<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco NAC - Mapping Rules with VLAN ID in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637389#M825788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did what you suggested and is working as expected, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2011 13:53:07 GMT</pubDate>
    <dc:creator>Daniel Stefani</dc:creator>
    <dc:date>2011-03-02T13:53:07Z</dc:date>
    <item>
      <title>Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637360#M825592</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a NAC L3 - OOB - Real IP Gateway environment. &lt;/P&gt;&lt;P&gt;The NAC is the version 4.8.1. &lt;/P&gt;&lt;P&gt;Each floor of the company has one Access Vlan, one Auth Vlan and one User Role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured an LDAP Auth Server where the default role is Unauthenticated Role &lt;/P&gt;&lt;P&gt;and created Mapping Rules based on the Vlan ID of Auth Vlan on each floor. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex: The Access Vlan of the 8th floor is&amp;nbsp; 380, the Auth Vlan is 908 and User Role is &lt;/P&gt;&lt;P&gt;FuncionariosB8. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run an Auth Test, the result is as expected and User is mapped to the desired Role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when put into production, the user enters the Default Unauthenticated Role. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The figures attached show my settings in the NAC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log file below is taken nac_manager.log &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:23.091 +0100 [TP-Processor23] INFO&amp;nbsp; com.perfigo.wlan.web.admin.UserInfoManager&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - UIM - removeUsersByMacList: 1 MACs 0 users&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.709 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=1 condId=1 type=2 lOp=VLAN ID op=equals rOp=907&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.709 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.709 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=0 condId=1 type=2 lOp=VLAN ID op=equals rOp=908&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=2 condId=1 type=2 lOp=VLAN ID op=equals rOp=909&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=3 condId=1 type=2 lOp=VLAN ID op=equals rOp=929&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=8 condId=1 type=2 lOp=VLAN ID op=equals rOp=928&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=11 condId=1 type=2 lOp=VLAN ID op=equals rOp=910&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=13 condId=1 type=2 lOp=VLAN ID op=equals rOp=931&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.710 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=15 condId=1 type=2 lOp=VLAN ID op=equals rOp=911&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.711 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.711 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=17 condId=1 type=2 lOp=VLAN ID op=equals rOp=912&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;2011-02-25 17:42:44.711 +0100 [TP-Processor23] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {1=false}&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;&lt;STRONG&gt;2011-02-25 17:42:49.103 +0100 [Thread-72] ERROR com.perfigo.wlan.web.sms.SnmpUtil&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Failed to find Access VLAN for switch [10.5.0.121] port [88]. Use default Access VLAN 380 instead.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM style="color: #000080; font-size: 10pt; "&gt;&lt;STRONG&gt;2011-02-25 17:42:49.354 +0100 [Thread-73] ERROR com.perfigo.wlan.web.sms.SnmpUtil&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Failed to find Access VLAN for switch [10.5.0.121] port [88]. Use default Access VLAN 380 instead.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help me with this problem? that will need to open a TAC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637360#M825592</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2020-02-21T12:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637361#M825598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't correctly configure a LDAP mapping rules.&lt;/P&gt;&lt;P&gt;LDAP use queries by looking in AD structure to find a user belongs to OU or groups and &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;the basis of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;received &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Click for alternate translations"&gt;responses&lt;/SPAN&gt; put user to the proper role.&lt;SPAN class="hps" title="Click for alternate translations"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In your&amp;nbsp; NAC configuration&amp;nbsp; it always put user in Unauthenticated role because you indicate Auth VLAN 908.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example in your AD is created a group called 'FunctionariosB8'&amp;nbsp; and it has a member called 'test'&lt;/P&gt;&lt;P&gt;Create a role that in the expression form be a formula 'memeberof contains FunctionariosB8'.&lt;/P&gt;&lt;P&gt;And you can now verify in Auth Test what is a response for user 'test'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 20:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637361#M825598</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-27T20:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637362#M825605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Mapping Rule setup, the condition VLAN ID is available for all Auth Servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I intend to use the condition type VLAN ID and not Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my environment, this condition is more appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the example you gave, you use Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See my illustrated attached file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply, but i believe it does not solve my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 22:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637362#M825605</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-27T22:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637363#M825618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show me how are you configure rules for users? Why are try tu use LDAP, it has any information about VLAN ID that you want to use?&lt;/P&gt;&lt;P&gt;I think better for you is to create port profile for a dedicated role and assign user to this role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, I verify to what you want to do and as I mention above the mapping rule is not your solution.&lt;/P&gt;&lt;P&gt;You must create port profile and assign port on a switch to this profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 08:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637363#M825618</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T08:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637364#M825626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The settings are attached.&lt;/P&gt;&lt;P&gt;I'm using LDAP to use AD as a base of users and an authentication option for users who are not on the Domain but have accounts in AD.&lt;/P&gt;&lt;P&gt;The method of authentication via SSO is the default, but the same problem happens in Mapping Rule.&lt;/P&gt;&lt;P&gt;I chose to use User Role VLAN  because i'm configuring the Guest access too.&lt;/P&gt;&lt;P&gt;Thus, a switch port may be in the Employees Network or Guest Network .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network does not propagate VLANs on a switch to the other, the entire L3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The focus on solving the problem should be in the nac_manager.log  messages I sent in the first post.&lt;/P&gt;&lt;P&gt;Finding the solution to the error will solve my problem.&lt;/P&gt;&lt;P&gt;For some reason, NAC Manager can not read the Auth VLAN ID of the user for mapping it correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It can be a SNMP problem, but not sure yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sending my SNMP settings for you see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 10:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637364#M825626</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T10:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637365#M825634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SNMP settings on a CAT switch are in mode read-only, so verify when you changed this SNMP settings for CAM's only to read-write.