09-14-2010 02:50 AM - edited 02-21-2020 04:05 AM
I have configuired nac but login page when i am entering user name password then password field becom empty and nothing happend
interface GigabitEthernet1/0/18
switchport trunk encapsulation dot1q
switchport trunk native vlan 998
switchport trunk allowed vlan 507,513,540
switchport mode trunk
interface GigabitEthernet1/0/15
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport trunk allowed vlan 504
switchport mode trunk
User in VLAN 513
Solved! Go to Solution.
09-19-2010 05:54 AM
Vikram,
Please turn the checkbox marked "Enable Subnet-Based VLAN retag" off, reboot your CAS and try again.
Thanks,
Faisal
09-21-2010 07:05 AM
Vikram,
Have you added a trap-receiver in your WLC? The error means CAM didn't get the trap.
Faisal
09-14-2010 05:02 AM
reply if any thinf missing
09-14-2010 02:19 PM
Vikram,
Can you share what your certs look like on the CAS and the CAM?
Also, your managed subnet is for VLAN 501, and your mappings are for 504->513.
You're also requiring the web agent AND the agent on the unauthenticated role which doesn't make sense.
You also have the Web Login options turned on for the consultant role. These are used only for Nessus scanning, so you should turn those off.
Please fix these and send me what your certs look like from both the CAM and the CAS.
Faisal
09-16-2010 03:54 AM
I am getting user login page but when I am trying to enter user name and password
Password box got blank and nothing happened, What settings I should check
09-16-2010 07:56 AM
Vikram,
Did you fix the things I detailed? Can you share your certificate setups on CAS and CAM?
Faisal
09-17-2010 04:57 AM
Hi faisal
I have followed the proces...
without adding management subnet i was able to ping gateway
but now(after Changes) I am not able to ping nac server as well as gateway
please find the attachements
Consultant VLAN- 513 IP - 10.20.20.0
Untrusted- 504 NO IP
L2
interface FastEthernet0/46
switchport access vlan 504 ***** Consultant PC****** ( It Should Consultant VLAN 513 or untrusted VLAN 504)
switchport mode access
snmp trap mac-notification added
spanning-tree portfast
L3
interface GigabitEthernet1/0/15 **** NAC Srv untrusted***
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport trunk allowed vlan 501,504
switchport mode trunk
interface GigabitEthernet1/0/18 ***** NAC Srv Trusted****
switchport trunk encapsulation dot1q
switchport trunk native vlan 998
switchport trunk allowed vlan 507,513,540
switchport mode trunk
interface GigabitEthernet1/0/10 ***** NAC Mgr ****
switchport access vlan 506
spanning-tree portfast
route
10.0.0.0 10.1.8.2 ( 10.1.8.2- Firewall IP )
09-19-2010 05:54 AM
Vikram,
Please turn the checkbox marked "Enable Subnet-Based VLAN retag" off, reboot your CAS and try again.
Thanks,
Faisal
09-19-2010 09:29 PM
Thanks Faisal Bhai
Thank you...............
09-21-2010 04:46 AM
wireless user is not able to authenticate getting following error
Unable to process out-of-band login request from [00:21:5D:80:9C:00 ## 10.20.20.5] vikram. Cause: OOB client 00:21:5D:80:9C:00/10.20.20.5 not found.
09-21-2010 07:05 AM
Vikram,
Have you added a trap-receiver in your WLC? The error means CAM didn't get the trap.
Faisal
09-21-2010 08:28 AM
Hi faisal there was the mismatch the community name
thankssss.....
09-29-2010 07:53 AM
03-24-2011 09:48 AM
Another issue I have found that results in this error is two MAC addresses showing up in the cam table of the switch. If the first one to show up is not the one used when the user tried to authenticate it will result in this error.
You can verify the cam entries either from the switch or from OOB Management --> Devices. Look at the Client MAC entry for the port.
Haven't quite figured out how/why the device has two MAC addresses but that is the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide