<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC OOB logoff feature not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593585#M832192</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've deployed NAC in L2 OOB VG mode with ADSSO and I'm trying to use the OOB logoff feature but it's not working. The VLAN change detect feature doesn't work either (I think the two problems might be related).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will work if each user role is assigned a different auth/access VLAN pair but in my setup, everyone has a common auth vlan and separate role-based access vlans. Because of this, I have to use the IP refresh feature as well (this works fine).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running Windows Vista and version 4.8.0 of the NAC software with version 4.8.1.5 of the agent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the release notes and found that caveat CSCth60233 identifies this bug with the VLAN change detect with the workaround being to refresh the IP address automatically after being logged out. Does anyone know of a workaround for this problem to do this automatically? Is a solution for this problem in the works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also would anyone be able to help me with my OOB logoff feature not working? I've configured everything according to the documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your responses&lt;/P&gt;&lt;P&gt;~Xavier&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:14:47 GMT</pubDate>
    <dc:creator>Xavier Lloyd</dc:creator>
    <dc:date>2020-02-21T12:14:47Z</dc:date>
    <item>
      <title>NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593585#M832192</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've deployed NAC in L2 OOB VG mode with ADSSO and I'm trying to use the OOB logoff feature but it's not working. The VLAN change detect feature doesn't work either (I think the two problems might be related).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will work if each user role is assigned a different auth/access VLAN pair but in my setup, everyone has a common auth vlan and separate role-based access vlans. Because of this, I have to use the IP refresh feature as well (this works fine).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running Windows Vista and version 4.8.0 of the NAC software with version 4.8.1.5 of the agent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the release notes and found that caveat CSCth60233 identifies this bug with the VLAN change detect with the workaround being to refresh the IP address automatically after being logged out. Does anyone know of a workaround for this problem to do this automatically? Is a solution for this problem in the works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also would anyone be able to help me with my OOB logoff feature not working? I've configured everything according to the documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your responses&lt;/P&gt;&lt;P&gt;~Xavier&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:14:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593585#M832192</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2020-02-21T12:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593586#M832204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are my configs if necessary. Tell me if anything else is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0" class="subtitle"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="80%"&gt;&lt;P&gt;User Management &amp;gt; User Roles&lt;/P&gt;&lt;/TD&gt;&lt;TD align="right" width="20%"&gt;&lt;INPUT name="logout" src="https://community.cisco.com/" title="Logout 'admin'" type="image" /&gt; &lt;INPUT name="adminid" type="hidden" value="8AFF5B5D4BEEF729DB6AE5B75FEB0FF3" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2"&gt;&lt;HR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0" style="margin-left: 5px;" width="99%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="inactive_tab" width="17%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/rolelist.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt;List of Roles&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="active_tab" width="17%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/rolemgt.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Edit Role &lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="17%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/securitypolicy.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt;Traffic Control&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="17%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/bwpolicylist.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt;Bandwidth&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="17%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/timepolicylist.