cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1500
Views
0
Helpful
5
Replies

Cisco NAC users don't get IP address

a7med_magdy
Level 1
Level 1

I have Cisco NAC server ,this is my configuration :NAC - IB - VG

users vlans: 10 ,30 , 60

authentication vlan : 11 ,31 , 61 respectively

I have added the managed subnets after doing the vlan Mapping to these vlans

and then I have added vlans 10,30,60 to the trusted interface of the CAS then add

vlans 11,31,and 61 to the Untruste side .

there is no interface vlan for the authentication vlans.

the only one work is vlan 10,and its authentication vlan 11

but other vlans : users on it doesn't get IP address. the confguration under the access ports is

the vlan of the authentication

I wonder where is the problem , why only one vlan works and users get IP address and the redirection

works fine.but when I try to do the same for vlans : 30 & 60 users don't get IP address.

5 Replies 5

Tiago Antunes
Cisco Employee
Cisco Employee

Hi,

Have you created the DHCP pools for all the VLANs?

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

yes we have DHCP pools configured for these vlans and tested

Hi,

Can you send us screenshots of the VLAN mapping and managed subnets screen?

Also, the show run from the switch where the CAS is connected would be great.

HTH,
Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

thank you Tiago for your reply but I am sure my configuration is correct

after I have deleted the vlan mapping and managed subnet and added it again

several times , suddenly it works and users can take IP address . I didn't add

any configuration .

it is just work without adding any configuration , what do you think the problem was?

hi,

It is hard to tell, as we do not have any data to compare the before and after your re-config...but for sure was there something missing...or a simple typo is an IP address...a check box missing...etc.

Good that it is working now.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

Review Cisco Networking for a $25 gift card