<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with NAC real IP/ layer 3/ in-band in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161589#M783321</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm deploying a NAC realIP/in-band/layer3, users cannot ping untrusted interface e1 of NAC server, user has to pass core sw 6500 and FW before hitting e1 of NAC server. I have tried to set the gateway of this intterface e1 to itself (as Cisco document) and FW module, but in both cases, user still cannot ping e1.&lt;/P&gt;&lt;P&gt;Anyone can help me? Much appreciate your replying!&lt;/P&gt;&lt;P&gt;User -- Core sw 6500 -- FW module (on core sw) -- NAC server -- NAC manager&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:12:16 GMT</pubDate>
    <dc:creator>namnt2604</dc:creator>
    <dc:date>2020-02-21T11:12:16Z</dc:date>
    <item>
      <title>Problem with NAC real IP/ layer 3/ in-band</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161589#M783321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm deploying a NAC realIP/in-band/layer3, users cannot ping untrusted interface e1 of NAC server, user has to pass core sw 6500 and FW before hitting e1 of NAC server. I have tried to set the gateway of this intterface e1 to itself (as Cisco document) and FW module, but in both cases, user still cannot ping e1.&lt;/P&gt;&lt;P&gt;Anyone can help me? Much appreciate your replying!&lt;/P&gt;&lt;P&gt;User -- Core sw 6500 -- FW module (on core sw) -- NAC server -- NAC manager&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161589#M783321</guid>
      <dc:creator>namnt2604</dc:creator>
      <dc:date>2020-02-21T11:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC real IP/ layer 3/ in-band</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161590#M783322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have pinged e1 (untrusted) of NAC server already. I have set both managed subnet and static route, something different with Cisco document (Cisco NAC Appliance - Clean Access Server Installation and Configuration Guide, Release 4.1(3)), this document recommends to configure static route for layer 3 deployment, not managed subnet!&lt;/P&gt;&lt;P&gt;Anyone has documents to deploy this scenario, pls share it to me! Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2009 17:59:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161590#M783322</guid>
      <dc:creator>namnt2604</dc:creator>
      <dc:date>2009-01-10T17:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC real IP/ layer 3/ in-band</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161591#M783323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Managed subnets are for L2 deployments and Static routes are for L3 deployment.&amp;nbsp; Both can exist on a CAS but for a individual subnet, ti will be one or the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the client and CAS can see each others broadcast, its a L2.&amp;nbsp; If not, its a L3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Feb 2009 20:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-real-ip-layer-3-in-band/m-p/1161591#M783323</guid>
      <dc:creator>Daniel Laden</dc:creator>
      <dc:date>2009-02-01T20:35:17Z</dc:date>
    </item>
  </channel>
</rss>

