<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Workstations Stuck in NAC Authentication VLAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2079998#M177227</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently running NAC 4.8 in layer 3 real IP gateway mode with Active Directory single sign on. I recently renewed our CAS server certificate with Verisign and have since had some PC's which appear to remain in the NAC authentication VLAN after what looks like a successful authentication on the CAM. The NAC client currently in production running on Windows 7 is version 4.8.1.5. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CAM logs report the user as successfully logged in and an SNMP trap is pushed to the switch to execute the VLAN change however the VLAN is not changed in the switch running configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before I start on my debugging journey I thought I would ask if anyone may have experienced this problem in the past and if so, how was it resolved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any assistance.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mark&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:59:25 GMT</pubDate>
    <dc:creator>premiers-maps</dc:creator>
    <dc:date>2019-03-11T02:59:25Z</dc:date>
    <item>
      <title>Workstations Stuck in NAC Authentication VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2079998#M177227</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently running NAC 4.8 in layer 3 real IP gateway mode with Active Directory single sign on. I recently renewed our CAS server certificate with Verisign and have since had some PC's which appear to remain in the NAC authentication VLAN after what looks like a successful authentication on the CAM. The NAC client currently in production running on Windows 7 is version 4.8.1.5. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CAM logs report the user as successfully logged in and an SNMP trap is pushed to the switch to execute the VLAN change however the VLAN is not changed in the switch running configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before I start on my debugging journey I thought I would ask if anyone may have experienced this problem in the past and if so, how was it resolved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any assistance.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mark&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2079998#M177227</guid>
      <dc:creator>premiers-maps</dc:creator>
      <dc:date>2019-03-11T02:59:25Z</dc:date>
    </item>
    <item>
      <title>Workstations Stuck in NAC Authentication VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2079999#M177269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you doublecheck the certs and make sure the manager cert didnt somehow get imported to the CAS? I have seen issues with AD when the wrong cert is installed the CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 06:59:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2079999#M177269</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-01-18T06:59:49Z</dc:date>
    </item>
    <item>
      <title>Workstations Stuck in NAC Authentication VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2080000#M177302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This problem has now been resolved. It was a combination of two issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue 1.&lt;/P&gt;&lt;P&gt;After further investigation it appeared as though the issue was related to the SNMP interface index being out of sync between the CAM and our access switches. The command,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp ifmib ifindex persist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;was missing from one particular switch. Cisco TAC recommended that I remove the switch from the CAM device list, enter the SNMP persist command above then re-enter the switch into the CAM. I did this and it broke all NAC access on this particular switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue 2.&lt;/P&gt;&lt;P&gt;Once the above was completed NAC broke on that particular switch with the following NAC client error displayed on the workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAC Invalid switch configuration-OOB Error:OOB client "mac/ip" not found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Somehow, the snmptrapd daemon on the CAM had stopped listening for incoming traps so the CAM was unaware of the new workstation MAC. Via an SSH console session on the CAM, check that the snmptrapd daemon is listening on UDP port 162 as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;netstat -an | grep 162&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output should include the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;udp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 0.0.0.0:162&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the CAM via the SSH console, snmpd and snmptrapd were restarted as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/etc/init.d/snmpd restart&lt;/P&gt;&lt;P&gt;/etc/init.d/snmptrapd restart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log file nac_manager.log was also used to help with this process located at &lt;/P&gt;&lt;P&gt;/perfigo/control/tomcat/logs/ &lt;/P&gt;&lt;P&gt;Logging was turned up to the TRACE setting via the CAM web management interface under &lt;/P&gt;&lt;P&gt;Administration -&amp;gt; CCA Manager -&amp;gt; Support Logs&lt;/P&gt;&lt;P&gt;(Dont forget to turn your logging back down when done)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps others who may run into this same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2 style="background-color: #ffffff; border-collapse: collapse; font-size: 2em; list-style: none; margin: 0px 100px 0px 0px; font-weight: normal; width: auto; font-family: Arial, verdana, sans-serif;"&gt;&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 00:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workstations-stuck-in-nac-authentication-vlan/m-p/2080000#M177302</guid>
      <dc:creator>premiers-maps</dc:creator>
      <dc:date>2013-02-01T00:33:17Z</dc:date>
    </item>
  </channel>
</rss>

