CAS managed subnet and vlan mapping

Hi to All,
I would like to ask some help for my nac appliance. Currently im setting up the nac appliance. I just having trouble what ip address should I use for the managed subnet. I have setup trusted vlan as it is existing in our network but what about the untrusted vlan? Should i make new ip addresses for it and put it in the untrusted? I dont know if made it correct but I cannot get an ip address everytime i change the switchport to port profile I made. Please can you guys help me i just need to know it for my project. thanks.

Hi Faisal,
Good day.
I dont have any interface vlan for the authentication in the untrusted. But I have the authentication vlan in the vlan database of the switch and allowed it to the switchport trunk. What I notice also I opened all the ports in the traffic policies thats why in the unauthenticated role the workstation could access the internet. When I limit the traffic it redirects to the domain but it is still cannot pass to the web login agent although I created an account to the local of the cam. Can you please tell what port should I put in the traffic policies for unauthenticated role? Is there something wrong with the ip address that im using or the certificate(Full domain name or ip:  MOD.local  ---> should it be ip address?). Thanks again your a great help.

Similar Messages

  • Logical network to physical network mapping (subnets and VLANS) in SCVMM 2012 R2

    In much of the blogs, documentation and literature on VMM, there are examples of deploying multiple logical networks onto one physical network i.e. Cluster (logical) + Storage (logical) + Backup (logical) + Live Migration (logical) + Management
    (logical) on top of Datacenter (physical).
    Does this mean it would be possible to have one (physical) flat VLAN-less network with one subnet and then have all those logical networks (with subnets and VLANs) on top of it? Even with a simple unmanaged L2 switch that doesn't support VLANs itself?
    If not, just how do you map multiple logical networks to just one physical network? How does that work in practice? Is a L3 switch needed to route traffic between logical networks for example?

    Hi. VMM Networking may be overwhelmed for the most, at first. But you really need to understand the modeling here and how things are related to each other. Especially if using NIC teaming in WS 2012 (and R2) together with this mix.
    I suggest that you read the following whitepaper where we explain how to setup networking in VMM (also to support network virtualization, but that is absolutely not mandatory): http://gallery.technet.microsoft.com/Hybrid-Cloud-with-NVGRE-aa6e1e9a
    -kn
    Kristian (Virtualization and some coffee: http://kristiannese.blogspot.com )

  • Case Management use and configuration

    Hi,
    In my understanding, this tool provides the capability to review those matching results who needs to be validated and then, I think, it permits to the end user, take an action. My question is: ¿what are the actions that the user could take?, specifically, ¿The user can manage the fields of the matching candidates to generate a gold record?
    In addition, I have been looking for resources/documentation to configure and use case management interface in EDQ. I wish to know how to configure a process of EDQ to raise alerts on the case management interface, and assigning it to a user.
    Thanks in advance for any help,
    regards,
    Daniel

    Hi Nick, Thanks for your answer. I've read the "Case Management Essentials" document located on the EDQ product page at OTN. In fact, this is the document in which was based my understanding of the tool. After search a lot for documentation, tutorials or any guidance to configure this feature, I was reading the online help as you say, but I found it some hard to understand. But I will continue using that resource, if I dont find any other material.
    Can you tell me what kind of actions can perform an end user over alerts and cases in this tool?, I need to know if it is posible to do manual merge or any kind of manipulation of the data who raise the alert. Because in the available examples I only see users change the status of the alert/case, but only that.
    Thanks for your atention,
    regards,
    Daniel

  • Managed subnet and dynamic vlans

    Hi all,
    I have confusion with managed subnet, we have 3 untrusted vlans, 9 trusted vlans and 3 separate vlans for vlan mapping. all vlans have different ip subnets, but untrusted vlans don’t have ip subnet, it will another vlan’s ip subnet so which vlan and which subnet ip should  I use for managed subnet?
    Here is the detail of vlan and ip
    Untrusted vlan               
    101      for floor 1         
    102     for floor 2              
    103 for floor    3               
    We have separate vlan for vlan mapping
    101 <-> 901            (172.30.1.0/24)
    102 <-> 902         (172.30.2.0/24)
    103 <-> 903         (172.30.3.0/24)
    In the initial phase untrusted client should get 172. 30.X.X range ip address from dhcp and for trusted clients they should get the ip address as per the trusted vlans as follows
    Trusted Vlan                              (ip subnet)
    501     for floor 1 sales dept     (192.168.1.0/24)     
    502     for floor 2 sale dept           (192.168.2.0/24)
    503    for floor 3 sales dept        (192.168.3.0/24)
    601 for floor 1 mkt dept          (192.168.4.0/24)
    602  for floor 2 mkt dept        (192.168.5.0/24)
    603 for floor 3 mkt dept        (192.168.6.0/24)
    701 for floor 1  admin dept      (192.168.7.0/24)
    702 for floor 2 admin dept      (192.168.8.0/24)
    703 for floor 3 admin dept     (192.168.9.0/24)
    And I need to configure dynamic vlan for all users. E.g. if user is from sales department and login from floor 1 trusted vlan should be 501 and if this user login from floor 2 then trusted vlan should be 502. Can anyone give me the configuration sample or ideas for this scenario?
    Thank you