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt;Schedule&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="active_tab" colspan="10"&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="4" cellspacing="0" style="font-family: verdana; font-size: 9pt; width: 98%; margin-left: 9px;"&gt;&lt;FORM name="rolemgmt"&gt;&lt;/FORM&gt; &lt;INPUT name="rid" type="hidden" value="3" /&gt; &lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2"&gt;&lt;INPUT name="disableRole" type="checkbox" value="OFF" /&gt; Disable this role&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Role Name&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="rname" size="30" type="text" value="role_engineer" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Role Description&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="rdesc" size="30" type="text" value="Syncon engineer users" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Role Type&lt;/TD&gt;&lt;TD&gt;&lt;SELECT name="rtype" size="1"&gt; &lt;OPTION selected="selected" value="1"&gt;Normal Login Role&lt;/OPTION&gt; &lt;OPTION value="2"&gt;Quarantine Role&lt;/OPTION&gt; &lt;/SELECT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;*Max Sessions per User Account&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (&lt;INPUT name="showcase" type="checkbox" value="ON" /&gt; Case-Insensitive Session Identifiers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; )&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="max" size="15" type="text" value="0" /&gt; &lt;SPAN style="color: #003399; font-size: 8pt;"&gt; (1 – 255; 0 for unlimited) &lt;/SPAN&gt;&amp;nbsp; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retag Trusted-side Egress Traffic with VLAN (In-Band)&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="ib_vlan" size="15" type="text" /&gt; &lt;SPAN style="color: #003399; font-size: 8pt;"&gt; (0 – 4095, or leave it&amp;nbsp; blank)(*This option has been deprecated, and it will be removed in&amp;nbsp; upcoming&amp;nbsp; releases) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;*Out-of-Band User Role VLAN&lt;/TD&gt;&lt;TD&gt;&lt;SELECT name="oob_vlan_type"&gt; &lt;OPTION selected="selected" value="0"&gt; VLAN ID &lt;/OPTION&gt; &lt;OPTION value="1"&gt; VLAN Name &lt;/OPTION&gt; &lt;/SELECT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="oob_vlan" size="15" type="text" value="14" /&gt; &lt;SPAN style="color: #003399;"&gt; (if left blank, it will default to the default access vlan&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; settings in the Port Profile) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;*Bounce Switch Port After Login (OOB)&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="swbouncing" type="radio" value="1" /&gt; Enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT checked="checked" name="swbouncing" type="radio" value="0" /&gt; Disable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #003399;"&gt; (This option is effective only when port profile is set to use it) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;*Refresh IP After Login (OOB)&lt;/TD&gt;&lt;TD&gt;&lt;INPUT checked="checked" name="iprefresh" type="radio" value="1" /&gt; Enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="iprefresh" type="radio" value="0" /&gt; Disable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #003399;"&gt; (This option only applies to L2 OOB Virtual Gateway with Role VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as Access VLAN and switch port is NOT bounced after VLAN change) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top"&gt;*After Successful Login Redirect to&lt;/TD&gt;&lt;TD&gt;&lt;INPUT checked="checked" name="redirect" type="radio" value="0" /&gt; previously requested URL &lt;BR /&gt; &lt;INPUT name="redirect" type="radio" value="1" /&gt; this URL: &lt;BR /&gt; &lt;TEXTAREA name="redirectUrl" rows="2" style="width: 100%;"&gt;&lt;/TEXTAREA&gt; &lt;SPAN style="color: #003399;"&gt;&lt;SPAN&gt; (e.g. &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/"&gt;http://www.cisco.com/&lt;/A&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top"&gt;Redirect Blocked Requests to&lt;/TD&gt;&lt;TD&gt;&lt;INPUT checked="checked" name="block" type="radio" value="0" /&gt; default access blocked page &lt;BR /&gt; &lt;INPUT name="block" type="radio" value="1" /&gt; this URL or HTML message:&lt;BR /&gt; &lt;TEXTAREA name="blockUrl" rows="2" style="width: 100%;"&gt;&lt;/TEXTAREA&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top"&gt;*Show Logged-on Users&lt;/TD&gt;&lt;TD&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="font-family: verdana; font-size: 9pt; width: 80%; margin-left: 0px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;INPUT checked="checked" name="showrole" type="checkbox" value="ON" /&gt; User info&lt;/TD&gt;&lt;TD&gt;&lt;INPUT checked="checked" name="showlogout" type="checkbox" value="ON" /&gt; Logout button&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2"&gt;&lt;INPUT checked="checked" name="togglePrA" type="checkbox" value="ON" /&gt; Enable Passive Re-assessment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #003399;"&gt; (To enable Passive Re-assessment for OOB Agent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; connections, you must also enable the OOB Logoff option at&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device Management &amp;gt; Clean Access &amp;gt; General Setup &amp;gt; Agent Login.)&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Re-assessment Interval&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="praInterval" size="4" type="text" value="240" /&gt; &lt;SPAN style="color: #003399; font-size: 8pt;"&gt; (Minimum of 60 minutes and maximum of 1440 minutes [24 hours]) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Grace Timer&lt;/TD&gt;&lt;TD&gt;&lt;INPUT name="graceTimer" size="4" type="text" value="5" /&gt; &lt;SPAN style="color: #003399; font-size: 8pt;"&gt; (Minimum of 5 minutes and maximum of 30 minutes) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Default action on failure&lt;/TD&gt;&lt;TD&gt;&lt;SELECT name="actionOnFailure"&gt; &lt;OPTION selected="selected" value="0"&gt;Continue&lt;/OPTION&gt; &lt;OPTION value="1"&gt;Allow user to remediate&lt;/OPTION&gt; &lt;OPTION value="2"&gt;Logoff user immediately&lt;/OPTION&gt; &lt;/SELECT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;&amp;nbsp; &lt;BR /&gt; &lt;INPUT name="addrole" type="submit" value="Save Role" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="caneditrole" type="submit" value="&amp;nbsp;&amp;nbsp;&amp;nbsp; Cancel&amp;nbsp;&amp;nbsp;&amp;nbsp; " /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2"&gt;&lt;SPAN style="color: #003399;"&gt; (*only applies to normal login role) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0" class="subtitle"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="80%"&gt;Device Management &amp;gt; Clean Access&lt;/TD&gt;&lt;TD align="right" width="20%"&gt;&lt;INPUT alt="Logout 'admin'" name="logout" src="https://community.cisco.com/" title="Logout 'admin'" type="image" /&gt; &lt;INPUT name="adminid" type="hidden" value="8AFF5B5D4BEEF729DB6AE5B75FEB0FF3" /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2"&gt;&lt;HR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="2" cellspacing="0" style="margin-left: 5px; font-family: verdana;" width="98%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="inactive_tab" width="20%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/macfilterlist.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Certified Devices&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="active_tab" width="20%"&gt;&lt;A class="active_tablink" href="https://172.16.0.203/admin/nsplugin.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; General Setup&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="20%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/nsplugins.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Network Scanner&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="20%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/dmconfig.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Clean Access Agent&lt;/A&gt;&lt;/TD&gt;&lt;TD width="1%"&gt; &lt;/TD&gt;&lt;TD class="inactive_tab" width="20%"&gt;&lt;A class="tablink" href="https://172.16.0.203/admin/dmsummary.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Updates&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="active_subtab" colspan="10"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A class="subtablink" href="https://172.16.0.203/admin/nsplugin.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Web Login&lt;/A&gt;&amp;nbsp;&amp;nbsp; ·&amp;nbsp; &lt;A class="active_subtablink" href="https://172.16.0.203/admin/agentsetup.jsp?CCA_TOKEN=po7OqMN3g9O0OFR5mJnwerTv0K*-OndZ1mNbzUh9Sv8."&gt; Agent Login&lt;/A&gt;&amp;nbsp; &lt;/TD&gt;&lt;/TR&gt;&lt;FORM name="theform"&gt;&lt;/FORM&gt; &lt;INPUT name="sw" type="hidden" value="no" /&gt; &lt;TR style="font-size: 9pt;"&gt;&lt;TD colspan="8"&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR style="font-size: 9pt;"&gt;&lt;TD&gt;User Role&lt;/TD&gt;&lt;TD colspan="7"&gt;&lt;SELECT id="role" name="role" size="1"&gt; &lt;OPTION value="0"&gt; Unauthenticated Role(not common)&lt;/OPTION&gt; &lt;OPTION selected="selected" value="3"&gt; role_engineer&lt;/OPTION&gt; &lt;OPTION value="4"&gt; role_developer&lt;/OPTION&gt; &lt;OPTION value="5"&gt; role_admin&lt;/OPTION&gt; &lt;OPTION value="6"&gt; role_sales&lt;/OPTION&gt; &lt;OPTION value="7"&gt; role_guest&lt;/OPTION&gt; &lt;/SELECT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="font-size: 9pt;"&gt;&lt;TD&gt;Operating System&amp;nbsp; &lt;/TD&gt;&lt;TD colspan="7"&gt;&lt;SELECT id="os" name="os" size="1"&gt; &lt;OPTION selected="selected" value="ALL"&gt; ALL&lt;/OPTION&gt; &lt;OPTION value="WINDOWS_ALL"&gt; WINDOWS_ALL&lt;/OPTION&gt; &lt;OPTION value="WINDOWS_XP"&gt; WINDOWS_XP&lt;/OPTION&gt; &lt;OPTION value="WINDOWS_VISTA_ALL"&gt; WINDOWS_VISTA_ALL&lt;/OPTION&gt; &lt;OPTION value="WINDOWS_7_ALL"&gt; WINDOWS_7_ALL&lt;/OPTION&gt; &lt;OPTION value="MAC_ALL"&gt; MAC_ALL&lt;/OPTION&gt; &lt;OPTION value="MAC_OSX"&gt; MAC_OSX&lt;/OPTION&gt; &lt;OPTION value="LINUX"&gt; LINUX&lt;/OPTION&gt; &lt;OPTION value="FREEBSD"&gt; FREEBSD&lt;/OPTION&gt; &lt;OPTION value="SOLARIS_ALL"&gt; SOLARIS_ALL&lt;/OPTION&gt; &lt;OPTION value="SOLARIS_86"&gt; SOLARIS_86&lt;/OPTION&gt; &lt;OPTION value="SOLARIS_SPARC"&gt; SOLARIS_SPARC&lt;/OPTION&gt; &lt;OPTION value="UNIX"&gt; UNIX&lt;/OPTION&gt; &lt;OPTION