06-02-2008 10:57 AM - edited 02-21-2020 02:02 AM
I have a Out of Band NAC deployment in a test sandbox network. I have set up a basic check for Symantec Antivirus 10.0 and current definitions using the Clean Access agent. My switch configuration is correct, authentication works properly and by looking at the report that is generated by the Clean Access agent on my test machine, I can see that the machine is passing posture validation. I am also having the Clean Access agent itself tell me that I have successfully logged into the network. However, the device is not showing up in the certified list, so therefore the machine never gets put into the Access VLAN (I can tell this from looking at the ports configuration on the switch from the CAM) Because it never gets put in the Access VLAN, the Agent just keps popping back up asking me to login even though I have successfully logged in.
Does anyone have any experience with why a device would not show up in the certified device list even though the Clean Access Agent tells me the device has passed posture validation?
06-02-2008 06:01 PM
If you are using in a L3 deployment, make sure that you have a discovery host IP. This should be the address of CAM or CAM cluster.
To find out right click on CCA and select properties.
06-03-2008 03:08 AM
The discovery host is there
06-03-2008 04:21 AM
Can you see snmp messages in the syslog of the switch showing the the CAM is trying to communicate via SNMP?
In your port profile, do the access\authentication VLANs match up with the switch settings?
Under Options: Device Connected to Port in bounce the port after VLAN being changed checked?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide