<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change VLAN only if check fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083927#M146639</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anybody know if it's possible to change the Client only then to the Auth VLAN if the check fails? We want to authenticated the pc by the MAC-Adressfilter and than the user with the NAC-Agent. But the pc should be always in the default Access-Vlan and only change to Auth-Vlan if the NAC-Agent check fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetings,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:51:14 GMT</pubDate>
    <dc:creator>david_austria</dc:creator>
    <dc:date>2019-03-11T02:51:14Z</dc:date>
    <item>
      <title>Change VLAN only if check fails</title>
      <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083927#M146639</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anybody know if it's possible to change the Client only then to the Auth VLAN if the check fails? We want to authenticated the pc by the MAC-Adressfilter and than the user with the NAC-Agent. But the pc should be always in the default Access-Vlan and only change to Auth-Vlan if the NAC-Agent check fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greetings,&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083927#M146639</guid>
      <dc:creator>david_austria</dc:creator>
      <dc:date>2019-03-11T02:51:14Z</dc:date>
    </item>
    <item>
      <title>Change VLAN only if check fails</title>
      <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083928#M146649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try playing with &lt;/P&gt;&lt;P&gt;Authorization&lt;/P&gt;&lt;P&gt;Session:PostureStatus = compliant/NonCompliant/Unknown [then] = AUTH_VLAN &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 19:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083928#M146649</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-12-04T19:24:12Z</dc:date>
    </item>
    <item>
      <title>Change VLAN only if check fails</title>
      <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083929#M146670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All checks?&amp;nbsp; Some checks?&amp;nbsp; One Check?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If all, then you are looking to use a AUTHZ policy for something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Fail-Check&lt;/SPAN&gt;&lt;STRONG&gt; if&lt;/STRONG&gt; &lt;SPAN style="text-decoration: underline;"&gt;Session:PostureStatus EQUALS NonCompliant&lt;/SPAN&gt; &lt;STRONG&gt;then &lt;/STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;NonCompliantVLAN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/7/2/117270-non-compliant-example.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I understand you want your machines to all pass by MAB and not 802.1X?&amp;nbsp; Or are you referencing the MAC as part of an 802.1X AUTHC rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your switch, you might want to consider how to handle the access policy if the authenticaiton server (RADIUS/ISE) is unavailable/dead...&amp;nbsp; Just to be thourough. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" value="" /&gt;&lt;PARAM name="counter" value="" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 21:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083929#M146670</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-04T21:07:37Z</dc:date>
    </item>
    <item>
      <title>Change VLAN only if check fails</title>
      <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083930#M146696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, first we want to pass the PC by the MAC-Address and after the User is logged on, we want to check the PC for anti virus software and so on. And only if the check&amp;nbsp; with the NAC-Agent fails, the PC should come into the Auth-VLAN. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 05:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083930#M146696</guid>
      <dc:creator>david_austria</dc:creator>
      <dc:date>2012-12-05T05:51:08Z</dc:date>
    </item>
    <item>
      <title>Change VLAN only if check fails</title>
      <link>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083931#M146720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As me and JW.SL9 (who was more thourough) stated you can do that if the status of that client is non compliant then client should go to Auth-Vlan, because if they fail to pass NAC-Agent checks and/or NAC-Agent itself fails they will not be compliant(allowed access) and will fall in Auth-Vlan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 14:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-vlan-only-if-check-fails/m-p/2083931#M146720</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-12-05T14:44:23Z</dc:date>
    </item>
  </channel>
</rss>

