<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC - Global Device Filter in OOB deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812247#M222614</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Was this ever resolved?&lt;/P&gt;&lt;P&gt;We are having issues as well and you can see in the above log the mac-address value is NULL. The NAC wont operate without knowing the mac-address of the client on the switchport.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Apr 2012 12:02:40 GMT</pubDate>
    <dc:creator>mgraham50</dc:creator>
    <dc:date>2012-04-11T12:02:40Z</dc:date>
    <item>
      <title>NAC - Global Device Filter in OOB deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812244#M222478</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some help would be appriciated. I'm trying to bypass authentication/posture assessment for a printer in an OOB NAC deployment (CAM/CAS &lt;SPAN style="font-size: 8pt;"&gt;Version 4.9.0&lt;/SPAN&gt;&lt;BR /&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added the device MAC address in the global device filter, with the ALLOW access type set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Change VLAN according to global device filter list" option is checked in the port profile set on the corresponding switch port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the device ends up in the Auth VLAN every time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812244#M222478</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2019-03-11T01:44:22Z</dc:date>
    </item>
    <item>
      <title>NAC - Global Device Filter in OOB deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812245#M222524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you managing the switch port in the CAM database and do you have a port profile assigned to the port? Also check your snmp settings, one more thing...what do you see in the event logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also set the OOB logging to debug and shut and no shut the port, check the nac manager.log file after downloading the logs and see what the logs show.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jan 2012 00:59:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812245#M222524</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-01-22T00:59:17Z</dc:date>
    </item>
    <item>
      <title>NAC - Global Device Filter in OOB deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812246#M222573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the port is managed and a test profile named 'Printer_test' is currently assigned to the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I see in the nac manager.log file (level set to debug) after the port comes up: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.219 +0100&amp;nbsp;&amp;nbsp; DefaultUDPTransportMapping_0.0.0.0/162 DEBUG com.perfigo.wlan.web.sms.SnmpTrapListener&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Received trap event SwitchTrapEvent [type=LINK_UP switch_ip=10.1.0.32 mac=null port=10035 dot1dBasePort=0 vlan=0]&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.219 +0100&amp;nbsp;&amp;nbsp; DefaultUDPTransportMapping_0.0.0.0/162 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SnmpRunnable com.perfigo.wlan.web.sms.task.SwitchNotificationTask id=5091348 is created: SwitchTrapEvent [type=LINK_UP switch_ip=10.1.0.32 mac=null port=10035 dot1dBasePort=0 vlan=0]&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.219 +0100&amp;nbsp;&amp;nbsp; DefaultUDPTransportMapping_0.0.0.0/162 DEBUG com.perfigo.wlan.web.sms.SnmpManager&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Task from device 10.1.0.32 submitted with task id 5091348&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.219 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SnmpRunnable com.perfigo.wlan.web.sms.task.SwitchNotificationTask id=5091348 starts run() after 0ms.&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.219 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Resolved PortProfile Switch Port Profile [ id=4 name='Printer_test' type='normal' auth_vlan=100 access_vlan=15 idle_vlan=-1 attributes=635 vlan_profile_id=0 description='' reserved='' ] from event SwitchTrapEvent [type=LINK_UP switch_ip=10.1.0.32 mac=null port=10035 dot1dBasePort=0 vlan=0]&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.220 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 INFO&amp;nbsp; com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Received SNMP LINK_UP trap, but switch 10.1.0.32 is not using LINK_UP&amp;nbsp; for task 5091348&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.220 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Trap does not need to processed: SwitchTrapEvent [type=LINK_UP switch_ip=10.1.0.32 mac=null port=10035 dot1dBasePort=0 vlan=0] for task 5091348&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.220 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SnmpRunnable com.perfigo.wlan.web.sms.task.SwitchNotificationTask id=5091348 ends run() after 1ms.&lt;/P&gt;&lt;P&gt;2012-01-24 14:41:08.220 +0100&amp;nbsp;&amp;nbsp; pool-3-thread-16 DEBUG com.perfigo.wlan.web.sms.SnmpRunnable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - SnmpRunnable com.perfigo.wlan.web.sms.task.SwitchNotificationTask id=5091348 finishes after 1ms.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 14:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812246#M222573</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2012-01-24T14:02:43Z</dc:date>
    </item>
    <item>
      <title>NAC - Global Device Filter in OOB deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812247#M222614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Was this ever resolved?&lt;/P&gt;&lt;P&gt;We are having issues as well and you can see in the above log the mac-address value is NULL. The NAC wont operate without knowing the mac-address of the client on the switchport.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2012 12:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-global-device-filter-in-oob-deployment/m-p/1812247#M222614</guid>
      <dc:creator>mgraham50</dc:creator>
      <dc:date>2012-04-11T12:02:40Z</dc:date>
    </item>
  </channel>
</rss>

