<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network drops after NAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071038#M775452</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get the chance to see the problem on a PC while it's occurring? Does the CCA agent keep refreshing its IP? Check to see if the PC has the IP from the user or auth vlan. If CCA Agent keeps on re-authenticating and goes in loop. You might want to block UDP 8905 and 8906 from the user vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give us more info in order to determine what is wrong. Find out what exactly happens on the user level is critical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Sep 2008 15:04:21 GMT</pubDate>
    <dc:creator>felixjai</dc:creator>
    <dc:date>2008-09-17T15:04:21Z</dc:date>
    <item>
      <title>Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071033#M775447</link>
      <description>&lt;P&gt;After implementation of NAC OOB VG, users are complaining random network loss. Any guess?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071033#M775447</guid>
      <dc:creator>hemen.goradia</dc:creator>
      <dc:date>2020-02-21T10:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071034#M775448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you getting any error messages?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2008 13:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071034#M775448</guid>
      <dc:creator>hadbou</dc:creator>
      <dc:date>2008-08-19T13:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071035#M775449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No errors "Destination Host Unreachable"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hemen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Aug 2008 14:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071035#M775449</guid>
      <dc:creator>hemen.goradia</dc:creator>
      <dc:date>2008-08-19T14:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071036#M775450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using Clean Access Agent v 4.1.3.0 upgrade to 4.1.3.1 and the problem will be resolved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 15:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071036#M775450</guid>
      <dc:creator>dgold</dc:creator>
      <dc:date>2008-09-15T15:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071037#M775451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After upgrade also it does not work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hemen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 15:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071037#M775451</guid>
      <dc:creator>hemen.goradia</dc:creator>
      <dc:date>2008-09-15T15:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071038#M775452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get the chance to see the problem on a PC while it's occurring? Does the CCA agent keep refreshing its IP? Check to see if the PC has the IP from the user or auth vlan. If CCA Agent keeps on re-authenticating and goes in loop. You might want to block UDP 8905 and 8906 from the user vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give us more info in order to determine what is wrong. Find out what exactly happens on the user level is critical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 15:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071038#M775452</guid>
      <dc:creator>felixjai</dc:creator>
      <dc:date>2008-09-17T15:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071039#M775453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i checked PC is not refreshing IP and it stays in user vlan always. I kept ping log for a day and it shows "destination host unreachable in between"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hemen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 16:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071039#M775453</guid>
      <dc:creator>hemen.goradia</dc:creator>
      <dc:date>2008-09-17T16:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071040#M775454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the PC holds the user vlan IP address but gets the "destination host unreachable" ping error, the CAM server might have put the port for the PC back to auth vlan due to some reason. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, you can do a dhcp release and renew on the PC. Or simply restart the PC. It should get an IP from the auth vlan and go through the CCA authentication and posture asessment. Then you will be good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing you can check to see why the port for the PC went back to auth vlan. &lt;/P&gt;&lt;P&gt;Go to Device Management -&amp;gt; Clean Access -&amp;gt; Certified Devices -&amp;gt; Timer&lt;/P&gt;&lt;P&gt;If you have a scheduled cleanup rule to clear your certified devices. Your PCs might be put back to auth vlan. Just edit the rule, and check the box for "Keep Online Users".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the above is not the cause, find out if there is any unexpected reboot on your access switch assuming your PC is connected to the port behind an IP phone. Because your PC didn't lose network connection, but the access layer switch detects a new MAC notification and triggers to switch to auth vlan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 17:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071040#M775454</guid>
      <dc:creator>felixjai</dc:creator>
      <dc:date>2008-09-17T17:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071041#M775455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried all above excercises. And this issue over the network and very frequest so to restart systems fessible solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is not timer set on certified devices in CAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we don't have IP phone in network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hemen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2008 17:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071041#M775455</guid>
      <dc:creator>hemen.goradia</dc:creator>
      <dc:date>2008-09-17T17:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Network drops after NAC</title>
      <link>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071042#M775457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more thing you can check-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to CAM, check Monitoring -&amp;gt; Event Logs -&amp;gt; Log Viewer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add filter for text and set "contains" and put the IP address or the username of one of the PCs that has problem. See what kind of events have been happening to the PC. This should give you some ideas of what's going on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 01:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-drops-after-nac/m-p/1071042#M775457</guid>
      <dc:creator>felixjai</dc:creator>
      <dc:date>2008-09-18T01:54:43Z</dc:date>
    </item>
  </channel>
</rss>

