<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC multiple issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1491999#M797203</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;looks like the trusted root for the cam or cas is not imported on the respective servers. ...&lt;/P&gt;&lt;P&gt;ie import the cas's public root on the cam and vice versa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Jul 2010 12:25:09 GMT</pubDate>
    <dc:creator>mecampr</dc:creator>
    <dc:date>2010-07-22T12:25:09Z</dc:date>
    <item>
      <title>NAC multiple issues</title>
      <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1491998#M797202</link>
      <description>&lt;P&gt;1st qeustion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am trying to pass my wireless users through nac. i have catalyst 3560 switch to which everything is connected to including the nas,nam,wlc and ap.&lt;/P&gt;&lt;P&gt;the problem is i can see the wireless users registered in the nam but they are unable to pick ip address. what could be the problem i attached every configuration i did on the switch, wlc and nam.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2nd question&lt;/P&gt;&lt;P&gt;how could i fix this error message&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/1/0/6015-error1.png" alt="error1.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1491998#M797202</guid>
      <dc:creator>mshebelle</dc:creator>
      <dc:date>2020-02-21T12:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAC multiple issues</title>
      <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1491999#M797203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;looks like the trusted root for the cam or cas is not imported on the respective servers. ...&lt;/P&gt;&lt;P&gt;ie import the cas's public root on the cam and vice versa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 12:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1491999#M797203</guid>
      <dc:creator>mecampr</dc:creator>
      <dc:date>2010-07-22T12:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC multiple issues</title>
      <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492000#M797204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) On the Device Management &amp;gt; Clean Access Servers &amp;gt; Advanced &amp;gt; Managed Subnet page, uncheck "Enable subnet-based VLAN retag".&amp;nbsp; You don't need that checked to do VLAN mapping, and it breaks most networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) There are two red nag messages.&amp;nbsp; One is complaining that you're using the temporary perfigo end entity certificate, and one that you have the temporary perfigo root in your trusted certificate authorities.&amp;nbsp; The only way to get rid of those messages is to get a CA-signed (non-perfigo) cert.&amp;nbsp; The reasoning behind this is that these certs are only meant for non-production environments, so if this is just a test network, you can just ignore them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 14:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492000#M797204</guid>
      <dc:creator>Lauren Sullivan</dc:creator>
      <dc:date>2010-07-22T14:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC multiple issues</title>
      <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492001#M797205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah, lauren you were right i needed to uncheck the "Enable subnet-based VLAN retag" and the agents pops up and it works fine.&lt;/P&gt;&lt;P&gt;what about if i don't want to user the agent and rather use the web login? what are the steps i need to follow? does it automatically pops up like the agent does? thank you very much bzw...u really saved my day.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jul 2010 09:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492001#M797205</guid>
      <dc:creator>mshebelle</dc:creator>
      <dc:date>2010-07-23T09:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAC multiple issues</title>
      <link>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492002#M797206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the user is in the auth VLAN and opens up a browser, they should get redirected to the CAS login page.&amp;nbsp; For this to happen, you do need to make sure that whatever web address they're trying to go to is blocked in the unauth traffic policy - so if&amp;nbsp; you had an "allow all" traffic rule in the unauth role for testing, make sure you remove it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Jul 2010 12:32:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-multiple-issues/m-p/1492002#M797206</guid>
      <dc:creator>Lauren Sullivan</dc:creator>
      <dc:date>2010-07-23T12:32:35Z</dc:date>
    </item>
  </channel>
</rss>

