<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604271#M818559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in my eyes there is no mistake in your switch config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ist there any entry in the log of your cta, or in the failed attempts of the ACS ?&lt;/P&gt;&lt;P&gt;For example SSL handshake Error or something similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also should check if there is any firewall active on the client (windows firewall for example)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Apr 2006 07:37:34 GMT</pubDate>
    <dc:creator>HarrytheBrain</dc:creator>
    <dc:date>2006-04-04T07:37:34Z</dc:date>
    <item>
      <title>NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604270#M818550</link>
      <description>&lt;P&gt;I have problem with nac 2 and acs 4.0, this is the conf in the switch 3560:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication eou default group radius&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip admission name nac eapoudp&lt;/P&gt;&lt;P&gt;ip admission name NAC-L2-IP eapoudp&lt;/P&gt;&lt;P&gt;ip admission name NAC-L2-IP-Bypass eapoudp bypass&lt;/P&gt;&lt;P&gt;ip admission name NAC-L3-IP eapoudp list EoU-ACL&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;eou allow clientless&lt;/P&gt;&lt;P&gt;eou timeout hold-period 60&lt;/P&gt;&lt;P&gt;eou timeout status-query 60&lt;/P&gt;&lt;P&gt;eou timeout revalidation 60&lt;/P&gt;&lt;P&gt;eou logging&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/23&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; ip access-group EoU-ACL in&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; ip admission NAC-L2-IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended EoU-ACL&lt;/P&gt;&lt;P&gt; permit udp any any eq 21862&lt;/P&gt;&lt;P&gt; permit udp any eq bootpc any eq bootps&lt;/P&gt;&lt;P&gt; permit udp any any eq domain&lt;/P&gt;&lt;P&gt; permit icmp any any&lt;/P&gt;&lt;P&gt; permit ip any host 10.0.0.6&lt;/P&gt;&lt;P&gt; deny   ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server host 10.0.0.6 auth-port 1645 acct-port 1646 key cisco123&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connect pc to port 23 and not happen nothing.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604270#M818550</guid>
      <dc:creator>davila_jc</dc:creator>
      <dc:date>2020-02-21T08:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604271#M818559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in my eyes there is no mistake in your switch config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ist there any entry in the log of your cta, or in the failed attempts of the ACS ?&lt;/P&gt;&lt;P&gt;For example SSL handshake Error or something similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also should check if there is any firewall active on the client (windows firewall for example)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Apr 2006 07:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604271#M818559</guid>
      <dc:creator>HarrytheBrain</dc:creator>
      <dc:date>2006-04-04T07:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604272#M818563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is the message error in acs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS or PEAP authentication failed during SSL handshake&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LSW1_Simulacion#sh eou all&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Address         Interface              AuthType   Posture-Token Age(min)&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;10.215.140.5    FastEthernet0/23       EAP        -------         25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Apr 2006 21:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604272#M818563</guid>
      <dc:creator>davila_jc</dc:creator>
      <dc:date>2006-04-05T21:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604273#M818564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; EAP-TLS or PEAP authentication failed during SSL handshake &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok, thats what i expected.&lt;/P&gt;&lt;P&gt;This means your CTA and the ACS couldn't build the tunnel with the certificate.&lt;/P&gt;&lt;P&gt;For that i would know if your ACS has a self-signed or a certificate from a CA. I think you have one from a CA ??&lt;/P&gt;&lt;P&gt;If so, you surely already have the ACS Certificate installed on the Client.&lt;/P&gt;&lt;P&gt;But now install the CA Certificate too, and try again. (with the mmc snap-in certificates or the content in IE, as root ca of course)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;harry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 07:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604273#M818564</guid>
      <dc:creator>HarrytheBrain</dc:creator>
      <dc:date>2006-04-06T07:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604274#M818566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the certificate installed in my machine and running.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 12:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604274#M818566</guid>
      <dc:creator>davila_jc</dc:creator>
      <dc:date>2006-04-06T12:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604275#M818568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the certificate installed in the user context or the system context?  Chances are the certificate ahs been installed by a user other than administrator.  You need to use the Microsoft MMC Certificate console to make sure that it's installed in the correct context.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Apr 2006 15:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604275#M818568</guid>
      <dc:creator>brford</dc:creator>
      <dc:date>2006-04-23T15:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAC problem</title>
      <link>https://community.cisco.com/t5/network-security/nac-problem/m-p/604276#M818569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to install the ACS Root Certificate (3rd Party Root Certificate, if ACS is using a 3rd Party Certificate) to the Trust Agent Store respository, which is different from the Machine\User repository managed by the MMC Snap-in.&lt;/P&gt;&lt;P&gt;From the Trust Agent directory use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ctaCert.exe /add "c:\&lt;WHATEVERPATH&gt;" /store "Root"&lt;/WHATEVERPATH&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Apr 2006 20:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-problem/m-p/604276#M818569</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2006-04-26T20:30:30Z</dc:date>
    </item>
  </channel>
</rss>

