<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC Clean Access Authentication not doing anything in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593684#M5237</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have instaled an NAC solution, using oob with acl's.&lt;/P&gt;&lt;P&gt;When i get to the Clean Access Authentication page, using the right user and password, or an worng one, the page keeps showing up, requesting to authenticate and without any errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did this happened to anyone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:25:43 GMT</pubDate>
    <dc:creator>mamaral</dc:creator>
    <dc:date>2020-02-21T18:25:43Z</dc:date>
    <item>
      <title>NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593684#M5237</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have instaled an NAC solution, using oob with acl's.&lt;/P&gt;&lt;P&gt;When i get to the Clean Access Authentication page, using the right user and password, or an worng one, the page keeps showing up, requesting to authenticate and without any errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did this happened to anyone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593684#M5237</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2020-02-21T18:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593685#M5239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We may need to quickly check the OOB configuration too.&lt;BR /&gt;How are the settings under the following pages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device Management &amp;gt; Clean Access Servers &amp;gt; [your CAS] &amp;gt;&amp;nbsp; Network &amp;gt; IP&lt;BR /&gt;Device Management &amp;gt; Clean Access Servers &amp;gt; [your CAS] &amp;gt; Advanced &amp;gt; Managed Subnets&lt;BR /&gt;Device Management &amp;gt; Clean Access Servers &amp;gt; [your CAS] &amp;gt; Advanced &amp;gt; VLAN Mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, could you please confirm what is the subnet of the trusted vlan where the user should be getting an IP address when it connects?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Dec 2010 11:40:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593685#M5239</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2010-12-30T11:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593686#M5240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration is using Out-of-Band Real-IP Gateway, so there is no VLAN Mapping.&lt;/P&gt;&lt;P&gt;My cas ip is 10.16.214.65/24&lt;/P&gt;&lt;P&gt;The Managment network is 10.16.0.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Buy the way, i have anothor problem. The Untrusted interface as the ip 10.16.0.194. I added an route so that the cas wold talk to the authentication network of the client using the untrusted interface, but when i access the url &lt;A href="http://10.16.0.194"&gt;http://10.16.0.194&lt;/A&gt;, it redirects to the url 10.16.214.65. Because of the route added, it does not has access. I then have to fix the url back to the ip 10.16.0.194 and then i access the authentication page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Dec 2010 11:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593686#M5240</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-30T11:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593687#M5242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for all the details Miguel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would still be useful to have some initial details from the following screenshots:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device Management &amp;gt; Clean Access Servers &amp;gt; [your CAS] &amp;gt;&amp;nbsp; Network &amp;gt; IP&lt;BR /&gt;Device Management &amp;gt; Clean Access Servers &amp;gt; [your CAS] &amp;gt; Advanced &amp;gt; Managed Subnets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, for managed subnets, we should be configuring static routes on the L3 switch(es).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Dec 2010 13:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593687#M5242</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2010-12-30T13:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593688#M5244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Here is the screenshoots that you asked for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Dec 2010 15:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593688#M5244</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-30T15:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593689#M5245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration so far looks OK.&lt;BR /&gt;The only test I would suggest would be to keep the clients on a vlan/subnet different from the CAS untrusted IP's subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am telling this because usually we have the following:&lt;BR /&gt;1. Clients are being assigned to a trusted vlan/subnet, for which we have an IP address configured in the CAS as a managed subnet and assigned to that vlan.&lt;BR /&gt;2. In this case, clients are getting an IP on the same subnet as the untrusted interface of the CAS, which is not doing any kind of vlan tagging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a further test, you could for example keep the clients on a subnet that is not the same as the one for the CAS untrusted interface and add the corresponding managed subnet for that client vlan.&lt;BR /&gt;Alternatively, you could configure the CAS untrusted interface to tag traffic on the same vlan where clients are getting an IP, but this is usually more tricky.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This suggestion comes from the fact that what you are experiencing (clients continuously re-prompted for authentication) is often seen when the CAS is not configured for the proper managed subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing to verify is that the user being authenticated is not falling under the Unauthenticated Role.&lt;/P&gt;&lt;P&gt;This could happen for example when configuring an Authentication Provider with the default role as Unauthenticated and mapping rules: if mapping rules are not triggered correctly, the default Unauthenticated Role will be assigned and the client will keep getting the authentication prompt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If these further points didn't show any improvements, I would recommend to keep following this through a TAC Service Request:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ServiceRequestTool/create/launch.do"&gt;http://tools.cisco.com/ServiceRequestTool/create/launch.do&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 10:01:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593689#M5245</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2010-12-31T10:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593690#M5246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already had the clients network and vlan diferent from the managment vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Managment network : 10.16.0.0/24&lt;/P&gt;&lt;P&gt;CLients network : 10.39.120.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried tagging the packets from the management vlan, but the problem presists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 11:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593690#M5246</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-31T11:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593691#M5247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your clients are connecting in the 10.39.120.0/24 network, you'd then need to add an IP from this network in the managed subnets and link it to the client's vlan.&lt;/P&gt;&lt;P&gt;Also, you should make sure that there are static routes configured pointing to the managed subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 12:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593691#M5247</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2010-12-31T12:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593692#M5248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, the client is on an remote site. I cannot get there trought switching. I can only get there trought rounting,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 12:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593692#M5248</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-31T12:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Clean Access Authentication not doing anything</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593693#M5249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Miguel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Managed subnets may still be needed under the CAS configuration, even if clients are in L3 mode.&lt;/P&gt;&lt;P&gt;Apart from checking this, you may then need to have this issue followed through a TAC case as it looks like it will require some more troubleshooting:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ServiceRequestTool/create/launch.do"&gt;http://tools.cisco.com/ServiceRequestTool/create/launch.do&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 13:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-clean-access-authentication-not-doing-anything/m-p/1593693#M5249</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2010-12-31T13:08:58Z</dc:date>
    </item>
  </channel>
</rss>