value="VMS"&gt; VMS&lt;/OPTION&gt; &lt;OPTION value="OS2"&gt; OS2&lt;/OPTION&gt; &lt;OPTION value="PALM"&gt; PALM&lt;/OPTION&gt; &lt;/SELECT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="font-size: 9pt;"&gt;&lt;TD colspan="8"&gt;&lt;INPUT name="usedefault" type="hidden" value="OFF" /&gt; &lt;SPAN style="font-family: verdana; color: #003399; font-size: 8pt;"&gt; (By default, 'ALL' settings apply to all client operating systems if no OS-specific settings are specified.) &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;INPUT id="role" name="role" type="hidden" value="3" /&gt;&lt;P&gt;&lt;/P&gt;&lt;INPUT id="os" name="os" type="hidden" value="ALL" /&gt;&lt;P&gt;&amp;nbsp; &lt;INPUT checked="checked" id="ooblogoff" name="ooblogoff" type="checkbox" value="ON" /&gt;&lt;/P&gt;&lt;P&gt;Enable OOB logoff for Windows NAC Agent and Mac OS X Agent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="font-family: verdana; color: #003399; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp; (This global option applies to all OOB CASs and user roles and&amp;nbsp; enables Agent logout and heartbeat timers for OOB Agent connections. You&amp;nbsp; must also enable this option for Passive Re-assessment to function with&amp;nbsp; OOB Agent connections.) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INPUT checked="checked" id="dmenforce" name="dmenforce" type="checkbox" value="ON" /&gt; Require use of Agent&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;(for Windows &amp;amp; Macintosh OSX only)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;Agent Download Page Message (or URL): &lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;TEXTAREA cols="60" id="enforcetext" name="enforcetext" rows="3"&gt;&amp;lt;b&amp;gt;Network&amp;nbsp; Security Notice:&amp;lt;/b&amp;gt; This network is protected by a Cisco NAC&amp;nbsp; Appliance Agent, a component of the Cisco NAC Appliance Suite. The Agent&amp;nbsp; ensures that your computer meets the requirements for accessing this&amp;nbsp; network, and helps you keep your computer secure and up-to-date.&amp;nbsp; &amp;lt;p&amp;gt;Please use the Agent to log in to the network. &amp;lt;p&amp;gt;If you&amp;nbsp; don't have the Agent software yet, download it by clicking the button&amp;nbsp; below. After downloading the installation file, run it to complete the&amp;nbsp; installation. &amp;lt;p&amp;gt;If you have already downloaded and installed the&amp;nbsp; Agent, please close this window and right-click the Agent icon in the&amp;nbsp; system tray and choose Login from the menu. Enter your usual network&amp;nbsp; user name and password in the login window.&lt;/TEXTAREA&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT checked="checked" id="taenforce" name="taenforce" type="checkbox" value="ON" /&gt;&lt;/P&gt;&lt;P&gt;Require use of Cisco NAC Web Agent &lt;SMALL&gt;(for Windows only)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SMALL&gt;Cisco NAC Web Agent Launch Page Message (or URL): &lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TEXTAREA cols="60" id="taenforcetext" name="taenforcetext" rows="3"&gt;&amp;lt;b&amp;gt;Network&amp;nbsp; Security Notice:&amp;lt;/b&amp;gt; This network is protected by the Cisco NAC&amp;nbsp; Web Agent, a component of the Cisco NAC Appliance Suite. The Cisco NAC&amp;nbsp; Web Agent ensures that your computer meets the requirements for&amp;nbsp; accessing this network, and helps you keep your computer secure and&amp;nbsp; up-to-date. &amp;lt;p&amp;gt;Please launch Cisco NAC Web Agent by clicking the&amp;nbsp; button below.&lt;/TEXTAREA&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INPUT checked="checked" id="dmtemp" name="dmtemp" type="checkbox" value="ON" /&gt; Allow restricted network access in case user cannot use&amp;nbsp;&amp;nbsp; NAC Agent or Cisco NAC Web Agent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restricted Access User Role:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SELECT id="dmtemprole" name="dmtemprole" size="1"&gt; &lt;OPTION value="3"&gt; role_engineer&lt;/OPTION&gt; &lt;OPTION value="4"&gt; role_developer&lt;/OPTION&gt; &lt;OPTION value="5"&gt; role_admin&lt;/OPTION&gt; &lt;OPTION value="6"&gt; role_sales&lt;/OPTION&gt; &lt;OPTION selected="selected" value="7"&gt; role_guest&lt;/OPTION&gt; &lt;/SELECT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restricted Access Button Text:&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;INPUT id="dmtempbtn" name="dmtempbtn" size="36" type="text" value="Get Restricted Network Access" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;Restricted Network Access Message: &lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;TEXTAREA cols="60" id="temptext" name="temptext" rows="3"&gt;&amp;lt;b&amp;gt;Restricted&amp;nbsp; Network Access:&amp;lt;/b&amp;gt; If you cannot use a Cisco NAC Appliance&amp;nbsp; Agent, you can obtain restricted network access temporarily by clicking&amp;nbsp; the button below.