<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491943#M797181</link>
    <description>&lt;P&gt;Hi !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My implementation is VG-OOB-L2&lt;/P&gt;&lt;P&gt;I have this:&lt;/P&gt;&lt;P&gt;VLAN Auth = 136, don´t have any subnet associate&lt;/P&gt;&lt;P&gt;VLAN Access = 140, subnet is 10.0.140.0/24&lt;/P&gt;&lt;P&gt;Another VLANs when user role works = 128,144 asnd the subnet´s (10.0.128.0/24 and 10.0.144.0/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I connect my pc, my port change to vlan 136, I receive the login of NAC Agent, I successfully login but my VLAN not changed to VLAN 128, and my ip address not chaged too. The snmp configuration is ok because in the first step when I connect into the port the vlan is changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My doubt about my config is:&lt;/P&gt;&lt;P&gt;In interface eth1(untrusted) CAS I have the VLAN 136&lt;/P&gt;&lt;P&gt;In interface eth0 (trusted) CAS I have the VLAN 140, my doubt, I need put the VLAN 128 and the 144?&lt;/P&gt;&lt;P&gt;In managed subnet I have only the 10.0.140.0/24 subnet wich correspond to vlan 140, I need put the 128 and 144 subnets?&lt;/P&gt;&lt;P&gt;VLAN Mapping is 136-140.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:03:21 GMT</pubDate>
    <dc:creator>julfp</dc:creator>
    <dc:date>2020-02-21T12:03:21Z</dc:date>
    <item>
      <title>NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491943#M797181</link>
      <description>&lt;P&gt;Hi !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My implementation is VG-OOB-L2&lt;/P&gt;&lt;P&gt;I have this:&lt;/P&gt;&lt;P&gt;VLAN Auth = 136, don´t have any subnet associate&lt;/P&gt;&lt;P&gt;VLAN Access = 140, subnet is 10.0.140.0/24&lt;/P&gt;&lt;P&gt;Another VLANs when user role works = 128,144 asnd the subnet´s (10.0.128.0/24 and 10.0.144.0/24)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I connect my pc, my port change to vlan 136, I receive the login of NAC Agent, I successfully login but my VLAN not changed to VLAN 128, and my ip address not chaged too. The snmp configuration is ok because in the first step when I connect into the port the vlan is changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My doubt about my config is:&lt;/P&gt;&lt;P&gt;In interface eth1(untrusted) CAS I have the VLAN 136&lt;/P&gt;&lt;P&gt;In interface eth0 (trusted) CAS I have the VLAN 140, my doubt, I need put the VLAN 128 and the 144?&lt;/P&gt;&lt;P&gt;In managed subnet I have only the 10.0.140.0/24 subnet wich correspond to vlan 140, I need put the 128 and 144 subnets?&lt;/P&gt;&lt;P&gt;VLAN Mapping is 136-140.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491943#M797181</guid>
      <dc:creator>julfp</dc:creator>
      <dc:date>2020-02-21T12:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491944#M797182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two places where SNMP is configured on the CAM. One is used for reading the switch config, one for writing when setting the ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please ensure both places have the correct values for the SNMP strings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 05:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491944#M797182</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-08-17T05:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491945#M797183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I solved the first problem, it was a dumb misconfiguration. What is happening now is that I have more than one user role, but only one auth VLAN. In the user role I have 3 VLANs with 3 different subnets, the problem is: when a client authenticates it dosn't renew the its IP address, it continues to use the same IP that it got when it was in the auth VLAN. I need the client do change its address to the correct subnet associate with the VLAN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using a OOB VGW L2 setup, in the access switch I can see that the port's VLAN is changed from the auth vlan to the user role VLAN, but the client keeps the same IP address from the auth VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 19:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491945#M797183</guid>
      <dc:creator>julfp</dc:creator>
      <dc:date>2010-08-17T19:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491946#M797184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure in your port profile you're setting the Access VLAN to "User Role VLAN". Also make sure the User role VLANs are defined for the User Role definitions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 11:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491946#M797184</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-08-19T11:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491947#M797185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Documenting resolution from the TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was a DHCP server problem of misconfiguration. CCA works as expected now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Aug 2010 05:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491947#M797185</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-08-21T05:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491948#M797186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you explain the issue in the DHCP server... I have a similar problem with Win2k8 R2 DHCP ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 21:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/1491948#M797186</guid>
      <dc:creator>George Ribarski</dc:creator>
      <dc:date>2010-12-21T21:27:46Z</dc:date>
    </item>
  </channel>
</rss>

