11-27-2018 04:23 AM - edited 03-11-2019 01:52 AM
Hello all,
I have a ISE appliance installed in a STANDALONE deployment, the node has the three personas installed on it (Administration, Monitoring, Policy)
When I try to do my tests via the câble, the cisco NAC agent doesn't popup for the verification of the posture to know if the equipment complies with the policy defined in order to be able to access the Internet or not.
I need your help to solve the problem.
Note: the NAC agent version is the following: 4.9.5.8, the Cisco ISE version is 2.0.0.306
ACLs defined in Cisco ISE :
permit udp any host x.x.x.z eq domain (AD server)
permit tcp any host x.x.x.y eq 8443 (ISE server)
permit tcp any host x.x.x.y eq 8905
permit udp any host x.x.x.y eq 8905
permit udp any host x.x.x.y eq 8906
permit udp any host x.x.x.y eq 8909
permit tcp any host x.x.x.y eq 8909
deny tcp any host x.x.x.z eq 3389
deny ip any any
ACLs defined in Cisco Switch :
deny udp any host x.x.x.z eq domain
deny tcp any host x.x.x.y eq 8443
deny tcp any host x.x.x.y eq 8905
deny udp any host x.x.x.y eq 8905
deny udp any host x.x.x.y eq 8906
deny udp any host x.x.x.y eq 8909
deny tcp any host x.x.x.y eq 8909
deny tcp any host x.x.x.z eq 3389
permit ip any any
Regards.
Solved! Go to Solution.
11-29-2018 08:22 AM
11-27-2018 05:30 AM
Better to work through TAC. NAC agent is EOL now.
Thanks,
Nidhi
11-27-2018 08:02 AM - edited 11-27-2018 11:56 PM
Hello Nidhi,
Thank you for your reply. But I need it to work with the NAC agent that was already installed on all user machines.
Regards.
11-28-2018 01:30 AM
11-28-2018 02:59 AM
Hello Surendra,
Thank you for you reply. When I plug the cable I get an IP adresse but the NAC client Can't Pop up.
When I try to open a Case on Cisco TAC I get this error message : "Contract Not Associated
This serial number FCH1945V0T3 is covered under a service contract not linked to your account. Would you like to add this contract now? "
.
Regards.
11-28-2018 03:03 AM
11-29-2018 08:18 AM
Hello Surendra,
I can not open a ticket on the Cisco site. I get the error message when I try to open a Case on Cisco TAC :
The message is the following :"Contract Not Associated
This serial number FCH1945V0T3 is covered under a service contract not linked to your account. Would you like to add this contract now? "
Regards.
11-29-2018 08:22 AM
12-03-2018 08:55 AM
Good afternoon all,
After a complete review of the configuration of the ISE and the switch, I think my problem is at the certificate level. I have the following error message at the certificate level in ISE "Certificate trust chain is incomplete".
Who can help me solve the problem.
Regards.
11-28-2018
02:59 AM
- last edited on
11-29-2018
08:26 AM
by
Jason Kunst
Hello Surendra,
Thank you for you reply. When I plug the cable I get an IP adresse but the NAC client Can't Pop up.
When I try to open a Case on Cisco TAC I get this error message : "Contract Not Associated
This serial number is covered under a service contract not linked to your account. Would you like to add this contract now? "
.
Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide