cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2402
Views
0
Helpful
12
Replies

NAC Agent takes long time to run

Tabish Mirza
Level 1
Level 1

Cisco NAC agent takes long time to popup or run on Windows 7 machine.

The client machine is windows 7, running nac agent 4.9.0.42, against ISE 1.1.1

Any ideas how to reduce NAC Agent timing?

12 Replies 12

Tarik Admani
VIP Alumni
VIP Alumni

Did you try to disable the l3 swiss delay and reduce some the timers...httpa discovery etc.

Also there is a bug in the current compliance modulr where the current wsc.dat files causes long posture time. You can delete this file from the nac agent directory and see if these suggestions help.

Thanks


Sent from Cisco Technical Support Android App

I have disabled the l3 swiss delay, reduced timers & removed the compliance module from client provisiong policy but no luck still it is taking time. Any other suggestion please.

Usually how much time nac agent takes to come up?

Eduardo,

That is what i initially suggested, doesnt look like that fixed their issue.

Tarik Admani
*Please rate helpful posts*

Any other suggestion please

Sent from Cisco Technical Support iPhone App

Hi Tariq,

Is there any way to run the nac agent in background without displaying to client ?

Please waiting for response.

Thanks

Hi Tariq,

I'm facing the same issue with ISE 1.1.1 (268) with Agent 4.9.0.47 for Windows XP clients. I have already configured "yes" to disabled the l3 swiss delay and reduced the httpa discovery timer from 30 to 05 sec but still clients get aprox 2.30 minutes to popup and finished the posture discovery.

Can you please advise if this is the minimum time or what is the minimum time and what are the parameters to set to a minimum time to complete agent popup and posture discovery..?

Is there any option that we can run this on backgroup..?

thanks in advance..

Saurav Lodh
Level 7
Level 7

Please try giving lower values to Http discovery process timeout. The valid range is 3 and above

Hi,

Can you please provide the acl configuration for the "agent redirect" scenario as well. Also when you use wireshark do you see communication to the ISE PSN during the delay?

I have verified that the nac agent service will not start till the netlogon process completes, you most likely will see this when a machine is locked and unlocked. You many need to consider opening AD ports and that will speed up the communication.

Thanks,

Sent from Cisco Technical Support iPad App

Hi

Please I have the same problem

what are the parameters to set to a minimum time to complete agent popup and posture discovery.

Thanks

Hi,

Use the NAC Agent 4.9.2.8

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: