<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Switch Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549806#M800855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX in advanced for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recieved with the CAM an license for 20 CAS, but nothing more.&lt;/P&gt;&lt;P&gt;The CAS server's did not bring any PAK.&lt;/P&gt;&lt;P&gt;This CAM and CAS were bought two years ago by my client, but just now he asked me to install it.&lt;/P&gt;&lt;P&gt;Do you know if two years ago the licensing was diferent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Dec 2010 11:15:33 GMT</pubDate>
    <dc:creator>mamaral</dc:creator>
    <dc:date>2010-12-09T11:15:33Z</dc:date>
    <item>
      <title>NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549799#M800813</link>
      <description>&lt;P&gt;Hi!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have bought an NAC Server and a Nac Manager, to manage centraly the vlan where the users connect to based on the authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have several sites, but the NAC server will be in the headquarters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; When a remote user authenticates, the nac should configure the user switch port for the right vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is this an out-of-band solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do i need an specific license for out-of-band?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regard's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel Amaral&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549799#M800813</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2020-02-21T12:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549800#M800814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello. You don't need an specific license for out-of-band. You just configure you NAC Manager to tell each NAC server to work as out-of-band or as in-band.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About your scenario, it seems logical to use out-of-band, but take into account that when the user is authenticating and remediating the traffic will always go through NAC Server (no matter if you have chosen out-of-band or in-band). The term "out-of-band" applies only after the user was authenticated and the pc was remediated. Then (and only then) the traffic of that user won't go through NAC server. Hope that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 17:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549800#M800814</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2010-11-19T17:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549801#M800818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tkx for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still have an problem. When i try to add an NAC server, i do not have the option of out-of-band.&lt;/P&gt;&lt;P&gt;Do you have any hint (i'm using version 4.8).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 13:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549801#M800818</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-07T13:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549802#M800826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to have an Out of Band license in order to be able to use Out of band features and add the Clean Access Servers as Out-of-band servers.&lt;/P&gt;&lt;P&gt;Without OOB license you will also not have the device administration menu on the left side of the GUI.&lt;/P&gt;&lt;P&gt;This is needed to configure the switches for OOB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 13:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549802#M800826</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-07T13:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549803#M800832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In very old version there were specific out-of-band and in-band licenses. But in new versions you don't need an specific Out-of-band license&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/license.html"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/license.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just installed version 4.8. As I mentioned before, my licenses let me choose inband or out-of-band behavior (but not both simultaneously for a single NAC server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You just go to "Device Management&amp;gt; Clean Access Servers"&amp;nbsp; click en New Server . There you type the IP address and you choose Server Type from&amp;nbsp; a drop-down list. You have to choose "Out-of-band virtual gateway". To finish you click "Add Clean Access Server".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 14:34:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549803#M800832</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2010-12-07T14:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549804#M800842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My problem is that when i do that, the option of Out-Of-Band does not show up in the list-box &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;and when i go to the license page, it does not show up the OOB license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Did you had to do anything to activate the OOB?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My NAC came with the version 4.1, and i have upgraded to the verions 4.8, but neither one had the OOB option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 14:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549804#M800842</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-07T14:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549805#M800850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need at least 2 licenses:&lt;/P&gt;&lt;P&gt;1 - CAM license -&amp;gt; This license is the one you install the first time you access the CAM WEB GUI.&lt;/P&gt;&lt;P&gt;2 - CAS license -&amp;gt; This license needs to be installed so that you can add Clean Access Servers to the CAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you installed the CAS license?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If not, you need to get the Product Activation Key (PAK) you received allong with the CAs and go to the licensing web page &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/SWIFT/Licensing/PrivateRegistrationServlet"&gt;https://tools.cisco.com/SWIFT/Licensing/PrivateRegistrationServlet&lt;/A&gt;&lt;SPAN&gt;, and request a CAS license. Please note that you need to enter the &lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Clean Access MANAGER&lt;/STRONG&gt;&lt;/SPAN&gt; eth0 mac address for the Clean Access Server (CAS) licence. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 17:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549805#M800850</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-07T17:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549806#M800855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX in advanced for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recieved with the CAM an license for 20 CAS, but nothing more.&lt;/P&gt;&lt;P&gt;The CAS server's did not bring any PAK.&lt;/P&gt;&lt;P&gt;This CAM and CAS were bought two years ago by my client, but just now he asked me to install it.&lt;/P&gt;&lt;P&gt;Do you know if two years ago the licensing was diferent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TKX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Miguel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 11:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549806#M800855</guid>
      <dc:creator>mamaral</dc:creator>
      <dc:date>2010-12-09T11:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Switch Configuration</title>
      <link>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549807#M800858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is the same schema: Yo uneed 2 licenses, one for CAM and one for CAS.&lt;/P&gt;&lt;P&gt;The one for CAM defines how many CASes you can add.&lt;/P&gt;&lt;P&gt;The one for CAS defines how many users are supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So either the CAS PAK was lost, or was never bought.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In either case you will need to get in touch with the entitiy that sold the devices and request for the CAS PAK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 11:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-switch-configuration/m-p/1549807#M800858</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-09T11:20:13Z</dc:date>
    </item>
  </channel>
</rss>

