First authorisation policy🔗

Access policies in NACVIEW determine whether and under what conditions a device can be authorised to access the network. In general, they fall into two types:

  • EAP authorisations - operate using the 802.1x supplicant

  • MAC authorisations (also known as MAB, mac-authorisation-bypass) - use the MAC address of the end device

Policies operate on a first-match basis, that is, the first policy to which an authorisation attempt matches will be used to process that authorisation attempt, even if further down the list there is a more specific policy to which the authorisation could qualify. For this reason, it is recommended that the most specific policies are at the top of the list.

The default action, if no policy is matched, is to deny network access. Policies can use, among other things, local user accounts and local terminal devices as the primary access control element.

In order to create a basic access policy, a number of objects are required to be created in advance, which are the key elements of the policies. These are:

  • User/Computer

  • VLAN

  • Network device

Creating a user account🔗

To create a simple user account:

  1. from the main system menu, select Objects -> Identities.

  2. click Add New Item.

  3. in the form, fill in the Login field.

  4. change the Valid for field to blank.

  5. confirm with Save.

The password will be generated automatically.

Creating a local device account🔗

Follow the same procedure to create a local device (computer) account:

  1. in the main menu, select Objects -> Endpoints.

  2. click Add New Item.

  3. in the form, complete the Name field and optionally the other device parameters

  4. confirm with Save.

Adding networks and VLANs🔗

The next step is to add the subnets in which the network devices operate and the subnets for which we will apply access policies to NACVIEW.

Adding an IPv4 subnet🔗

  1. in the main menu, select IPv4 subnets in the Networks section.

  2. click Add New Item.

  3. give the subnet a name, its address (e.g. 10.10.1.0), mask and colour identifier

  4. configure DHCP: - deselect DHCP enabled if you are using an external DHCP server and click Save. - if you want to configure a DHCP server for this subnet, leave the option enabled and set the desired IP address lease time

  5. Click Save and exit.

Associating a subnet with a VLAN🔗

  1. select VLAN in the Networks section.

  2. click Add new entry.

  3. give the VLAN a name and its TAG

  4. select the subnet and colour ID

  5. click Save.

Adding a network device🔗

Setting up credentials🔗

In NACVIEW, it is possible to monitor network devices via SNMP and to access the CLI of the device directly from the NACVIEW GUI.

To configure credentials:

  1. Go to Administration → Device credentials.

  • add a new entry

  • enter a name to be displayed in NACVIEW

Enter login and password Add additional options if necessary:

  • CLI

  • SNMPv3

Change of Authorization (CoA) is a mechanism used in networks based on RADIUS and TACACS+ protocols to dynamically change a user’s authorization without having to log in again.

Tip

A good practice before adding network devices is to create a group of objects called, for example, ‘network devices’. This will make it easier to apply policies to more switches/APs. You can create the group by going to Administration->Object Groups.

Procedure for adding a network device:🔗

  1. in the main menu, go to Network Devices under Networks.

  2. click Add New Item and fill in the form: - Select the device model (e.g. ‘Network device’ for a switch) - Enter the number of physical ports on the switch, name and IP address - Click Change/set password to configure RADIUS passwords - Enter the RADIUS key set on the switch and repeat the password - If you have created a group for network devices, select it from the Object Groups list.

  3. click Save. On the next Privilege Settings screen, we have the option to select the login details for the switch for the various connection protocols

  4. then Further to proceed to the summary

  5. click Monitoring, check the SNMP protocol settings and save

CoA configuration (if the device supports it):🔗

  1. click Edit Disconnect.

  2. fill in the port number (default 3799)

  3. enter the RADIUS password

  4. select the manufacturer name of the switch

  5. click Save - the switch has been added

Creating an access policy🔗

  1. select Access Policies in the Configuration section of the main menu.

  2. click Add a rule.

  3. name the policy

  4. select the authentication method (e.g. MAC) and Access to VLAN action

  5. indicate the VLAN and: - Endpoint - select MAC address or address group. - Network devices - select a device or group of devices.

  6. click Save and then the yellow button Install list.

Note

Remember to install the access policy list when you make changes or add a policy. Until a new list is installed, network access is governed by the previous installed list.