    Laxman,
    Your managed subnets should be the IP range of 172.30.x.y (where y is a valid number and NOT the network number, i.e.0 or 255) with a VLAN tag of 101, 102 or 103.
    For ensuring that the VLANs translate properly according to where your users are, you can assing named VLANs in the role-based VLAN config screens. Make sure the case matches as you define them on the switch and CAM. So this way if a user is on first floor and his role-based assigned VLAN is Sales, it will translate to 501, etc
    HTH,
    Faisal

  • How do I add a Subnet and vlan with a catalyst 3550 and RV120

    Hello Friends.
    I have a scenario that i'm hoping i can get some help with. I'll be as detailed and descriptive as i can.
    This is for a business with 100 employees nodes and 100 camera nodes all needing IP internet through private addressing and public gateway.
    I have a business class gateway with a private range of 12 public addresses. Ther modem does nothing but act as a gateway since i have disabled the firewall and DHCP.
    In place of the firewall and DCHP from the modem i have installed a RV120 Firewall with VPN. When installing i replicated the IP scheme of the modem as to not disturb and distrup the devices assigned addresses from that scheme from the modem. I did this because the owner could not have any down time or any disruption to the business operations.
    The RV120 now acts as firewall , DHCP , and VPN. I'll address the subnet first. I's using 10.0.0.0/24 subnet range.
    DHCP is assigning 10.1.10.50 - 10.1.10.100 the rest are static and i plan to use static DHCP with the IP and MAC assigned to each static DHCP address.
    There are 100 cameras with static IP addresses in the range of 10.1.10.11 - 10.1.10.40, and 10.1.0.1.101 - 10.1.10.170.
    VPN uses PPTP assigned address 10.1.10.6 - 10.1.10.10.
    There are no layer 3 switches that i know of. Just a layer two that is the primary swith and ports have run out, and various out of the box switches and wireless access points connected to the primary switch.
    I want to implement subnets into the network and VLANS as well on a new Layer 3 switche from cisco. Thinking 3550 from Cisco or one of the older layer 2 switches with layer three capabilities.
    I also want to introduce a 192.168.0.0/24 IP range for the existing wireless network and segment the traffic from the rest of the traffic on other ranges.
    I want to replace the 10.0.0.0/24 DHCP alltogether and the static addresses for end user nodes on the same network, but keep that range just for camera nodes segmented.
    I want to implement a NEW end user IP range and VLAN for employee/guest networks using the 172.16.0.0/24 range.
    Iv'e thought of replacing all the wireless nodes with RV120's and use VLAN. Dont know if that strategy works. Need to think it through.
    I want the 192.168.0.0/24 IP range comunicate to with the 172.16.0.0/24 and possibly the 10.0.0.0/24 range.
    Any advice on how to do this?
    As a side note the next step after this is to install a server domain controller as all the computers are all stand alones in their own workgroups. It's a simultaneous project that will introdue a DCHP, WINS, DNS server.

    Hi Omid, it sounds like you're proposing the 3550 switch but you're not decided yet. The 3550 switch is a pretty old device and needs enhanced multilayer image. It may be more prudent to use a more current switch such as small business SG300 or SG500 as the feature set is more rich and it supports around 480 LAN connections.
    To answer the inquiry, the RV120W, when you create a VLAN it will automatically create an IP interface. From this you may assign subnet as you like along with 'enable or disable' for inter vlan routing. Since the RV120W has this feature, a layer 3 switch is not required unless you are looking to keep the routing load smaller by routing locally with the switch.
    With Catalyst or a small business switch you would need to create a VLAN. After creating the VLAN, on a Catalyst you can simply issue "switchport trunk encapsulation dot1q" on the desired interface and all VLAN will passage without issue. For a port connecting a user "switchport mode access" "native vlan xx" This will assign the port as untag member of the desired VLAN.
    If using a small business switch, it is slightly different, you still create the VLAN but the command issue is a bit different  "switchport trunk allowed vlan add xx" for the link to the router, where xx = the VLAN ID to tag to the router. For access client it remains the same as Catalyst.

