<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC manager doesn't change auth vlan to access vlan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453579#M827943</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zoran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is as expected. If your client is in one of the managed subnet, then by default the CAS sends out all traffic through it's untrusted interface. That's why when you're already authenticated, and you try to access the CAS, the replies to those queries/attempts would go out the untrusted interface and never reach your client back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Apr 2010 15:40:46 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2010-04-29T15:40:46Z</dc:date>
    <item>
      <title>NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453574#M827812</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to install L2 out-of band NAC in my LAN but I have problem for which I don't seem to find any solutions.&lt;/P&gt;&lt;P&gt;The problem is that NAC manager simply doesn't change switchport from authentication to access vlan although user&lt;/P&gt;&lt;P&gt;is authenticated and all CAA requirements have been met.&lt;/P&gt;&lt;P&gt;I connect my laptop to switch and NAM changes vlan to auth. vlan and laptop gets IP address from access vlan (vlan mapping&lt;/P&gt;&lt;P&gt;configured on NAM). Then CCA login pops out and I enter username and password. After that CAA says: "Successfully logged in&lt;/P&gt;&lt;P&gt;to network" but laptop stays in auth. vlan and I can see my user in "out of band" users list (on NAM) but laptop (his MAC address) is not&lt;/P&gt;&lt;P&gt;in the certified devices list. And Manager keeps it in auth. vlan. So when I click OK in CAA, the login window pops out again because I'm still&lt;/P&gt;&lt;P&gt;in authentication vlan.&lt;/P&gt;&lt;P&gt;What could be the problem? I really tried everything and I don't know why manager doesn't put laptop to certified devices list (I repeat, user is in out&lt;/P&gt;&lt;P&gt;of band users list) and CCA says successfully logged in to network, and all requirements are met too.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453574#M827812</guid>
      <dc:creator>zoran.suica</dc:creator>
      <dc:date>2020-02-21T11:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453575#M827838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zoran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the SNMP strings to ensure you have everything set right on the CAM and the switches. First thought suggests that the CAM is unable to write to the switch, which means your RW strings might be messed up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Apr 2010 20:08:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453575#M827838</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-04-28T20:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453576#M827866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for quick answer. SNMP is ok because when I manually enter access vlan in NAM, NAM sets port to that vlan. And then&lt;/P&gt;&lt;P&gt;again when I connect my laptop to that port, NAM again changes vlan to authentication. So that seems to be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I do not see laptops MAC in certified devices list so I think that is the reason why NAM doesn't put port to access vlan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Apr 2010 20:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453576#M827866</guid>
      <dc:creator>zoran.suica</dc:creator>
      <dc:date>2010-04-28T20:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453577#M827884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zoran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have a managed subnet entry for the subnet you're working with? Please post screenshots of your CAS config pages, your SNMP Receiver page and sanitized output from your switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 02:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453577#M827884</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-04-29T02:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453578#M827926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very much, yes that was the problem. I didn't have managed subnet entry. Now it works fine, but I have another problem. When I added managed&lt;/P&gt;&lt;P&gt;subnet I cannot connect to NAC server from my PC which has IP address from that subnet range. I cannot ping neither connect via https, totally&lt;/P&gt;&lt;P&gt;inaccessible.&lt;/P&gt;&lt;P&gt;What can I do to have that managed subnet entry, and still to be able to connect to server from that subnet (VLAN)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried adding managed subnet entry with auth. vlan (400) and then with access vlan (110) and no-vlan (-1) but the situation is same - clean access&lt;/P&gt;&lt;P&gt;works fine, but I cannot reach server from my PC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 11:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453578#M827926</guid>
      <dc:creator>zoran.suica</dc:creator>
      <dc:date>2010-04-29T11:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAC manager doesn't change auth vlan to access vlan</title>
      <link>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453579#M827943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zoran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is as expected. If your client is in one of the managed subnet, then by default the CAS sends out all traffic through it's untrusted interface. That's why when you're already authenticated, and you try to access the CAS, the replies to those queries/attempts would go out the untrusted interface and never reach your client back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 15:40:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-manager-doesn-t-change-auth-vlan-to-access-vlan/m-p/1453579#M827943</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-04-29T15:40:46Z</dc:date>
    </item>
  </channel>
</rss>

