<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Implementation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528192#M834126</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vikram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you fix the things I detailed? Can you share your certificate setups on CAS and CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Sep 2010 14:56:57 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2010-09-16T14:56:57Z</dc:date>
    <item>
      <title>NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528188#M834110</link>
      <description>&lt;P&gt;I have configuired nac but login page when i am entering user name password then password field becom empty and nothing happend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/18&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk native vlan 998&lt;BR /&gt; switchport trunk allowed vlan 507,513,540&lt;BR /&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/15&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk native vlan 999&lt;BR /&gt; switchport trunk allowed vlan 504&lt;BR /&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User in VLAN 513&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528188#M834110</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2020-02-21T12:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528189#M834115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;reply if any thinf missing&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 12:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528189#M834115</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-14T12:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528190#M834120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vikram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share what your certs look like on the CAS and the CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, your managed subnet is for VLAN 501, and your mappings are for 504-&amp;gt;513.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're also requiring the web agent AND the agent on the unauthenticated role which doesn't make sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also have the Web Login options turned on for the consultant role. These are used only for Nessus scanning, so you should turn those off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please fix these and send me what your certs look like from both the CAM and the CAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 21:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528190#M834120</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-14T21:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528191#M834123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OfficeDocumentSettings&gt; &lt;o:AllowPNG&gt;&lt;/o:AllowPNG&gt; &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;I am getting user login page but when I am trying to enter user name and password&lt;/P&gt;&lt;P class="MsoNormal"&gt;Password box got blank and nothing happened, What settings I should check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 10:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528191#M834123</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-16T10:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528192#M834126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vikram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you fix the things I detailed? Can you share your certificate setups on CAS and CAM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 14:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528192#M834126</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-16T14:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528193#M834129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have followed the proces...&lt;/P&gt;&lt;P&gt;without adding management subnet i was able to ping gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now(after Changes) I am not able to ping nac server as well as gateway&lt;/P&gt;&lt;P&gt;please find the attachements&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Consultant VLAN- 513&amp;nbsp;&amp;nbsp; IP - 10.20.20.0&lt;/P&gt;&lt;P&gt;Untrusted- 504 NO IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L2&lt;/P&gt;&lt;P&gt;interface FastEthernet0/46&lt;BR /&gt; switchport access vlan 504&amp;nbsp;&amp;nbsp; ***** Consultant PC******&lt;SPAN style="color: #ff0000;"&gt; ( It Should Consultant VLAN 513 or untrusted VLAN 504)&lt;/SPAN&gt;&lt;BR /&gt; switchport mode access&lt;BR /&gt; snmp trap mac-notification added&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L3&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/15&amp;nbsp;&amp;nbsp; **** NAC Srv untrusted***&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk native vlan 999&lt;BR /&gt; switchport trunk allowed vlan 501,504&lt;BR /&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/18&amp;nbsp;&amp;nbsp; ***** NAC Srv Trusted****&lt;BR /&gt; switchport trunk encapsulation dot1q&lt;BR /&gt; switchport trunk native vlan 998&lt;BR /&gt; switchport trunk allowed vlan 507,513,540&lt;BR /&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/10&amp;nbsp;&amp;nbsp; ***** NAC Mgr ****&lt;BR /&gt; switchport access vlan 506&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route&lt;/P&gt;&lt;P&gt;10.0.0.0 10.1.8.2&amp;nbsp; ( 10.1.8.2- Firewall IP )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Sep 2010 11:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528193#M834129</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-17T11:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528194#M834131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vikram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please turn the checkbox marked "Enable Subnet-Based VLAN retag" off, reboot your CAS and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Sep 2010 12:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528194#M834131</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-19T12:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528195#M834134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Faisal Bhai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you...............&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 04:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528195#M834134</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-20T04:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528196#M834137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;wireless user is not able to authenticate getting following error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to process out-of-band login request from [00:21:5D:80:9C:00 ##&amp;nbsp; 10.20.20.5] vikram. Cause: OOB client 00:21:5D:80:9C:00/10.20.20.5 not found.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 11:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528196#M834137</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-21T11:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528197#M834139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vikram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you added a trap-receiver in your WLC? The error means CAM didn't get the trap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 14:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528197#M834139</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-21T14:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528198#M834142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi faisal there was the mismatch the community name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thankssss.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Sep 2010 15:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528198#M834142</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-21T15:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528199#M834145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some times user is not able to ping nac server thats why they&amp;nbsp; are not able to redirect to nac server&lt;/P&gt;&lt;P&gt;user is getting directly internet connection&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 14:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528199#M834145</guid>
      <dc:creator>k_vikrams</dc:creator>
      <dc:date>2010-09-29T14:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Implementation</title>
      <link>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528200#M834148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another issue I have found that results in this error is two MAC addresses showing up in the cam table of the switch.&amp;nbsp; If the first one to show up is not the one used when the user tried to authenticate it will result in this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can verify the cam entries either from the switch or from OOB Management --&amp;gt; Devices.&amp;nbsp; Look at the Client MAC entry for the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Haven't quite figured out how/why the device has two MAC addresses but that is the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2011 16:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-implementation/m-p/1528200#M834148</guid>
      <dc:creator>cbradt</dc:creator>
      <dc:date>2011-03-24T16:48:10Z</dc:date>
    </item>
  </channel>
</rss>

