Cisco Network Admission Control, Volume II: 2 and over one million other books are available for Amazon Kindle. Learn more


or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Kindle Edition
 
   
Sell Back Your Copy
For a $0.45 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting
 
 
Start reading Cisco Network Admission Control, Volume II: 2 on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting [Paperback]

Jazib Frahim (Author), Omar Santos (Author), David White (Author)
5.0 out of 5 stars  See all reviews (2 customer reviews)

Price: $65.00 & this item ships for FREE with Super Saver Shipping. Details
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 2 left in stock--order soon (more on the way).
Want it delivered Tuesday, February 14? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for students on millions of items. Learn more

Formats

Amazon Price New from Used from
Kindle Edition $38.40  
Paperback $65.00  

Book Description

December 1, 2006 1587052253 978-1587052255 1

Cisco Network Admission Control

Volume II: NAC Framework Deployment and Troubleshooting

 

The self-defending network in action

 

Jazib Frahim, CCIE® No. 5459

Omar Santos

David White, Jr., CCIE No. 12,021

 

When most information security professionals think about threats to their networks, they think about the threat of attackers from the outside. However, in recent years the number of computer security incidents occurring from trusted users within a company has equaled those occurring from external threats. The difference is, external threats are fairly well understood and almost all companies utilize tools and technology to protect against those threats. In contrast, the threats from internal trusted employees or partners are often overlooked and much more difficult to protect against.

 

Network Admission Control (NAC) is designed to prohibit or restrict access to the secured internal network from devices with a diminished security posture until they are patched or updated to meet the minimum corporate security requirements. A fundamental component of the Cisco® Self-Defending Network Initiative, NAC enables you to enforce host patch policies and to regulate network access permissions for noncompliant, vulnerable systems.

 

Cisco Network Admission Control, Volume II, helps you understand how to deploy the NAC Framework solution and ultimately build a self-defending network. The book focuses on the key components that make up the NAC Framework, showing how you can successfully deploy and troubleshoot each component and the overall solution. Emphasis is placed on real-world deployment scenarios, and the book walks you step by step through individual component configurations. Along the way, the authors call out best practices and tell you which mistakes to avoid. Component-level and solution-level troubleshooting techniques are also presented. Three full-deployment scenarios walk you through application of NAC in a small business, medium-sized organization, and large enterprise.

 

“To successfully deploy and troubleshoot the Cisco NAC solution requires thoughtful builds and design of NAC in branch, campus, and enterprise topologies. It requires a practical and methodical view towards building layered security and management with troubleshooting, auditing, and monitoring capabilities.”

—Jayshree V. Ullal, Senior Vice President, Datacenter, Switching and Security Technology Group, Cisco Systems®

 

Jazib Frahim, CCIE® No. 5459, is a senior network security engineer in the Worldwide Security Services Practice of the Cisco Advanced Services for Network Security team. He is responsible for guiding customers in the design and implementation of their networks with a focus on network security.

 

Omar Santos is a senior network security engineer in the Worldwide Security Services Practice of the Cisco Advanced Services for Network Security team. He has more than 12 years of experience in secure data communications.

 

David White, Jr., CCIE No. 12,021, has more than 10 years of networking experience with a focus on network security. He is currently an escalation engineer in the Cisco TAC, where he has been for more than six years.

 

  • Effectively deploy the Cisco Trust Agent
  • Configure Layer 2 IP and Layer 2 802.1x NAC on network access devices
  • Examine packet flow in a Cisco IOS NAD when NAC is enabled, and configure Layer 3 NAC on the NAD
  • Monitor remote access VPN tunnels
  • Configure and troubleshoot NAC on the Cisco ASA and PIX security appliances
  • Install and configure Cisco Secure Access Control Server (ACS) for NAC
  • Install the Cisco Security Agent Manage-ment Center and create agent kits
  • Add antivirus policy servers to ACS for external antivirus posture validation
  • Understand and apply audit servers to your NAC solution
  • Use remediation servers to automatically patch end hosts to bring them in compliance with your network policies
  • Monitor the NAC solution using the Cisco Security Monitoring, Analysis, and Response System (MARS)

 

This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.

