===========================
First authorisation policy
===========================

.. Odpowiada 5. rodziałowi z https://docs.nacview.com/e/en/Step-by-Step/implementation-guide

Access policies in NACVIEW determine whether and under what conditions a device can be authorised to access the network. In general, they fall into two types:

- EAP authorisations - operate using the 802.1x supplicant
- MAC authorisations (also known as MAB, mac-authorisation-bypass) - use the MAC address of the end device

Policies operate on a **first-match** basis, that is, the first policy to which an authorisation attempt matches will be used to process that authorisation attempt, even if further down the list there is a more specific policy to which the authorisation could qualify. For this reason, it is recommended that the most specific policies are at the top of the list.

The default action, if no policy is matched, is to deny network access. Policies can use, among other things, local user accounts and local terminal devices as the primary access control element.

In order to create a basic access policy, a number of objects are required to be created in advance, which are the key elements of the policies. These are:

- User/Computer
- VLAN
- Network device

-----------------------
Creating a user account
-----------------------

To create a simple user account:

1. from the main system menu, select **Objects -> Identities**.
2. click **Add New Item**.
3. in the form, fill in the **Login** field.
4. change the **Valid for** field to blank.
5. confirm with **Save**.

The password will be generated automatically.

-------------------------------
Creating a local device account
-------------------------------

Follow the same procedure to create a local device (computer) account:

1. in the main menu, select **Objects -> Endpoints**.
2. click **Add New Item**.
3. in the form, complete the **Name** field and optionally the other device parameters
4. confirm with **Save**.

-------------------------
Adding networks and VLANs
-------------------------

The next step is to add the subnets in which the network devices operate and the subnets for which we will apply access policies to NACVIEW.

Adding an IPv4 subnet
=====================

1. in the main menu, select **IPv4 subnets** in the **Networks** section.
2. click **Add New Item**.
3. give the subnet a name, its address (e.g. 10.10.1.0), mask and colour identifier
4. configure DHCP:
   - deselect **DHCP enabled** if you are using an external DHCP server and click **Save**.
   - if you want to configure a DHCP server for this subnet, leave the option enabled and set the desired IP address lease time
5. Click **Save and exit**.

Associating a subnet with a VLAN
================================

1. select **VLAN** in the **Networks** section.
2. click **Add new entry**.
3. give the VLAN a name and its TAG
4. select the subnet and colour ID
5. click **Save**.

Adding a network device
-----------------------

Setting up credentials
======================

In NACVIEW, it is possible to monitor network devices via SNMP and to access the CLI of the device directly from the NACVIEW GUI.

To configure credentials:

1. Go to **Administration → Device credentials**.

* add a new entry
* enter a name to be displayed in NACVIEW

Enter login and password
Add additional options if necessary:

* CLI
* SNMPv3

Change of Authorization (CoA) is a mechanism used in networks based on RADIUS and TACACS+ protocols to dynamically change a user's authorization without having to log in again.

.. TIP::

    A good practice before adding network devices is to create a group of objects called, for example, ‘network devices’. This will make it easier to apply policies to more switches/APs. You can create the group by going to **Administration->Object Groups**.

Procedure for adding a network device:
======================================

1. in the main menu, go to **Network Devices** under **Networks**.
2. click **Add New Item** and fill in the form:
   - Select the device model (e.g. ‘Network device’ for a switch)
   - Enter the number of physical ports on the switch, name and IP address
   - Click **Change/set password** to configure RADIUS passwords
   - Enter the RADIUS key set on the switch and repeat the password
   - If you have created a group for network devices, select it from the **Object Groups** list.
3. click **Save**. On the next **Privilege Settings** screen, we have the option to select the login details for the switch for the various connection protocols
4. then **Further** to proceed to the summary
5. click **Monitoring**, check the SNMP protocol settings and save

CoA configuration (if the device supports it):
==============================================

1. click **Edit Disconnect**.
2. fill in the port number (default 3799)
3. enter the RADIUS password
4. select the manufacturer name of the switch
5. click **Save** - the switch has been added

-------------------------
Creating an access policy
-------------------------

1. select **Access Policies** in the **Configuration** section of the main menu.
2. click **Add a rule**.
3. name the policy
4. select the authentication method (e.g. MAC) and **Access to VLAN** action
5. indicate the VLAN and:
   - **Endpoint** - select MAC address or address group.
   - **Network devices** - select a device or group of devices.
6. click **Save** and then the yellow button **Install list**.

.. NOTE::
    Remember to install the access policy list when you make changes or add a policy. Until a new list is installed, network access is governed by the previous installed list.
