<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522350#M803932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; As far as the Radius accounting feature do i have to enable it even though SSO feature is not enabled?&lt;/P&gt;&lt;P&gt;&amp;gt; If i enable the Radius accounting will i see discoverd clients on the CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Wireless SSO you have to point the RADIUS accounting to the CAS.. not the CAM.&lt;/P&gt;&lt;P&gt;You will be able to see the users under the "active VPN clients"; the VPN terminology comes by the fact that Wireless and VPN SSO actually share the same method, being RADIUS accounting from either the WLC or the VPN gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if for now you don't see any web redirection nor agent pop-up, I'd check the WLC dynamic interface config for the access and quarantine VLAN, but also the VLAN mapping and managed subnet configuration on the VGW CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Oct 2010 20:26:17 GMT</pubDate>
    <dc:creator>Federico Lovison</dc:creator>
    <dc:date>2010-10-13T20:26:17Z</dc:date>
    <item>
      <title>Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB mode</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522346#M803928</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;Our client&amp;nbsp; has a network with 20 CAS pairs and 1 CAM pair all with v4.7.2.The wired users are all pass through NAC for authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;We now want to implement the same setup for the wireless users. The client has a WLC 4404 with v6.0.199.For the need of NAC authentication 1 pair of CAS has been implemented.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;I have followed the document&lt;SPAN class="apple-converted-space"&gt; &lt;/SPAN&gt;&lt;STRONG&gt;NAC Out−Of−Band (OOB) Wireless Configuration Example&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; font-size: 11pt;"&gt;&lt;SPAN style="color: #000000;"&gt;(&lt;/SPAN&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a138cc.shtml" target="_blank"&gt;&lt;SPAN style="color: #0000ff;"&gt;http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a138cc.shtml&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: #000000;"&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;I have also checked the guides for CAM(V4.7.2) and WLC(V6.0).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color: #1f497d; font-size: 11pt;"&gt;&lt;STRONG&gt;The issue is that the implementation of NAC and WLC is not working. The users are connecting like there is no NAC in between. From the troubleshooting I have performed it seems that the WLC is not communicating correctly with the CAM.I can only see Disassociation traps from the WLC.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;Is there any updated document or any other info that can help me to solve the issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style=": ; color: #000000; font-size: 11pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; ,&amp;amp;quot: ; Calibri&amp;amp;quot: ; "&gt;Stratos Demosthenous&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522346#M803928</guid>
      <dc:creator>s.demosthenous</dc:creator>
      <dc:date>2020-02-21T12:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522347#M803929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That document is a nice one and contains all needed to have it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure that accounting is configured on the WLAN so that the WLC can send the accounting start to the CAM.&lt;/P&gt;&lt;P&gt;Also, plese verify if you have the NAC check box enabled on the WLAN.&lt;/P&gt;&lt;P&gt;Is the quarantine interface configured on the WLC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is exactly the client behavior?&lt;/P&gt;&lt;P&gt;Does the client get an IP address?&lt;/P&gt;&lt;P&gt;Does the Clean Access Agent pops up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 10:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522347#M803929</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-10-08T10:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522348#M803930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tiago,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAC checkbox and quarantine interface is enabled on WLC.&lt;/P&gt;&lt;P&gt;The client behaviour is like before i enable the NAC:it connects to the SSID and access the network.No agent or redirction page appears.&lt;/P&gt;&lt;P&gt;As far as the Radius accounting feature do i have to enable it even though SSO feature is not enabled?&lt;/P&gt;&lt;P&gt;If i enable the Radius accounting will i see discoverd clients on the CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stratos Demosthenous &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 19:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522348#M803930</guid>
      <dc:creator>s.demosthenous</dc:creator>
      <dc:date>2010-10-08T19:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522349#M803931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a note from the controller perspective.&lt;/P&gt;&lt;P&gt;The interface vlan must be the NAC access vlan and what WLC calls "quarantine vlan" is the NAC authentication vlan.&lt;/P&gt;&lt;P&gt;When a client is wireless connected, go in the monitor client page and check the client details. In which vlan is it placed? is it NAC_REQD state or RUN state ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's run, it means it somehow got the OK from the CAM while if it's NAC_REQD, it means the WLC is doing its job but apparently your quarantine vlan allows network access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Oct 2010 07:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522349#M803931</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2010-10-09T07:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522350#M803932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; As far as the Radius accounting feature do i have to enable it even though SSO feature is not enabled?&lt;/P&gt;&lt;P&gt;&amp;gt; If i enable the Radius accounting will i see discoverd clients on the CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Wireless SSO you have to point the RADIUS accounting to the CAS.. not the CAM.&lt;/P&gt;&lt;P&gt;You will be able to see the users under the "active VPN clients"; the VPN terminology comes by the fact that Wireless and VPN SSO actually share the same method, being RADIUS accounting from either the WLC or the VPN gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if for now you don't see any web redirection nor agent pop-up, I'd check the WLC dynamic interface config for the access and quarantine VLAN, but also the VLAN mapping and managed subnet configuration on the VGW CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 20:26:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522350#M803932</guid>
      <dc:creator>Federico Lovison</dc:creator>
      <dc:date>2010-10-13T20:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522351#M803933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your inputs.&lt;/P&gt;&lt;P&gt;The problem in the end was not the configuration/nor the software of the WLC but the operation of the device itself.&lt;/P&gt;&lt;P&gt;I configured the Wism module(same software version as the Wlc) on the 6500 switch that the client has and moved the wireless configuration to it.&lt;/P&gt;&lt;P&gt;By the minute i performed this the NAC opration worked!!!!&lt;/P&gt;&lt;P&gt;I have also enabled SSO using Windows AD&amp;nbsp; in order for the user to have the same feeling as its wired connection.That also worked from the start.&lt;/P&gt;&lt;P&gt;It seems that the WLC has a lot of problems&amp;nbsp; and Cisco needs to solve them out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stratos Demosthenous&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 08:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522351#M803933</guid>
      <dc:creator>s.demosthenous</dc:creator>
      <dc:date>2010-10-25T08:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522352#M803934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stratos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I strongly doubt that it's a platform problem. Especially since a Wism blade is actually 2 WLC 4404 assembled in a blade, so the platform IS really the same.&lt;/P&gt;&lt;P&gt;I'm quite sure that there is something different in your setup between the wism and the WLC so you might want to check on their differences. It can be as simple as a vlan missing or something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 08:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522352#M803934</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2010-10-25T08:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522353#M803935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;WLC was a temporary solution until Wism been placed to the network so there is no need to furhter troubleshoot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Anyway since you doubt there is a problem with the WLC, have you performed such a setup and worked?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;If yes please post it in order to use for future clients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Stratos Demosthenous&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 09:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522353#M803935</guid>
      <dc:creator>s.demosthenous</dc:creator>
      <dc:date>2010-10-25T09:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAC v4.7.2 and WLC version v6.0.199.4 in L2-OOB</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522354#M803936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't have such a setup always ready at disposal, but we'll sure consider posting config examples of NAC + WLC OOB actually. thanks for the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 09:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-nac-v4-7-2-and-wlc-version-v6-0-199-4-in-l2-oob/m-p/1522354#M803936</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2010-10-25T09:37:30Z</dc:date>
    </item>
  </channel>
</rss>