&lt;/TEXTAREA&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="shownetworkpolicy" type="checkbox" value="ON" /&gt;&lt;/P&gt;&lt;P&gt;Show Network Policy to NAC Agent and Cisco NAC Web Agent users &lt;SMALL&gt;(for Windows only)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Network Policy Link:&amp;nbsp;&amp;nbsp; &lt;INPUT name="networkpolicylink" size="50" type="text" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT checked="checked" name="logoffonexit" type="checkbox" value="ON" /&gt;&lt;/P&gt;&lt;P&gt;Logoff NAC Agent users from network on their machine logoff or shutdown after&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="delayedlogouttime" size="4" type="text" value="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; secs &lt;SMALL&gt;(for Windows &amp;amp; In-Band setup, for OOB setup when OOB Logoff is enabled)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana; color: #003399; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Setting the time to zero secs will logout user immediately. Valid range: 0 - 300 secs.) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INPUT checked="checked" name="gpupdate" type="checkbox" value="ON" /&gt; Refresh Windows domain group policy after login&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;(for Windows only)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INPUT checked="checked" name="autocloseloginscr" type="checkbox" value="ON" /&gt; Automatically close login success screen after&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;INPUT name="autocloseloginscrtime" size="4" type="text" value="5" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; secs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana; color: #003399; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Setting the time to zero secs will not display the login success screen. Valid range: 0 - 300 secs.) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INPUT checked="checked" name="autocloselogoutscr" type="checkbox" value="ON" /&gt; Automatically close logout success screen after&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;INPUT name="autocloselogoutscrtime" size="4" type="text" value="5" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; secs&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;(for Windows only)&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana; color: #003399; font-size: 8pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Setting the time to zero secs will not display the logout success screen. Valid range: 0 - 300 secs.) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;INPUT name="ok" type="submit" value="Update" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 21:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593586#M832204</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-02-10T21:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593587#M832207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I the out of band logoff feature is now working. It wasn't working before because the host couldn't communicate with the NAC Server for some reason. I didn't change any config but now it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the VLAN Change detect IP refresh is still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 15:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593587#M832207</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-02-15T15:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593588#M832214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Xavier&lt;/P&gt;&lt;P&gt;How is the host communicating wiht the NAC server ?&lt;/P&gt;&lt;P&gt;In OOB L2 VG, the agent is using swiss protocol (L2 8905 towards default-gateway or L3 8906 towards discovery host), but the nac server does not have an IP in your access-vlan, it only has a management adress i another vlan... &lt;/P&gt;&lt;P&gt;And the discovery host is common your CAM, so the agent wont reach your server on the trusted side.&lt;/P&gt;&lt;P&gt;Cisco sais that acl, pbr or vrf is the answer - but in and L2 oob non of these solutions would not work, because the nac server only has a management adress and no L3 conectivity to access vlan.&lt;/P&gt;&lt;P&gt;And if discovery host should be used - how is multible nac servers supportet ??&lt;/P&gt;&lt;P&gt;Can the cam tell the agent anything or forward the swiss packets ??&lt;/P&gt;&lt;P&gt;Am i missing something ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Henrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 21:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593588#M832214</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2011-06-20T21:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593589#M832224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Henrik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At that time, for some strange reason I could ping the NAC Server from the host...I'm not sure how or why but now I can't anymore so I guess that wasn't the real reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thinking about it, the NAC Server and the agent can't speak at all once I've authenticated because of the VLAN mapping and IP addressing. So it must be the NAC Manager that talks to the agent but I'm not sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd have to sniff my port to find out for sure but I don't know when I'll be able to do that because I'm doing some other testing with my machine and so my PC isn't configured for NAC at the moment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 22:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593589#M832224</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-06-20T22:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593590#M832231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Ok - but it is still working??