Security

 View Only
  • 1.  Any mechanism to identify if NAC-related configuration is removed from NAD(switch) device

    Posted Jun 13, 2025 06:17 AM

    Hello

    Is there any mechanism we can apply to automatically identify if RADIUS/NAC configuration has been removed from a switch?

    As of now, we can only know this:

    1. If incoming RADIUS requests stops from a particular switch which we only know at the later time OR
    2. Through configured SPLUNK alert if there are any alternation in switch configuration


  • 2.  RE: Any mechanism to identify if NAC-related configuration is removed from NAD(switch) device

    Posted Jun 13, 2025 10:40 AM

    There is an option in ClearPass Insight to configure alerts via email or SMS. I never tried, but may help to resolve your issue.



    ------------------------------
    Harendra | ACEX165 | ACEP | CWDP | CWSP
    If you find my answer useful, consider giving kudos and/or mark it as the solution.
    ------------------------------



  • 3.  RE: Any mechanism to identify if NAC-related configuration is removed from NAD(switch) device

    Posted Jun 14, 2025 02:59 AM

    Can your monitoring system send test authentications and evaluate the responses? And send an alarm if no response is received?



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 4.  RE: Any mechanism to identify if NAC-related configuration is removed from NAD(switch) device

    Posted Jun 15, 2025 05:01 AM

    An alternative approach would be to use TACACS+ to monitor for any changes within the switches configuration… 




  • 5.  RE: Any mechanism to identify if NAC-related configuration is removed from NAD(switch) device

    Posted Jun 16, 2025 11:17 PM

    We do have an alert configured in SPUNK when any modification are done at switch level.