<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco NAC Agent pop up twice (Login twice) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-nac-agent-pop-up-twice-login-twice/m-p/1637270#M758658</link>
    <description>&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Dear All:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;We have NAC&amp;nbsp; version 4.8.0 and the agent version is 4.8.1.5. The deployment type is Out-Of-band virtual gateway. Windows SSO is enable and working as a champion but the problem is when the agent successfully login the users the CAM logs out it after a while (NAC agent pop up again) I found that the switch port is changed back to the unauthenticated VLAN by the CAM and then to the access VLAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;The host under testing: IP 10.30.8.207, MAC 78:E7:D1: CD: D8:8A and the switch port is 10048 (FA0/48)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;The log for kicking out the user is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;2011-03-09 13:15:30.450 +0300 [Timer-199783] DEBUG c.p.wlan.web.admin.DelayedOobLogoutInfoManager&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- DLIM: delete DLI for 10.30.8.207 from CAS user_key='10.30.8.207_VTMJDKPIR41ABQLT'&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;2011-03-09 13:15:30.451 +0300 [Thread-334356] DEBUG c.p.wlan.web.admin.DelayedOobLogoutInfoManager&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- DLIM: userip = 10.30.8.207maclist = 78:E7:D1:CD:D8:8Auserkey = user_key='10.30.8.207_VTMJDKPIR41ABQLT'&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;And the log for login is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;2011-03-09 13:15:57.335 +0300 [TP-Processor24] TRACE com.perfigo.wlan.web.sms.SnmpTimerTask&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- SnmpTimerTask com.perfigo.wlan.web.sms.task.SwitchCertifiedTask id=2004989 is created: set port [10048] to Access VLAN [308] on switch [10.1.40.14] for [78:E7:D1:CD:D8:8A&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I don’t know the meaning of “DLIM: delete DLI for 10.30.8.207 from CAS” and why this is happening. Would you please help?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Attached log file.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:16:54 GMT</pubDate>
    <dc:creator>abu_khair</dc:creator>
    <dc:date>2020-02-21T12:16:54Z</dc:date>
    <item>
      <title>Cisco NAC Agent pop up twice (Login twice)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-agent-pop-up-twice-login-twice/m-p/1637270#M758658</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Dear All:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;We have NAC&amp;nbsp; version 4.8.0 and the agent version is 4.8.1.5. The deployment type is Out-Of-band virtual gateway. Windows SSO is enable and working as a champion but the problem is when the agent successfully login the users the CAM logs out it after a while (NAC agent pop up again) I found that the switch port is changed back to the unauthenticated VLAN by the CAM and then to the access VLAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;The host under testing: IP 10.30.8.207, MAC 78:E7:D1: CD: D8:8A and the switch port is 10048 (FA0/48)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;The log for kicking out the user is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;2011-03-09 13:15:30.450 +0300 [Timer-199783] DEBUG c.p.wlan.web.admin.DelayedOobLogoutInfoManager&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- DLIM: delete DLI for 10.30.8.207 from CAS user_key='10.30.8.207_VTMJDKPIR41ABQLT'&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;2011-03-09 13:15:30.451 +0300 [Thread-334356] DEBUG c.p.wlan.web.admin.DelayedOobLogoutInfoManager&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- DLIM: userip = 10.30.8.207maclist = 78:E7:D1:CD:D8:8Auserkey = user_key='10.30.8.207_VTMJDKPIR41ABQLT'&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;And the log for login is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;2011-03-09 13:15:57.335 +0300 [TP-Processor24] TRACE com.perfigo.wlan.web.sms.SnmpTimerTask&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;- SnmpTimerTask com.perfigo.wlan.web.sms.task.SwitchCertifiedTask id=2004989 is created: set port [10048] to Access VLAN [308] on switch [10.1.40.14] for [78:E7:D1:CD:D8:8A&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I don’t know the meaning of “DLIM: delete DLI for 10.30.8.207 from CAS” and why this is happening. Would you please help?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Attached log file.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-agent-pop-up-twice-login-twice/m-p/1637270#M758658</guid>
      <dc:creator>abu_khair</dc:creator>
      <dc:date>2020-02-21T12:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC Agent pop up twice (Login twice)</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-agent-pop-up-twice-login-twice/m-p/1637271#M758659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe my answer will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I had a similar problem with my Out-of-Band Real-IP-Gateway deployment. The reason was that NAC agent was still commnicating with untrusted interface of the NAC server, after logging in with Windows AD login/password. And of course, NAC agent pop up again, after client successfully looged in with active directory login\password, and his computer were transferring from "auth" vlan to "access" vlan.&lt;/P&gt;&lt;P&gt;Cisco experts says, that it's better to brake communication between NAC agent and NAC server, if the client machine is in access vlan. You can implement, for example, an access-list for "access" vlan. The goal of that access-list is to deny all packets destined for NAC server, and permit all other packets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2011 18:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-agent-pop-up-twice-login-twice/m-p/1637271#M758659</guid>
      <dc:creator>Petr Nagernyuk</dc:creator>
      <dc:date>2011-03-13T18:40:04Z</dc:date>
    </item>
  </channel>
</rss>

