of the station that is temporarily denied access. |
| Interface | Port on which the identity of the station is learned. |
| Auth type | Authentication method (802.1x or MAC) used to verify the identity of the station. |
| Reason | Reason the station MAC address is temporarily denied access. |
| Deny expiry | Configured duration of time that the station MAC address is denied access. |
Stations History
Use the NAC Stations History tab to track and monitor stations that fail authentication including repeat failures. If a station fails authentication repeatedly, the entry in the table is updated with each failure.
To refresh the table, click Auto refresh. To pause updates to the table, click Pause. By default, the table refreshes automatically.
| Column | Description |
|---|---|
| Appliance | Name of the appliance. |
| MAC address | MAC address of the station. |
| Interface | Port on which the identity of the station is learned. |
| Reason | Reason the MAC address is temporarily denied access. |
| Total count | Number of times the MAC address has been denied access due to a failed authentication attempt. This number is updated in the table entry for a station each time it fails authentication. |
| Inactive time | Date and time when the MAC address was denied access due to a failed authentication attempt. This timestamp is updated in the table entry for a station each time it fails authentication. |
| Details | Click the information icon to display a complete list of NAC history details for the station. |
Enable or Edit Network Access Control (NAC)
Setting Network Access Control (NAC) is a four-step process that is completed in the Network Access Control (NAC) dialog box.
-
Create an 802.1x/MAC authentication profile. See 802.1x/MAC Authentication Profiles.
-
Define the servers and optional server groups used for authenticating stations on the selected interface. See Server.
-
Add or edit the AAA profiles used for authentication. See AAA Profile.
-
Apply the Network Access Control (NAC) policies to the interface labels. See Apply Policies.
802.1x/MAC Authentication Profiles
Use the 802.1x/MAC tab to add or edit authentication profiles. You should create both 802.1x authentication and MAC authentication profiles. If the station is 802.1x compliant, the appliance will use the 802.1x profile to authenticate the station. If the station is not 802.1x compliant, the appliance will use the MAC profile to authenticate the station.
802.1x Authentication Profile Fields
-
On the Network Access Control (NAC) tab, click Configuration. Then select one or more appliances from the appliance tree, hover over the Actions column, and click the edit icon in the applicable table row.
The Network Access Control (NAC) dialog box opens.
-
Click Enable NAC.
-
Click Add to add a new 802.1x authentication profile, or hover over the Actions column and click the edit icon to edit an existing 802.1x profile.
The Add 802.1x Authentication Profile dialog box opens.
NOTE: To modify an existing profile, edit the applicable fields and then click Done. To delete an 802.1x authentication profile, hover over the Actions column for the profile and click the X icon.
-
Complete the following fields.
Field Description Profile Enter a name for the 802.1x profile. Max auth failure Maximum number of authentication failures allowed before the station is denied access. Default is 1, and the range is 1-5. Max request Maximum number of authentication requests that the appliance will send to the server. Default is 0, and the range is 0-3. Identity requests interval Interval (in seconds) between identity request retries. Default is 5 sec, and the range is 1-65535 sec. Quiet period Interval (in seconds) to wait before attempting to reauthenticate after a failed authentication. Default is 30 sec, and the range is 1-65535 sec. Server retry count Maximum number of retries that can be made on each server in a server group. If a server is not available, after the specified number of retries, Orchestrator attempts to access the next server in the server group. Default is 3, and the range is 1-5. Server group retry period Timeout duration (in seconds). If the appliance cannot reach the server within the specified period, the session times out. Default is 60 sec, and the range is 60-65535 sec. Reauthentication Select this check box to force the appliance to perform a reauthentication within the configured reauthentication interval. Max reauthentication Maximum number of reauthentication attempts. Default is 3, and the range is 1-10. Reauthentication interval Interval (in seconds) between reauthentication attempts. The configured interval is overridden if the RADIUS server provided the reauthentication period. Default is 86400 sec, and the range is 60-864000 sec. Ignore EAPOL-START Select this check box if the appliance should ignore the EAPOL-START messages after authentication. Handle EAPOL-Logoff Select this check box to handle the EAPOL-LOGOFF messages sent by the stations. -
Click Done.
MAC Authentication Profile Fields
-
Click Add to add a new MAC authentication profile, or hover over the Actions column and click the edit icon to edit an existing MAC authentication profile.
The Add MAC Authentication Profile dialog box opens.
NOTE: To modify an existing profile, edit the applicable fields and then click Done. To delete a MAC authentication profile, hover over the Actions column for the profile and click the X icon.
-
Complete the following fields.
Field Description Profile Enter a name for the MAC authentication profile. Max auth failure Maximum number of authentication failures allowed before the station is denied access. Default is 1, and the range is 1-5. Quiet period Interval (in seconds) to wait before attempting the retry after the failed authentication. Default is 30 sec, and the range is 1-65535 sec. Server retry count Maximum number of retries that can be made on each server in a server group. If a server is not available, after the specified number of retries, Orchestrator attempts to access the next server in the server group. Default is 3, and the range is 1-5. Server group retry period Timeout duration (in seconds). If the appliance cannot reach the server within the specified period, the session times out. Default is 60 sec, and the range is 60-65535 sec. Reauthentication Select this check box to force the appliance to perform a reauthentication within the configured reauthentication interval. Max reauthentication Maximum number of reauthentication attempts. Default is 3, and the range is 1-10. Reauthentication interval Interval (in seconds) between reauthentication attempts. Default is 86400 sec, and the range is 60-864000 sec. Message authenticator Select this check box to require all MAC authentication requests to include the Message-Authenticator attribute. -
Click Done.
Continue to Server for server and server groups configuration.
Server
Use the Server tab to add or edit the servers and server groups you want to use to authenticate the stations that are attempting to log in to the network.
Server Fields
-
On the Network Access Control (NAC) dialog box, click Server.
-
Click Add to add a new server, or hover over the Actions column and click the edit icon to edit an existing server.
NOTE: To modify an existing server, edit the applicable fields and then click Done. To delete a server, hover over the Actions column for the server and click the X icon.
-
Complete the following fields.
Field Description ID Unique identifier of the server. Server name Enter a name for the server. Host Enter the FQDN, IPv4 address, or IPv6 address of the RADIUS server. Key Pre-shared key of the authentication server. This key is shared between the Mobility Conductor and the server. The maximum length is 128 characters. Auth port Server port on the server. Interface for source IP address IP address of the RADIUS server. This option allows the user to configure the interface to reach the RADIUS server. Source segment Segment name of the interface configured to reach the server. -
Click Done.
Server Groups Fields
You can create groups of servers. If one server is not reachable based on the server retry count configured on the 802.1x/MAC tab, the appliance will try to reach another server.
-
Click Add to add a new server group, or hover over the Actions column and click the edit icon to edit an existing server group.
The Server Group dialog box opens.
NOTE: To modify an existing server group, edit the applicable fields and then click Done. To delete a server group, hover over the Actions column for the server group and click the X icon.
-
Complete the following fields.
Field Description ID Unique identifier of the server group. Server group name Enter a name for the server group. Servers Servers in the server group. Click the cell to select servers from the list. -
Click Done.
Continue to AAA Profile.
AAA Profile
Use the AAA Profile tab to add or edit AAA profiles to map the 802.1x and MAC authentication profiles to a server group you want to use to authenticate stations. This profile is used for dynamic authorization—for example, when a station needs to be reauthenticated or when the existing session is disconnected. After you create a AAA profile, you assign the profile to an interface label.
-
On the Network Access Control (NAC) dialog box, click AAA Profile.
-
Click Add to add a AAA profile, or hover over the Actions column and click the edit icon to edit an existing AAA profile.
The Edit AAA Profile dialog box opens.
NOTE: To modify an existing AAA profile, edit the applicable fields and then click Done. To delete a AAA profile, hover over the Actions column for the profile and click the X icon.
-
Complete the following fields.
Field Description Profile Enter a name for the AAA profile. DA Enable Select this check box to enable Dynamic Authorization functionality. DA Server If you enabled DA, select the server to use for Dynamic Authorization. 802.1x Auth Profile Select the name of the 802.1x authentication profile. 802.1x Default Role Select the default role assigned to 802.1x stations. 802.1x Auth Server Group Select the server group used for 802.1x authentication. MAC Auth Profile Select the name of the MAC authentication profile. MAC Default Role Select the role assigned to the station for MAC stations. MAC Auth Server Group Select the name of the server group used for MAC authentication. Enable Survivability Select this check box to enable authentication survivability. When enabled, if the authentication server becomes unavailable, stations that were already successfully authenticated retain access because the session information is stored in the local cache of the EdgeConnect appliance. Access for cached stations is based on the configured survivability duration (timer). Authentication Survivability is only applicable for MAC authentication. 802.1x enabled stations do not survive the authentication when an upstream RADIUS server becomes unreachable. Survivability Duration Maximum period of time (in hours) that a cached station can stay connected when all RADIUS servers are unreachable. After the survivability duration expires, the station must reauthenticate. Default is 24 Hrs, and the range is 1-168 Hrs. Survivability Duration must be set equal to or greater than the reauthorization interval if reauthorization is enabled (802.1x or MAC authentication profile). Enable Deny List Select this check box to add stations to the deny list if they have excessive authentication failures and are denied access. When a station MAC address is added to the deny list, it is prevented from attempting authentication for a configured period of time. While on the deny list, any new authentication requests from the MAC address are silently dropped. Deny List Duration Maximum period of time (in minutes) that a station remains on the deny list. After the deny list duration expires, the station is automatically removed from the list and can retry authentication. Default is 15 Min, and the range is 1-1440 Min. Deny List Threshold Count The Deny List Threshold Count controls how aggressively the system identifies and temporarily blocks stations (clients) that are experiencing excessive authentication failures. This setting works in conjunction with the Max auth failure value configured in your 802.1x or MAC authentication profile to determine the total number of authentication attempts a station is allowed before it is added to the deny list. Default is 3, and the range is 1–50.
Formula:
[Deny List Threshold Count] × [Max auth failure] = Total allowed authentication attempts
Example: If the Deny List Threshold Count is set to 2 and the Max auth failure is set to 3 in the MAC or 802.1x authentication profile, the station is allowed a total of 6 authentication attempts before being denied.
[2] × [3] = 6 total allowed authentication attempts -
Click Done.
Continue to Apply Policies.
Apply Policies
Use the Apply Policies tab to modify the policies that are assigned to each interface label. Stations plugged into the LAN port with the assigned interface label will be authenticated using the policy you select.
Each LAN interface label defined in your Orchestrator deployment is assigned the default authentication policy. The default authentication policy is set to “trusted.” When authentication is set to “trusted”, no authentication is required to access the network.
-
On the Network Access Control (NAC) dialog box, click Apply policies.
-
Click Modify.
The Interfaces dialog box opens. All available LAN interfaces are listed.
-
Hover over the Actions column and click the edit icon for the interface label that you are assigning a policy to.
The Apply Policy dialog box opens.
-
Select a AAA profile.
NOTE: If AAA profile is set to none, the Auth type is automatically set to Trusted.
-
Select an authentication method from the Auth type menu.
-
Trusted: Select Trusted if no authentication is required.
-
Both: Select Both to first attempt 802.1x authentication and then fall back to MAC authentication.
-
802.1x: Select 802.1x if the port only supports 802.1x authentication.
-
Mac: Select Mac if the port only supports MAC authentication.
-
-
To close the Apply Policy dialog box, click Done.
-
To close the Interfaces dialog box, click Save.
-
To close the Network Access Control (NAC) dialog box and finish enabling NAC, click Save.
You will receive a green status message if your policy was successfully applied.
Delete a Policy
To delete a policy from a LAN interface, hover over the Actions column for the LAN interface and click the X icon. The NAC security settings for this LAN interface return to the default values.