09-08-2014 01:41 AM - edited 03-10-2019 10:00 PM
Dear guys,
I have problem in my lab case like sequence below:
In addition:
I will be grateful for any help you can provide.
Have a nice day !
09-08-2014 09:08 AM
Symptom:
Revocation failed dialog box keeps popping up on client machine despite of clicking "Yes" button
Conditions:
This issue is seen on the client machine performing login either using Windows agent or NAC web agent. The issue happens when the Clean Access Server (CAS) certificate root CA is not listed in the trusted store on the client machine. The issue is known to be reproducible on all flavors of Win XP & Win Vista using Windows or NAC web agent
Workaround:
Try selecting Yes. If this does not work you can turn off the security certificates revocation check by changing the options in Internet Explorer IE.
Use the following procedure to change the option in IE:
1. Launch IE
2. From the tool bar, select Tools then Internet Options
3. Select the Advanced tab
4. In the Security section, un-check the option "Check for server certificate revocation"
5. Click on the Apply button
6. Click on the OK button
7. Close IE
8. Try the web login again
Known Affected Releases: | (1) |
09-08-2014 07:20 PM
Dear mohanak,
Thank you for your help.
But i have already configured the option "Check for server certificate revocation". The error stil happens.
In addition, my product is Cisco ISE.
Thanks !
09-16-2014 04:00 AM
What version of web / NAC agent is this ? Please try upload the NAC agent from local machine and see of the problem solved. We need to exclude any corruption while uploading the agent to ISE.
10-09-2014 02:58 PM
09-16-2014 12:56 AM
Dear mohanak,
When guest access to guest portal for installing web agent. I got a error like this :
Base on "Table 11-4 Java Server Page Status Codes from ActiveX Control or Java Downloader Applet " at link : "http://www.cisco.com/c/en/us/td/docs/security/nac/appliance/configuration_guide/49/cam/49cam-book/m_report.html#wpxref71558"
Anyone got this error ? How i can debug and reslove this error ?
My current ISE version: 1.2.1.198 patch 1.
I will be grateful for any help you can provide.
I would greatly appreciate any help you can give me in working this problem
10-09-2014 02:56 PM
Hi;
Are you using the hostname identical to the canonical name that you have in the certificate?
If the CN of the certificate is CN=isepsn01.cisco.com you shoul be using a redirect URL like,
http://isepsn01.cisco.com:8443 and not http://10.1.1.1 .
Regards;
09-18-2014 07:11 PM
This could be bug
05-08-2015 01:23 AM
Check the ACL or dACL for the switch OR the ACL on wireless LAN controller, when the Post status on ISE is "Pending".
You need to allow tcp/8443, udp/8905 and tcp/8905 traffic to the IP address of ISE.
TCP/8443 is for the web-redirection
UDP/8905 + TCP/8905 is for posture (NAC)
This should solve the issue, hopefully ;-)
05-13-2015 04:11 AM
your redirection acl should look something like this
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Hi;
Are you using the hostname identical to the canonical name that you have in the certificate?
If the CN of the certificate is CN=isepsn01.cisco.com you shoul be using a redirect URL like,
http://isepsn01.cisco.com:8443 and not http://10.1.1.1 .
Regards;