  • Subnet vs VLAN, L2 broadcast and L3 broadcast

    Hi all,
    I understand what are subnets and VLANs in which subnet breakup a network into different smaller segment, whereas VLAN is the logical breaking of a physical switch into several logical ones.
    By right, each subnet and VLAN belongs to its own broadcast domain.
    However, there are still some grey areas which i am not able to fully grasp and hope gurus here can advice further
    q1) is VLAN and subnet a 1:1 relationship ? can multiple subnets belong to a single VLAN, or multiple VLANs share a same subnet ?
    The reason being I have come across a design specs which lay down "Production environment" , inside it has multiple subnets which is okay, but I am not sure are the subnets belonging to the same VLAN ? or rather can they ?
    q2) if devices are from a same subnet/connected to the same switch does not need to be routable to another other subnet/network. there is no need to set a gateway ip in the devices already am i right ? But do they still need IP addresss to communicate with one another ?
    q3) Technically, can a frame be send from a device to another device connected to the same switch without "IP addresses" assuming both the source and destination MACs are made known ?  (meaning that the src and dest ip in the frame is empty)
    q4) If multiple devices from different subnets  (e.g. device a,b are from subnet ab, device c,d are from subnet cd) are connected to the same switch, are they still technically consider to be in the same broadcast domain ? 
    q4.1)  I would assume that an arp request is a L2 broadcast am i right ? and it will affect all the devices above (a,b,c,d) despite them being in different subnet . e.g. [src mac a.b.c.d] [dst mac f.f.f.f]  [src ip 192.168.1.1] [dst ip 192.68.1.10], am i right ?
    q4.2) Above arp request is a L2 broadcast with specific L3 destination address but L2 broadcast address,
    Is there any example on L3 broadcast (255.255.255.255) which have specific L2 destination mac address ?
    q5) if mutiple devices from different subnets are connected to the same switch, is there any possibilities that frames from one subnet will inter-cross to devices on other subnet beside L2 broadcast ?  Is there any other impact ?
    Hope my questions make sense.
    Regards,
    Noob

    Duplicate post, please add any answers into the other thread -
    https://supportforums.cisco.com/discussion/12471861/subnet-vs-vlan-l2-broadcast-and-l3-broadcast
    Jon

  • What is the Best way to connect CRM Case Management with EP-KM?

    Hi Gurus,
    We will implement a Case Management in CRM 7.0 EHP2  and  EP 7.31 with  KM.
    The Client needs Clasifications and Search of the documents in Case Management, the number of documents could be 1,000, 000 aprox...
    I thing are 2 options :
    1) The documents are stored in CRM Repositories, and KM access him, (I know this is posible using WebDAV repositories), but I do not know if this could affects in some way the process in Case Management. And if CRM repositories can store the huge volume of documents.
    2) The documents are stored in KM Repositories, and CRM access him. 
         -¿Is this posible?.
         -¿CRM can access the documents without problem?
         -How can store the documents to KM on line from CRM Case Management?
    What is the best solution?.
    Please Help.
    Best regards.

    Hello quinstar,
    It sounds like you would like to use either your Personal HotSpot to AirPrint from your MacBook Pro or use an Airport to do so without internet access to the home. According to the following Featured Discussion you very well may be able to use AirPrint with Personal HotSpot:
    HT4356 Can I use personal hotspot as wifi to connect printer?
    https://discussions.apple.com/thread/4007254
    Also, the Airport products to not need an active internet connection to set up a home Wi-Fi connection so that is another option as well.
    Thank you for using Apple Support Communities.
    Take care,
    Sterling

  • Configuring workflow for case management

    Hi
    My requirement is to copy the standard workflow for case management WS01700044 and add few things once the case is processed.
    Now my problem is, how do I configure this new Z workflow in the SCASE. So that once I save the case, I should be able to start the workflow I have created.
    Currently only 2 workflows are listed for case management.
    1. WS01700051
    2. WS01700044
    I want three workflows to be listed.
    Do we need to configure the newly created workflow in SPRO under case management? Please guide me.
    Thanks in advance.

    Hi There,
    The workflow in case management is triggered by the event BUS2022.NONPROFESSIONALUSERSET which is the same trigger that invokes WS01700044. You will first need to disable that trigger (open that workflow and remove the trigger (the first node in the workflow)). I would then add that trigger to your new Z workflow and that should do the trick.
    This is the best way to do it rather than looking in the IMG.
    Hope that helps,
    Brenton.

  • EURent Case Management demo - start case

    I have deployed the case management composite and UI and I can log perfectly into the UI and I can see in Enterprise Manager that EURent has been deployed.
    Now I want to test it by creating a case, and use the sample XML payload for the EURent.startCase service, and when I send the request (http://localhost:port/soa-infra/services/default/EURent/EURent.service), I get an "Accepted" response and by looking in enterprise manager it seems that a case has been started. My problem is, that I cannot see this case when I log into the UI as the mmitch user as specified in the guide.
    Is anybody else experiencing problems with actually viewing the cases in the demo UI?

    Can you tell me what environment you are using when succesfully trying the UIRent demo?
    I am having A LOT of trouble with even the most simple case management projects and I am out of ideas.
    I have installed JDeveloper 11g which includes a WebLogic 10.3.5 server and I have installed the SOA/BPM Suite too. I have added patches p15995111 and p14526899 which according to Oracle are the required patches for Case management.
    Even when I create the simplest case manegement demo with a single automatic BPM process which doesn't do anythign and a rule which sets a milestone after the activity is completed doesnt work. I can see in Enterprise Manager that the BPM process is completed but the rule is never fired.  Is there something special which have to be configured on the WL server to be able to run case management projects?

  • Case Management - Arrays as case data

    I have a Case Management project where I would like to have an array of people on the case as case data. My thought is, that the way to do it is to model a Business Object "People" which has a list of "Person" Business Objects. Then I can add the "People" object as case data.
    But what happens if I have two different case activities (or two instances of the same activity) which adds a person to the "People" object and saves as case data? I'm not sure what best practice is in this scenario. Should I make a sevice call in the BPM process where a service executes some custom java code to interact with the Case Management API and manipulate the data?

    Hi,
    please try the following - I just checked it:
    1) Create your composite with case and caserule
    2) Create a HumanTask (e.g. HumanTask1) with input / output => e.g. parameter1 & parameter2
    3) Promote the task as CaseActivity.
    4) Open the Business Rule associated with the case. Go to Facts and create a new XML Fact based on the generated HumanTask1Payload.xsd (it contains the booleans that you defined for the HumanTask). Press OK.
    5) From now on you can use the fact in your rule. For example in the condition type HumanTask1PayloadType and select the appropriate parameter.
    Please let me know if it works for you.
    Danilo

  • QinQ vs. Vlan mapping

    Hi guys, for me it is new, so i would like to ask that what is different between QinQ and vlan mapping. I hope all guy let could explain me. Thank

    To my knowledge vlan-mapping is another word for vlan translation, meaning you translate (modify) the vlan ID in the frame when entering / exiting a specific interface.
    QinQ is sometimes also called vlan stacking, meaning a frame is altered with a outer vlan tag (ID) and keeping the inner tag of the original frame. This technique is mostly used by service providers to designate a vlan ID per customer in a VPLS network.

  • FlexConnect VLAN mapping management

    How to manage larger amout of FlexConnect APs? Especialy VLAN mapping, which is saved separately in each AP. I would like to have a list of AP-WLAN-VLAN settings. Is there any CLI command (except show run-config) for it? And what about backup of this setting? How to restore it in case of an AP crash?
    Many thanks.

