<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC deployment on Remote Branch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965905#M426270</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Without understanding your network this is a little challenging to troubleshoot what you are facing. All clients must be on the unauthenticated vlan for their traffic to be isolated till they are authorized by the manager, where snmp is used to reassign the clients on the appropriate vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Jul 2012 03:08:45 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-07-02T03:08:45Z</dc:date>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965901#M426262</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need help for deploying Cisco NAC on remote branch. i did all the necesary steps &amp;amp; configs but still no luck, On main site we have OOB-Real IP Gateway deployment. all the campus is deployed but for remote branch it is not working, we have inbetween firewalls &amp;amp; routers(offcorse) i have allowed IP any to NAC Server &amp;amp; Manager. but still no luck. &lt;/P&gt;&lt;P&gt;Is there any point i am missing do i have to do some extra config for remote branch ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965901#M426262</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2019-03-11T02:15:23Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965902#M426263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you give us a brief example of your current setup? Do you have PBR setup in order to force the users through the CAS during posture assessment, also do you have the static routes configured on the CAS that will route the traffic back to the clients? Also do you have the static routes configured so that if any response that needs to reach these clients are set to go through the trusted ip address of the CAS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can post a visio please do so, it will make it much easier to see what the path is for the clients and the CAS'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2012 05:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965902#M426263</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-01T05:53:26Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965903#M426266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry i cannot paste visio, i will giv you brief, All of the answers Yes i did.&lt;/P&gt;&lt;P&gt;1. NAC CAM &amp;amp; CAS both in Datacenter. &lt;/P&gt;&lt;P&gt;2. Our campus is big, so we have routing within Campus, and on each branch within campus we configured PBR on Branch Core Switches. whic is working fine for within the Campus.&lt;/P&gt;&lt;P&gt;3. The remote branch which is connected through IPVPN &amp;amp; Leased Lines, i have configured PBR on Core Switch as we did in Campus. Forced the Cient subnet to communicate only with CAS if in unauthenticated VLAN, and routed to CAS IP.&lt;/P&gt;&lt;P&gt;4. Did the Static route in CAS for this Branch Subnet.&lt;/P&gt;&lt;P&gt;5. Configured ACLs on ASA from any to CAS &amp;amp; CAM All IPs (Trust,Untrust,Virtual,real)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else required ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2012 06:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965903#M426266</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-01T06:18:51Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965904#M426268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it spossible the default vlan creating problem ??&amp;nbsp; that Branch is using Default VLAN, the Normal VLAN is default VLAN1 &amp;amp; have created Vlan 10 for un-authenticated users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jul 2012 06:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965904#M426268</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-01T06:37:53Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965905#M426270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Without understanding your network this is a little challenging to troubleshoot what you are facing. All clients must be on the unauthenticated vlan for their traffic to be isolated till they are authorized by the manager, where snmp is used to reassign the clients on the appropriate vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 03:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965905#M426270</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-02T03:08:45Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965906#M426272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;i can draw u rough diagram, diagram in detail will be not possible. wud tht be enough ?&lt;/P&gt;&lt;P&gt;l&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 04:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965906#M426272</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-02T04:20:05Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965907#M426274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to verify that your routing for the unauthenticated clients is symmetric and flows through the cas. You also want to configure the correct static routes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 04:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965907#M426274</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-02T04:29:04Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965908#M426275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;find below the rough diagram of this branch. i hope it helps ?&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/7/2/94275-NAC-Diagram-AMPUS-v-0.0.01.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 08:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965908#M426275</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-02T08:06:57Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965909#M426278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the remote branch are you forwarding all the tunneled traffic to the CAS virtual ip? Also with respect to static routes on the CAS are you pointing the untrusted clients subnets to the interface on the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you open a web page to google for example what happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2012 16:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965909#M426278</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-02T16:57:32Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965910#M426279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 From the remote branch are you forwarding all the tunneled traffic to the CAS virtual ip? &lt;/P&gt;&lt;P&gt;All traffic passing through tunnel, but un-authenticated traffic to CAS Virtual IP. through Policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 Also with respect to static routes on the CAS are you pointing the untrusted clients subnets to the interface on the firewall.&lt;/P&gt;&lt;P&gt;No, its been routed to SVI on our core switches. we have CAS &amp;amp; CAM in Seprate VLAN, so routing those traffic to This interface on CoreSW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its not connected to internet. we hav no connection to internet, so anyway when it is in authenticated VLAN we cannot do anything, though i can reach to CAS &amp;amp; CAM IPs from clients but it is not shifted to normal VLAN, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 04:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965910#M426279</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-03T04:32:32Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965911#M426282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically here is the traffic flow for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Unauthenticated clients are on 10.0.0.0/24, cas untrusted ip is 172.16.0.1/24 and trusted is 172.16.1.1/24&lt;/LI&gt;&lt;LI&gt;Unauthenticated traffic is routed to 172.16.0.1 via PBR for subnet 10.0.0.0/24&lt;/LI&gt;&lt;LI&gt;On your core switch you have a static route that points 10.0.0.0/24 to 172.16.1.1 (trusted CAS interface)&lt;/LI&gt;&lt;LI&gt;On your CAS configuration you have a static route that points 10.0.0.0/24 out the untrusted interface (over to the next hop which is usually the firewall interface).