We have NAC version 4.8.0 and the agent version is 18.104.22.168. The deployment type is Out-Of-band virtual gateway. Windows SSO is enable and working as a champion but the problem is when the agent successfully login the users the CAM logs out it after a while (NAC agent pop up again) I found that the switch port is changed back to the unauthenticated VLAN by the CAM and then to the access VLAN.
The host under testing: IP 10.30.8.207, MAC 78:E7:D1: CD: D8:8A and the switch port is 10048 (FA0/48)
The log for kicking out the user is:
2011-03-09 13:15:30.450 +0300 [Timer-199783] DEBUG c.p.wlan.web.admin.DelayedOobLogoutInfoManager- DLIM: delete DLI for 10.30.8.207 from CAS user_key='10.30.8.207_VTMJDKPIR41ABQLT'
2011-03-09 13:15:57.335 +0300 [TP-Processor24] TRACE com.perfigo.wlan.web.sms.SnmpTimerTask- SnmpTimerTask com.perfigo.wlan.web.sms.task.SwitchCertifiedTask id=2004989 is created: set port  to Access VLAN  on switch [10.1.40.14] for [78:E7:D1:CD:D8:8A]
I don’t know the meaning of “DLIM: delete DLI for 10.30.8.207 from CAS” and why this is happening. Would you please help?
So, I had a similar problem with my Out-of-Band Real-IP-Gateway deployment. The reason was that NAC agent was still commnicating with untrusted interface of the NAC server, after logging in with Windows AD login/password. And of course, NAC agent pop up again, after client successfully looged in with active directory login\password, and his computer were transferring from "auth" vlan to "access" vlan.
Cisco experts says, that it's better to brake communication between NAC agent and NAC server, if the client machine is in access vlan. You can implement, for example, an access-list for "access" vlan. The goal of that access-list is to deny all packets destined for NAC server, and permit all other packets.
What is SecureX?
Cisco SecureX is included with all Secure Endpoint (formerly AMP for Endpoints) subscriptions. SecureX is a cloud-native platform that aggregates capabilities across your security environment. It’s designed to simplify your environment, ...
Cisco ISE Secure Wired Access Prescriptive Deployment Guide
Authors: Hariprasad Holla (until June 2018), Mahesh Nagireddy (until Dec 2018)
For an offline or printed copy of this document, simply choose ⋮ Options > Printer ...
Meet the Authors Slides- SecureX and the Evolution of Security Orchestration Automation and Response
(Live event – Wednesday, 20th, 2021 at 10:00 a.m. Pacific / 1:00 p.m. Eastern / 6:00 p.m. Paris)
This event had place on Wednesday 20th, January 202...
The following guide goes over the in and out of the Cisco Endpoints Security Analytics Dashboard as an overview and faq page
For more information on the product offering, licensing, support, and how to solution (TAC) guide links and more please visit the...
Join us live on Tuesday, January 19 at 10:00 am PT (and on demand after) as we discuss the latest version of ATT&CK and the expansion of TTPs in v8.
As a security expert, you are tasked with protecting your environment. You see the value of...