&lt;/P&gt;&lt;P&gt;regards Henrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 07:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593590#M832231</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2011-06-21T07:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593591#M832235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes everything works except VLAN change detect on Windows Vista machines.&lt;/P&gt;&lt;P&gt;Things work fine on XP and Windows 7 but Vista gives a problem for some reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aside from that though, which I've learned to live with since I'm the only person in the office with Vista and I happen to be the NAC administrator. &lt;STRONG&gt;ipconfig /release &amp;amp;&amp;amp; ipconfig /renew&lt;/STRONG&gt; works just fine&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593591#M832235</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-06-21T13:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593592#M832242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.&lt;/P&gt;&lt;P&gt;When you rebooted the nacservers, did you do this from whithin tha CAM or did you just reboot from cas interface ?&lt;/P&gt;&lt;P&gt;can you still not ping cas-server (certificate subject name) form your host ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Henrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593592#M832242</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2011-06-21T13:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593593#M832252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When rebooting NAC server I do it from the Manager interface because I can't communicate with the NAC Server from my computer any at all. No HTTP, no ping, no nothing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593593#M832252</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-06-21T13:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593594#M832258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thanks&lt;/P&gt;&lt;P&gt;I´ll try rebooting my cas´s from the cam, to see if this works (before i did it from a server vlan directly on cas).&lt;/P&gt;&lt;P&gt;Do you run a HA setup (both cas/cam) ?&lt;/P&gt;&lt;P&gt;Regards Henrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593594#M832258</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2011-06-21T13:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593595#M832266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No I'm not running HA.&lt;/P&gt;&lt;P&gt;What's your problem exactly though?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~ Xavier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 14:01:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593595#M832266</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-06-21T14:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593596#M832274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My problem is that oob-logoff doesn´t work.&lt;/P&gt;&lt;P&gt;When i enable oob-logoff on cam and reboot cas´s, and then do a " netstat -unl | egrep -w '890[12]' ", i don´t se the cas´s listening on udp 8901/8902...&lt;/P&gt;&lt;P&gt;Does your cas listen on those ports ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(and i still don´t understand how agent talkes to cam/cas (cisco sais it should be cas...))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Henrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 14:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593596#M832274</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2011-06-21T14:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: NAC OOB logoff feature not working</title>
      <link>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593597#M832281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't access the console of either the NAC manager or server right&amp;nbsp; now. I changed the password and forgot what it was and I haven't done&amp;nbsp; the password recovery yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the mean time, what operating system are you running on your host(s)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I don't really understand the communication either...I'll try to sniff my port and see what communication goes on)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Xavier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 17:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-oob-logoff-feature-not-working/m-p/1593597#M832281</guid>
      <dc:creator>Xavier Lloyd</dc:creator>
      <dc:date>2011-06-21T17:00:12Z</dc:date>
    </item>
  </channel>
</rss>