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes senses, if it doesnt then you will need to contact your partner or open a TAC case so they can take a better look at your topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 04:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965911#M426282</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-03T04:41:26Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965912#M426284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your core switch you have a static route that points 10.0.0.0/24 to 172.16.1.1 (trusted CAS interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You talking about the route in core switch of remote branch right???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i do not understand, first you are routing untrusted ip to untrusted interface of CAS then same traffic to trusted IP of CAS ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 05:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965912#M426284</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-03T05:17:55Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965913#M426286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I apologize for the confusion. The traffic needs to be routed to the untrusted interface, where the CAS will then inspect the traffic and then route the interface through to its trusted interface, where it will hit the core. Your static routes in the core need to send any responses for these untrusted subnets back through the trusted interface, where the routing table inside the CAS will then send the traffic back out to the subnet for these clients. This is because the CAS do not support routing protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that clears up the confusion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2012 14:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965913#M426286</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-03T14:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965914#M426288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Tarik for clearification.&lt;/P&gt;&lt;P&gt;These all have already been done, as i said from the Clients, either in Untrusted VLAN or trusted VLAN i can reach to CAS &amp;amp; CAM Ip addresses. All untrusted traffic for clients been forwarded to CAS untrusted IP using policy map in core of remote site. but still not working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 05:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965914#M426288</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-05T05:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965915#M426290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the issue you are having? Is the traffic being dropped at the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How are you able to verify that all the traffic is symmetrically routing through the Cas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What ports do you have opened for the unauthenticate role? In real ip mode all dns traffic isn't allowed unless you allow it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 06:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965915#M426290</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-05T06:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965916#M426292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue is&amp;nbsp; after installing the Agent on client, it switches to untrusted vlan, but NAC agent seems to be dead, no activity or not showing anything, may be not communicating with CAS or CAM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in firewall there is access-list for IP any to CAM &amp;amp; CAS. so it means no blocks from firewall. even CAM is able to Manage remote switches (changing vlan, assigning port profiles etc)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 09:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965916#M426292</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-05T09:49:15Z</dc:date>
    </item>
    <item>
      <title>NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965917#M426294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you generate the CAS certificate from the untrusted inteface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_admin.html#wp1136393"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_admin.html#wp1136393&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what is the discovery host for the agent set to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cam/m_agntd.html#wp1050646"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cam/m_agntd.html#wp1050646&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also do you have L3 support enabled on the CAS and also make sure that you do not have a managed subnet configured for these clients since that will break the L3 discovery mechanisms for these end users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post a few screenshots of your static routes that are defined on the CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 14:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965917#M426294</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-05T14:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965918#M426297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the above questions.&lt;/P&gt;&lt;P&gt;1. Yes CAS certificate generated.&lt;/P&gt;&lt;P&gt;2. Yes L3 Suppor tenabled.&lt;/P&gt;&lt;P&gt;3. discovery host is the CAM IP.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; &lt;EM&gt;make sure that you do not have a managed subnet configured for these clients &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;How &amp;amp; Where to verify this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. here is a Static route for remote branch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subnet 192.17.25.0/255.255.255.0&amp;nbsp; - &amp;gt; 192.17.8.19 (gateway)&amp;nbsp;&amp;nbsp; untrusted &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2012 04:51:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965918#M426297</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2012-07-08T04:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC deployment on Remote Branch</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965919#M426299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you generate the certificate on the CAS so it resolved to the &lt;SPAN style="text-decoration: underline;"&gt;untrusted&lt;/SPAN&gt; interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find the managed subnet configuration here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_addSrvr.html#wp1060206" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cas/s_addSrvr.html#wp1060206&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also keep in mind, any changes you make related to certificates or network settings, you must reboot the CAS for thoses changes to take into effect. Please reboot the CAS and see if that restore your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also wanted to verify how you were able to get the download page? The reason is that if you are not being automatically redirected to the page then most likely all the client traffic isnt being redirect either. For troubleshooting you may want to change the discovery host of the agent to the untrusted ip of the CAS and see if that causes the agent to pop up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2012 04:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-deployment-on-remote-branch/m-p/1965919#M426299</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-08T04:56:43Z</dc:date>
    </item>
  </channel>
</rss>

