<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network congestion with NAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601475#M769508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Xavier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like a loop.&amp;nbsp; Check the switchports connected to the trusted and untrusted side of the CAS - I'm assuming you've got them set to trunks.&amp;nbsp; If so, make sure there are no shared VLANs between the two ports, and make sure the native VLAN on each is set to a different garbage VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, for a quick example.&amp;nbsp; Say you're mapping VLAN 500 to VLAN 5 and VLAN 600 to VLAN 6, and VLAN 998 and 999 are currently not being used on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;trusted side&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 998&lt;/P&gt;&lt;P&gt;switchport trunk allowed vlan 5, 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;untrusted side&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 999&lt;/P&gt;&lt;P&gt;switchport trunk allowed vlan 500, 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, you'll also want to allow the management VLAN on the trusted side, too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other thing - are you seeing any errors on the directly connected switch about those ports or the CAS MAC addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Lauren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Feb 2011 21:06:46 GMT</pubDate>
    <dc:creator>Lauren Sullivan</dc:creator>
    <dc:date>2011-02-08T21:06:46Z</dc:date>
    <item>
      <title>Network congestion with NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601474#M769477</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've deployed successfully in L2 OOB VG mode with PCs plugged in behing IP phones, however everytime I connect the NAC to the network the Internet slows down and the phone quality degrades. What could be the cause of this? An ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;~Xavier.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601474#M769477</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2020-02-21T12:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Network congestion with NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601475#M769508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Xavier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds like a loop.&amp;nbsp; Check the switchports connected to the trusted and untrusted side of the CAS - I'm assuming you've got them set to trunks.&amp;nbsp; If so, make sure there are no shared VLANs between the two ports, and make sure the native VLAN on each is set to a different garbage VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, for a quick example.&amp;nbsp; Say you're mapping VLAN 500 to VLAN 5 and VLAN 600 to VLAN 6, and VLAN 998 and 999 are currently not being used on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;trusted side&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 998&lt;/P&gt;&lt;P&gt;switchport trunk allowed vlan 5, 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;untrusted side&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 999&lt;/P&gt;&lt;P&gt;switchport trunk allowed vlan 500, 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, you'll also want to allow the management VLAN on the trusted side, too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other thing - are you seeing any errors on the directly connected switch about those ports or the CAS MAC addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Lauren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Feb 2011 21:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601475#M769508</guid>
      <dc:creator>Lauren Sullivan</dc:creator>
      <dc:date>2011-02-08T21:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Network congestion with NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601476#M769540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lauren,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have any common VLANs between the trusted and untrusted ports and I've configured everything on the CAS and CAM according to the best practices in the config guide so I suspect that it's a network problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the time I made the post, I haven't heard anyone complain about the Internet again so the problem &lt;STRONG&gt;&lt;EM&gt;seems&lt;/EM&gt;&lt;/STRONG&gt; to have resolved itself. If it happens again then I'll be sure to take a look at the switch and provide the information you asked for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help =]&lt;/P&gt;&lt;P&gt;Xavier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Feb 2011 22:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-congestion-with-nac/m-p/1601476#M769540</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-02-08T22:09:12Z</dc:date>
    </item>
  </channel>
</rss>

