Thursday, September 25, 2008

Getting the NAC of It

I've been told that everyone might like a little plain English explanation of the Network Access Control (NAC) project being rolled out this week by OIT. Now, I'm no authority on this, but as I understand it, the NAC basically authenticates you on the network, registering your computer's MAC address and verifying that you are who you say you are when you log in to any GPC-owned PC.

In conjunction with this, OIT is installing a little program called the "Cisco Clean Access Agent." It will run in the background and renew your information once your credentials time out. You may have seen this pop up on your desktop and in your system tray recently. The icon is a little green square with a key inside.

If the NAC has been rolled out on your campus, but the PC you are trying to use does not have the Cisco Clean Access Agent yet, you will have to open a browser window and log in there (using the same login and password that you do for email) in order to gain access to the network.

All this is intended to prevent non-GPC folks from hopping on the network without authentication and making mischief. It also allows the network guys in OIT to know what port each user is logging in through. Basically, it's a security measure, and a very good one I'm sure. For the libraries though, it presents the problem of how to provide computer access to community users lacking GPC credentials. I haven't heard a solution on that yet, but I'm sure OIT will work something out for us. Also, I have heard that the initial roll-out on Decatur campus has been a little bumpy, so brace yourselves for students not being able to log into the library PCs, and report these problems to the Help Desk as they arise.

That's the extent of my knowledge, but I'll happily contact OIT for further clarification if anyone wants it.

2 comments:

Eileen Kramer said...

To what URL does a person who does not have Cisco Clean Agent (the turquoise icon with the key inside it) point their browser since their default home page is probably not the login page? So far the page OIT suggested just leads to the Getmylogin page we use to look up student userids and passwords.

Tessa Minchew said...

I wasn't under the impression that you had to point the browser to a particular URL. Here's what the genmail from OIT said.


Should the agent not be installed:

1.) Employees will need to open a web browser (Internet Explorer, Firefox, etc) before network access will be granted.

2.) Upon opening the browser, the employee will be automatically redirected to the NAC login page.

3.) Select the correct provider, GPC Faculty-Staff.

4.) Use the same username/password that you use to login to your GPC computer or email.


Now, if it isn't working that way on your computer, call the Help Desk (#3460) and they should be able to get you fixed up.