    Yes... If your ap and users are going to be put in the data Vlan, you can just leave the port to an access port and you don't have to setup any native val. Or Vlan mapping in the FlexConnect AP. If you decide you want to map users to the voice Vlan, then you need to trunk it.
    If you want to trunk it anyways, then you can map a WLAN to the data Vlan too.
    Sent from Cisco Technical Support iPhone App

  • CDP nei results and Flex Connect AP vlan mapping behavior

    Hi all,
        We're running controller code 7.4.100.108 and PRIME version 1.3.
        Occassionally, usually as the result of some networking event that causes flex connect AP's to lose connectivity to their controller, the flex connect AP's lose their vlan mapping configuration when they reconnect to their home controller.
        We "think" we have noticed that the cdp nei results are different for AP's that have proper vlan mappings from those that have lost their mappings.  For example, in the below example, only AP's 8213 and 8219 have lost their vlan mapping configs (all the AP's below are flex connect):
    8107   Gig 1/0/45        177           R T      AIR-LAP11 Gig 0
    8106   Gig 1/0/44        163           R T      AIR-LAP11 Gig 0
    8216   Gig 1/0/47        136           R T      AIR-LAP11 Gig 0
    8213   Gig 1/0/48        135           R T      AIR-LAP11 Gig 0.2
    8219   Gig 1/0/46        159           R T      AIR-LAP11 Gig 0.2
    8109   Gig 2/0/48        153           R T      AIR-LAP11 Gig 0
    ...and when the vlan mapping is fixed:
    8107   Gig 1/0/45        177           R T      AIR-LAP11 Gig 0
    8106   Gig 1/0/44        163           R T      AIR-LAP11 Gig 0
    8216   Gig 1/0/47        149           R T      AIR-LAP11 Gig 0
    8213   Gig 1/0/48        149           R T      AIR-LAP11 Gig 0
    8219   Gig 1/0/46        152           R T      AIR-LAP11 Gig 0
    8109   Gig 2/0/48        153           R T      AIR-LAP11 Gig 0
         I've done some reading to try to understand the details of the "Port ID" field of cdp neighbor with AP's but haven't found my answer.  I want to know what the significance of the difference between "Gig 0" and "Gig 0.2" is.
         I'm going to lab up an AP and see if I can replicate the behavior and confirm that it is related to the vlan mapping, but haven't gotten to it yet.   If anyone can point me to the nuts/bolts behind that sublte change in "Port ID" it'll help.
         By the way, I'm interested in this problem so that I can quickly identify which of my hundreds of flex connect AP's have lost their vlan mappings after a network disruptive event.  I can't find an interesting report in PRIME that will let me see it quickly.  So if a scriptable cdp nei command could identify the problem as well, that would be interesting.
         Thanks in advance for the help.

    I also have created WCS/NCS/PI templates to push the WLAN to vlan changes in the early morning just I'm case. When users start complaining, it's faster to just push out the commands to all than trying to find what AP lost its vlan setting.
    Sent from Cisco Technical Support iPhone App

  • Case management: Partner confirmation and subsequent case creation

    Hi,
    When i confirm a partner and then click case, the partner number does NOT reflect when the case details open. Is this the standard functionality or am I missing to activate or configure something here. For instance when i create a lead, the partner confirmed before gets automatically reflected in the lead details. In this issue of case, I am right now manually adding the partner. Please clarify on this.
    My second query is about triggering an action (mail) to the related partner when i 'save' the case. Any input here would be appreciated.
    Thank You,
    Amar.

    Hello Amar,
    I'm afraid that I can't add much additional value here. For your second point about emails I would normally suggest OneOrder PPF (Post Processing Framework) actions. But I assume that these only work in One Order documents and not for the case. Perhaps someone else can confirm?
    And I am not aware of any additional enhancements to Case Management, except for some Investigate Case Management functionality rolled out in CRM 7.0 targeted at the public sector (e.g., government and law enformance agencies). My recommendation would be to look at the new IT-IL based Incident/Service Request  IT Service Management functionality available in CRM 7.0 which provides a lot more power and flexibility than the old Case Management (or Service Ticket) functionality.
    Best regards,
    John

  • Getting TF42008: The test case management package could not be loaded. Verify that Visual Studio Test Tool is installed and try again.

    We are trying to run unit tests in TFS server.
    Below is the System Configuration:
    Visual studio version: VS 2013 Ultimate
    TFS: TFS 2013
    For this we have created a build and able to run the build successfully. And build page showing one link for Test result. When we click on this link, we got below error message.
    "Getting TF42008: The test case management package could not be loaded. Verify that Visual Studio Test Tool is installed and try again."
    And below is the screenshot of the error message. So please let us know is there and thing else we need to do to solve this issue?

    Hi RS, 
    Thanks for your reply.
    Yes, if you want to open and view test result on your laptop, you need install the VS 2013 on your laptop as well.
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

Maybe you are looking for