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 10:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637365#M825634</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T10:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637366#M825643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;imagine&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;SNMP settings&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;are correct&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;If&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;I make&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;snmpwalk&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;for the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;switch&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;got the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;following&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;output&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;[root@srvtatcam001 ~]# snmpwalk -v 1 -c nac-ro 10.5.0.121 | more&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysDescr.0 = STRING: Cisco IOS Software, s3223_rp Software (s3223_rp-ADVENTERPRISEK9_WAN-M), Version 12.2(33)SXH5, RELEA&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SE SOFTWARE (fc1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;Copyright (c) 1986-2009 by Cisco Systems, Inc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;Compiled Thu 16-Apr-09 01:34 by prod&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.9.1.400&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (320415575) 37 days, 2:02:35.75&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysContact.0 = STRING: &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysName.0 = STRING: SWITATIDF002&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysLocation.0 = STRING: &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysServices.0 = INTEGER: 78&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;SNMPv2-MIB::sysORLastChange.0 = Timeticks: (0) 0:00:00.00&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifNumber.0 = INTEGER: 357&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.1 = INTEGER: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.2 = INTEGER: 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.3 = INTEGER: 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.4 = INTEGER: 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.5 = INTEGER: 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.6 = INTEGER: 6&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.7 = INTEGER: 7&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.8 = INTEGER: 8&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000080;"&gt;IF-MIB::ifIndex.9 = INTEGER: 9&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 11:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637366#M825643</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T11:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637367#M825651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you test when you changed CAT 6500 and CAM switch profile to SNMP version 2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 11:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637367#M825651</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T11:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637368#M825662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remains the same behavior, users are still being mapped out for Unauthenticated Role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;HR originaltext="---" /&gt;&lt;P&gt;Mensagem original&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 14:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637368#M825662</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T14:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637369#M825672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In AD create a user and test through Auth test and show a CAM's response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 14:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637369#M825672</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T14:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637370#M825681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See attached files...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 14:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637370#M825681</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T14:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637371#M825692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, you have an answer why users are put in Unautheticated Role.&lt;/P&gt;&lt;P&gt;In mapping role change the value 908 to 380 and test it with a acsadmin user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 14:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637371#M825692</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T14:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637372#M825702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;The users are put in Unautheticated Role because the NAC Manager is unable to obtain the VLAN ID of the switch port where User is connected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;This can be seen in the file nac_manager.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="color: #000080;"&gt;2011-02-28 16:37:55.601 +0100 [TP-Processor22] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - Cond#1:AuthServerMapCondition: mapid=4 condId=1 type=2 lOp=&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; "&gt;VLAN ID&lt;/STRONG&gt;&lt;SPAN style="color: #000080;"&gt; op=equals rOp=&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; "&gt;908&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="color: #000080;"&gt;2011-02-28 16:37:55.601 +0100 [TP-Processor22] INFO&amp;nbsp; c.perfigo.wlan.web.auth.expr.RoleMappingEvaluator&amp;nbsp; - conditions - {&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; "&gt;1=false&lt;/STRONG&gt;&lt;SPAN style="color: #000080;"&gt;}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the result of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;condition&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;should&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;be &lt;/SPAN&gt;&lt;SPAN style="color: #000080;"&gt;conditions - {&lt;/SPAN&gt;&lt;STRONG style="color: #003300; "&gt;1=true&lt;/STRONG&gt;&lt;SPAN style="color: #000080;"&gt;}.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;In consequence of&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;condition&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;is&lt;/SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;false&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;NAC&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Manager&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;puts&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the switch port&lt;/SPAN&gt;&amp;nbsp; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;in the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Default&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Vlan&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Access&lt;/SPAN&gt; configured in &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Port&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Profile&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;and the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;in the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Unauthenticated&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Role, &lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;which is &lt;/SPAN&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;default&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;LDAP&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Auth&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Server&lt;/SPAN&gt; &lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;&lt;STRONG&gt;But the big question to be answered is why it(NAC Manager) can not read this VLAN ID?.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;In the user guide says:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt;"The Mapping Rules forms can be used to map users into user role(s) based on the following parameters:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN lang="EN-US"&gt;•The &lt;STRONG&gt;VLAN ID&lt;/STRONG&gt; of user traffic originating from the &lt;STRONG&gt;UNTRUSTED SIDE&lt;/STRONG&gt; of the CAS (all auth server types). ------&amp;gt; &lt;STRONG&gt;IN MY CASE IS THE VLAN 908&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="padding-left: 30px;"&gt;&lt;SPAN lang="EN-US"&gt;•Authentication attributes passed from LDAP and RADIUS auth servers (and RADIUS attributes passed from Cisco VPN Concentrators)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Kind Regards,&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 16:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637372#M825702</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T16:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637373#M825708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Read this document about&lt;SPAN style="font-size: 10pt;"&gt; Cisco NAC Appliance Switch and Wireless LAN Controller Support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/switch_spt.html#wp89679"&gt;http://www.cisco.com/en/US/docs/security/nac/appliance/support_guide/switch_spt.html#wp89679&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a command try it on the CAM.&lt;/P&gt;&lt;P&gt;snmpget -v 1 -c &lt;SWITCH_SNMP_COMMUNITY_STRING&gt; &lt;SWITCH_IP&gt; 1.3.6.1.2.1.1.2.0&lt;/SWITCH_IP&gt;&lt;/SWITCH_SNMP_COMMUNITY_STRING&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If CAM response with the same OID as above, your SNMP settings are correct but test more SNMP settings on CAM and on a switch.&lt;/P&gt;&lt;P&gt;As far sa i know you have supported IOS on CAT6500 by CAM or maybe are some bugs in your IOS version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The simple way to check SNMP go to port profile on CAM chose the proper port on a switch an bounce port to which is connected a PC.&lt;/P&gt;&lt;P&gt;In that way you verify of CAM communication thtough SNMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 17:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637373#M825708</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-02-28T17:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637374#M825716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a test with snmpget using the OID of VLAN ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="root@srvtatcam001 mibs"&gt;&lt;/A&gt;# snmpget -v 1 -c nac-ro 10.5.0.121 1.3.6.1.4.1.9.9.68.1.2.2.1.2.88&lt;/P&gt;&lt;P&gt;SNMPv2-SMI::enterprises.9.9.68.1.2.2.1.2.88 = INTEGER: 908&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also collected packets between the switch and NAC Manager during&lt;/P&gt;&lt;P&gt;Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 20:56:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637374#M825716</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-02-28T20:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637375#M825721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could not open attached file, please send this file as a txt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 09:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637375#M825721</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-03-01T09:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637376#M825728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Captured&lt;/SPAN&gt; by &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;TCPDUMP&lt;/SPAN&gt; in &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;NAC&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;MANAGER&lt;/SPAN&gt; the &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;communications between the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Switch&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;and &lt;/SPAN&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;CAM&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;We can&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;see&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;in line&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;14&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; S&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;witch&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;responds&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;to requests from the&lt;/SPAN&gt; &lt;SPAN class="hps atn" title="Clique para mostrar traduções alternativas"&gt;get-&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;request&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;made&lt;/SPAN&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;by&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;CAM&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;with&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;VLAN&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;ID&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;information&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 09:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637376#M825728</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-03-01T09:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637377#M825733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all, solve the problem of SNMP and when are you sure that is OK move to next step.&lt;/P&gt;&lt;P&gt;The attached file show capture from wireshark but every log which you send is always massage of SNMPv2.&lt;/P&gt;&lt;P&gt;Why are you refers to the VLAN 908 all the time, it's just Auth VLAN.&lt;/P&gt;&lt;P&gt;Do you get proper OID from the switch on CAM?&lt;/P&gt;&lt;P&gt;Are you able manage switch ports by CAM on port profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 10:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637377#M825733</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-03-01T10:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637378#M825735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;ok&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;, I think&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;snmp&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;is working&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;properly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;somehow&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;NAC&lt;/SPAN&gt; app &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;does not receive&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;information&lt;/SPAN&gt; of the&amp;nbsp; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;VLAN&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;ID&lt;/SPAN&gt; during &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;conditional tests&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;of the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Mapping&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Rule&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;how&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;do I get&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;proper&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;OID&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;on&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;NAC&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;from the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;switch&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;&lt;/SPAN&gt;On captures &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;I just&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;see the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;OIDs&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;NAC&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;itself&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;sends&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;to the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;switch&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;during&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;a&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;process&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;of &lt;/SPAN&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;user authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;Yes&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;, I can&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;manage&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;switch ports&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;through&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;CAM, see att file...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 10:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637378#M825735</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2011-03-01T10:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco NAC - Mapping Rules with VLAN ID</title>
      <link>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637379#M825739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I send you a link to the &lt;SPAN class="content"&gt;&lt;/SPAN&gt;Switch OID Support and there is a command how to verify.&lt;/P&gt;&lt;P&gt;This command also I send you earlier and is snmpget.&lt;/P&gt;&lt;P&gt;What happend when you bounce the port 88. Is the CAM change VLAN to 908?&lt;/P&gt;&lt;P&gt;If yes, verify also on a switch console for this port.&lt;/P&gt;&lt;P&gt;You can verify how CAM see detail about connected switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 11:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-nac-mapping-rules-with-vlan-id/m-p/1637379#M825739</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2011-03-01T11:04:51Z</dc:date>
    </item>
  </channel>
</rss>