 

Category: Cisco Press—Security

Covers: Network Admission Control

 

$60.00 USA / $75.00 CAN

 


Frequently Bought Together

Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting + Cisco Network Admission Control, Volume I: NAC Framework Architecture and Design + Cisco NAC Appliance: Enforcing Host Security with Clean Access
Price For All Three: $161.52

Show availability and shipping details

Buy the selected items together
  • In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Cisco Network Admission Control, Volume I: NAC Framework Architecture and Design $45.55

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Cisco NAC Appliance: Enforcing Host Security with Clean Access $50.97

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details



Editorial Reviews

About the Author

Jazib Frahim, CCIE No. 5459, has been with Cisco Systems for more than seven years. With a Bachelor’s degree in computer engineering from Illinois Institute of Technology, he started out as a TAC engineer with the LAN Switching team. He then moved to the TAC Security team, where he acted as a technical leader for the security products. He led a team of 20 engineers as a team leader in resolving complicated security and VPN technologies. Jazib is currently working as a Senior Network Security Engineer in the Worldwide Security Services Practice of Cisco’s Advanced Services for Network Security. He is responsible for guiding customers in the design and implementation of their networks, with a focus in network security. He holds two CCIEs, one in Routing and Switching and the other in Security. He also authored the Cisco Press book Cisco ASA: All-in-one Firewall, IPS, and VPN Adaptive Security Appliance(ISBN: 1-58705-209-1). Additionally, Jazib has written numerous Cisco online technical documents and has been an active member on Cisco’s online forum, NetPro. He has presented at Networkers on multiple occasions and has taught many onsite and online courses to Cisco customers, partners, and employees.

Jazib is currently pursuing a Master of Business Administration (MBA) degree from North Carolina State University.

 

Omar Santos is a Senior Network Security Consulting Engineer in the Worldwide Security Services Practice of Cisco’s Advanced Services for Network Security. He has more than 12 years of experience in secure data communications. Omar has designed, implemented, and supported numerous secure networks for Fortune 500 companies and the U.S. government, including the United States Marine Corps (USMC) and Department of Defense (DoD). He is also the author of the Cisco Press book Cisco ASA: All-in-one Firewall, IPS, and VPN Adaptive Security Appliance(ISBN: 1-58705-209-1) and many Cisco online technical documents and configuration guidelines. Prior to his current role, he was a technical leader of Cisco’s Technical Assistance Center (TAC), where he taught, led, and mentored many engineers within the organization. He is an active member of the InfraGard organization, a cooperative undertaking between the Federal Bureau of Investigation and an association of businesses, academic institutions, state and local law-enforcement agencies, and other participants that are dedicated to increasing the security of the critical infrastructures of the United States of America. Omar has also delivered numerous technical presentations to Cisco customers, partners, and other organizations.

 

David White, Jr., CCIE No. 12021, has more than ten years of networking experience with a focus on network security. He is currently an Escalation Engineer in the Cisco TAC, where he has been for more than six years. In his role at Cisco, he is involved in new product design and implementation and is an active participant in Cisco documentation, both online and in print. David holds a CCIE in Security and is also NSA IAM certified. Before joining Cisco, David worked for the U.S. government, where he helped secure its worldwide communications network. He was born and raised in St. Petersburg, Florida, and received his Bachelor’s degree in computer engineering from the Georgia Institute of Technology.

 


Product Details

  • Paperback: 624 pages
  • Publisher: Cisco Press; 1 edition (December 1, 2006)
  • Language: English
  • ISBN-10: 1587052253
  • ISBN-13: 978-1587052255
  • Product Dimensions: 9.1 x 7.4 x 1.3 inches
  • Shipping Weight: 2.2 pounds (View shipping rates and policies)
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (2 customer reviews)
  • Amazon Best Sellers Rank: #1,382,589 in Books (See Top 100 in Books)

More About the Authors

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

2 Reviews
5 star:
 (2)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (2 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

1 of 1 people found the following review helpful:
5.0 out of 5 stars Are you ready to NAC?, March 6, 2007
By 
Martin (Los Angeles CA) - See all my reviews
This review is from: Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting (Paperback)
The first volume for Cisco Network Admission Control series explains the architecture, design and components for NAC Framework. The second volume explains the production deployment as well as troubleshooting NAC Framework to build a self-defending network.

