<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC OOB problem - moving users between ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434794#M792657</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. I'm hitting the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "mac-address-table notification mac-move" works fine only when the user connect and disconnects from ports on the same switch. But it doesn't work if I disconnect from switch "A" and connects to switch "B". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know any solution to this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Sep 2012 20:14:48 GMT</pubDate>
    <dc:creator>Eduardo Aliaga</dc:creator>
    <dc:date>2012-09-04T20:14:48Z</dc:date>
    <item>
      <title>NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434786#M792605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem with an OOB deployment I am currently working on: when I move an authenticated OOB client from one switch to another, it remains stuck in the auth VLAN. It seems that NAC doesn't detect the new port correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I did to replicate the issue, in detail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) A computer is connected to port 'a' on switch 'A' (A[a]). The port is automatically changed to auth VLAN and authentication and posture assessment are performed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The computer passes both, and the port is changed back to the designated Access VLAN. OOB user appears in the Online Users list, and the computer is added to the Discovered (Wired) Clients list. All the detailed information on both pages is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) The computer is disconnected. OOB user is removed from the Online Users list, but the computer remains in the Discovered Clients list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) The computer is connected to port 'b' on switch 'B' (B[b]). It is automatically changed to auth VLAN and authentication and posture assessment passes successfully one more time. However, the information in the Discovered Clients list is not updated and, moreover, OOB user appears once again in the Online Users list - but the specified location is port A[a]!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The end result is taht the computer remains stuck in the Auth VLAN and NAC Agent Authentication dialogue keeps popping out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the reverse scenario (port B[b] to port A[a]) after manually clearing all user and client information, and the result was pretty much the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Boris&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434786#M792605</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2020-02-21T12:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434787#M792606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Boris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What switches are you working with? Codes on them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide a rough diagram of how things are layed out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 13:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434787#M792606</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-13T13:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434788#M792610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;Faisal,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;The switches I'm working with are:&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;Switch A:&amp;nbsp; WS-C2960-48TC-L&lt;BR /&gt;SW Image: C2960-LANBASEK9-M, Version 12.2(52)SE&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;Switch B: WS-C3560-48TS&lt;BR /&gt;SW Image: C3560-IPSERVICESK9-M, Version 12.2(53)SE&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;There is also switch C (another 3560, not sure about the image) where NAC appliances are connected.&lt;BR /&gt;Furthermore, there is a redundant NAS server on a different location, connected to switch B through another path (however, the active server atm of this test was the one connected to switch C).&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;BR /&gt;All the switches are connected with GE trunks (just a single link, no EtherChannels), in the following order:&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;A &amp;lt;-&amp;gt; B &amp;lt;-&amp;gt; C&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;BR /&gt;Both Access and Auth VLANs, and a third VLAN (for NAM-NAS-switches communication) are all terminated on switch B.&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;I understand there is some information missing - if you think it would be useful, I can provide a more detailed diagram...&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;Thanks,&lt;BR /&gt;Boris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jul 2010 14:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434788#M792610</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2010-07-13T14:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434789#M792614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Boris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before I ask for more information, a prelim question. Have you tried enabling MAC-Move notifications and whether the behaviour worked for you with that or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jul 2010 02:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434789#M792614</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-14T02:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434790#M792617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration includes the following lines (on both switches I used for access):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server community *** RW&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server community *** RO&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server trap-source Vlan2 (management subnet)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server location 10.0.0.101 (NAM IP address)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server enable traps snmp linkdown linkup&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server enable traps mac-notification change move threshold&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp-server host 10.0.0.101 version 2c cisco&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;mac-notification snmp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, NAC added the following line on monitored interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Consolas; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;snmp trap mac-notification change added&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this all that is required to send MAC-change and MAC-move traps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I captured SNMP traps with a 'tcpdump' on the NAM and I can confirm it receives traps from both switches, with correct source IP addresses. I will try to look into a "raw" dump to see the exact traps it received...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Boris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jul 2010 08:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434790#M792617</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2010-07-14T08:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434791#M792620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Boris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These two commands would enable mac-move:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mac-address-table notification mac-move&lt;/P&gt;&lt;P&gt;snmp-server enable traps mac-notification change move&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 13:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434791#M792620</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-15T13:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434792#M792622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Faisal! Indeed, this helped and resolved the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interestingly, there is no mention of the "mac-address-table notification mac-move" command in the Clean Access Manager Configuration Guide, Release 4.7(2), not even a note...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again, thank you.&lt;/P&gt;&lt;P&gt;Boris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 14:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434792#M792622</guid>
      <dc:creator>boris.senker</dc:creator>
      <dc:date>2010-07-15T14:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434793#M792629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Boris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quoting Dick Brandon: "Documentation is like sex: When it is good, it's very very good; and when it is bad, it is better than nothing"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're working on improving things, so hopefully it'll get better &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 19:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434793#M792629</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-15T19:32:14Z</dc:date>
    </item>
    <item>
      <title>NAC OOB problem - moving users between ports</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434794#M792657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. I'm hitting the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "mac-address-table notification mac-move" works fine only when the user connect and disconnects from ports on the same switch. But it doesn't work if I disconnect from switch "A" and connects to switch "B". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know any solution to this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 20:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-problem-moving-users-between-ports/m-p/1434794#M792657</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-09-04T20:14:48Z</dc:date>
    </item>
  </channel>
</rss>