I found the second volume more helpful and practical as it provides technical configuration and implementation guidelines. The book is basically divided into four parts: NAC Framework solution Overview, Configuration Guidelines, Deployment Scenarios and finally Managing and Monitoring NAC.

I think that the first chapter is the most important as it explains the NAC Framework solution overview and the components needed to support it. It shows which Cisco network access devices and which Cat or Cisco IOS version support this feature. It explains the difference among NAC-L3-IP, NAC-L2-IP and NAC-L2-802.1X. The chapter includes Cisco online reference so readers can research each device in details and get the most up-to-date list of all Cisco NAC-enabled devices.

The next 11 chapters cover installation, configuration and brief troubleshooting tips for each component: Cisco Trust Agent, VPN Concentrator, ASA and PIX firewall, Cisco Security Agents and even some brief introductions for third party vendor appliances such as QualysGuard Scanner for audit servers.

The following 3 chapters describe the deployment scenario for NAC in small, medium and large businesses. These chapters offer 3 interesting scenarios but all of them are just recaps of configuration mentioned in previous chapters.

The last 2 chapters explain the NAC deployment best practices and NAC monitoring using Cisco CsMARS. The best practices provide guidelines to roll this NAC deployment successfully by completing a readiness assessment of the current infrastructure, identifying responsible party, building lab and test plans as well as tuning and post deployment monitoring. Having experiences in deploying security projects, I believe that they should also add organization security policy which is approved by top management for NAC deployment best practices. This policy will help to remove any major obstacles encountered from end users.

I found this book very helpful in explaining Cisco NAC Framework. The book is definitely not for beginners as understanding of Cisco configuration and familiarity with Cisco products are needed to understand this.

NAC Framework is not for everyone. If you run a Cisco centric shop with the latest hardware and software, this NAC Framework is for you to build the self-defending network on top of your Cisco network and host based IPS, firewall, 802.1X enabled network access devices and others. If not, a much simpler Cisco Clean Access or other third party NAC appliance can probably do the job with less complicated configuration and upfront investment.

The book does not mention anything about Cisco NAC Framework integration or configuration with the new Microsoft NAP (Network Access Protection) although Cisco has officially provided the plan to do this in its web site.

In conclusion, the author has provided a very concise and understandable reading with the few number of pages provided. Each chapter goes straight to the topics, explains in an easy to follow manner, provides a lot of configuration examples and screenshots and closes with online references.

I liked this book a lot and certainly will recommend others to read this. I gave the book five out of five stars.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


0 of 3 people found the following review helpful:
5.0 out of 5 stars Installing, Deploying, and Troubleshooting the Cisco NAC, December 4, 2006
This review is from: Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting (Paperback)
It is generally believed that the biggest problems in network security come from the outside, but only sometimes is this true. The biggest loses tend to come from the inside. The people inside your company or organization know more about what there is to steal, how to create the most damage, and furthermore may feel that they have a direct reason to be angry and wanting to cause deliberate damage.

The second part of the problem is that todays organizations may have huge networks with many different areas to be protected from many different kinds of people, coming into the systems from many areas withing the organization including other facilities, suppliers, customers, remote salesmen, travelling executives, etc.

Cisco NAC Architecture and Design, the first volume in this series covers the protocols, design concepts, networking structure - in general the higher level preliminary setup of the NAC.

This volume covers the nuts and bolts of the actual installation and management of the Cisco NAC and the integration of the NAC into other Cisco components such as: VPN, ASA, PIX and more.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Inside This Book (learn more)
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
scanner appliance, posture validation, scripting interface, device name, network access devices, shared profile components, audit servers, network profile, enable password, network discovery, address interface, logging service, session type, station policy, network segment, administrative client, configure authentication, watchdog packets, connection entry, certificate file, trusted servers, system posture token, posture credentials, agentless host, show eou
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Cisco Secure, Cisco Trust Agent, Program Files, Cisco Systems, System Configuration, Review Questions, Configuring Layer, Total View, Cisco Security Agent, New York, Cisco Catalyst, Network Access Profiles, Medium-Size Enterprise, Failed Attempts, Log Output, Access Accept, Cisco Security Appliances, System Report, Send Events, Click the Add, Large Enterprise, Production Network, Internet Explorer, Altiris Agent, Small Business
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(65)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject