Cisco NAC Server eth0 fails communication when connected to trunking switchport

NAC deployment is L2 OOB Virtual-Gateway-Mode
When our CAS eth0 is connected to a trunk port, the port will chage to a connected state but we are unable to ping the CAS from the CAM or from switch connected to the CAS. Our CAM is on vlan 32 and the cas is on VLAN 60. Below is the config for the port connecting the CAS. The CAS managment ip is assigned to vlan 60.The switch is a 6509. Blade 2 only supports dot1q so we do not need to set encapsolation type for this switchport.
interface GigabitEthernet2/39
description Trust eth0
no ip address
switchport
switchport trunk native vlan 998
switchport trunk allowed vlan 33,34,40,60
switchport mode trunk
end
If we disable trunking and switch the port to access vlan 60 we are able to communicate with the CAS. Has anyone ran in to this when deploying NAC?
If so, how was the issue resolved?

I have the same issue. But it gets even stranger; I had the CAM/CAS working in a test LAN enviroment, got the AD SSO to work by appllying VLANs based on AD group membership of the user logging on. Client was pleased.
Move the two NAC devices to their location and reloaded clean both CAM & CAS from CD, did the same configuration and now eth0 (Trusted) can't see the AD domain controller but can see the CAM. I ran nslookup on the CAS to test the network settings and the result is no server found - the DNS server is the AD domain controller.

Similar Messages

  • Cisco NAC Server

    Hello! Help me please!
    Im perform installation Cisco NAC Server 3315 ver. 4.8(2) but after that I cann't connect to Server by https - HTTP 403 Forbidden. And I can connect to NAC Server by ssh.
    What could be the reason?

    While rebooting , i am getting this:
    Starting nc_drivers:  /dev/nfastpci0
    [  OK  ]
    Starting nc_hardserver:  waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    nCipher server did not start; see /opt/nfast/log/hardserver.log
    [FAILED]
    Starting sshd:WARNING: initlog is deprecated and will be removed in a future release
    key_load_private_pem: RSA_blinding_on failed
    Could not load host key: /root/.perfigo/sec/tomcat.key
    Disabling protocol version 2. Could not load host key
    sshd: no hostkeys available -- exiting.
    [FAILED]
    Starting xinetd: [  OK  ]
    Starting console mouse services: [  OK  ]
    Starting nessusd: Loading the Nessus plugins...
    All plugins loaded                                  
    [  OK  ]
    Starting crond: [  OK  ]
    Starting anacron: [  OK  ]
    Starting atd: [  OK  ]
    Starting jexec:  Starting jexec services[  OK  ]
    Starting Ncipher services
    -- Running startup script 45drivers
    -- Running startup script 46exard
    -- Running startup script 50hardserver
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    waiting for nCipher server to become operational ...
    nCipher server did not start; see /opt/nfast/log/hardserver.log
    Starting perfigo:  click: starting router thread pid 2092 (f7b7d340)
    Failed execute command : CONNECTFORCE, Error : Connection refused
    BaseAgent process reconnecting...
    Failed execute command : ACTIVE, Error : Connection refused
    BaseAgent executes [ACTIVE] ...
    Link Detect Manager only operates when HA is enabled.
    NFastApp_Connect failed: ServerNotRunning
    And then in the hardserver log I am getting nCipher card not in operational mode. Please change the settings on the card.
    How to resolve the issue.
    Thanks
    Shalvi Yadav

  • Server error in communication when trying to submit a formscentral form?

    What does it mean when one of my form users gets a "server error in communication" when trying to submit a form.  The saving function worked just fine.  Help this is my first form!
    Thanks!

    It is a rather generic error message that can occur for a number of reasons.  Further details are needed to pinpoint an exact cause.  Do you know if your user can submit now?  There was service outage earlier this week that may have caused the problem.  Other issues are browser security settings, company or individual firewall setting, or actual bugs to out product. If you could get more information from your user such as their Operating System and version, browser version, if the error is still occuring, when the error occurred that would be helpful.
    Some things your user can try in the mean time is clearing their browser cache, restarting their browser or trying a different browser.
    Jeff Canepa
    Software Quality Engineer
    Adobe Systems, Inc.
    [email protected]

  • Cisco NAC server hang issue

    Hi All Cisco NAC Experts,  I am currently experiencing a Cisco NAC NAC3315-SVR hang issue.
    The issue was already happened for few time on the same server and the symptom when NAC server hung includes no response to ICMP ping, no response to SSH request, no response for access request to CAS management page via https, HA pair was detected down from its HA neighbor and triggered failover to secondary CAS.
    The CAS server was recovered after manually power cycle the hardware. 
    After went through the attachment CAS logs, I found all the services and logging service were stopped when the issue happening but unfortunately there is no any suspicious activity was logged down before or during the issue happening.
    I have also tried to search on Cisco Bug Toolkit but no similar case was found, I believe it was not caused by software bug due to the software version 4.8.1 is running in my company for years and only one CAS server having the issue.
    That will be great if any one can help me out for the same.
    Thanks,
    Eric

    Hi Bro
    This could be a problem with the certificate in that Cisco NAC appliance itself. My suggestion is to redo the certificate generation between the CAS CAM and CA Server. If this still doesn’t work, it could also be due to overload/broadcast storm on the LAN portion. This can be verified via Wireshark.
    If all else fail, then a hardware swap would seem like the next best thing.

  • "logon failed" error when connecting to XML data source

    I have an HTTP source that generates XML. I have a schema that describes this XML. If I save the XML to a local file it works fine as a data source with the schema. However, when I try to access the same data via HTTP, I get the following error:
    Logon failed.
    Details: Cannot open file
    Server returned HTTP response code: 401 for URL: http://localhost:8004/report.xqy?Validate%20XML=0&Use%20WS-Security%20Config%20File=&WS-Security%20File%20Location
    However, if I enter that URL in a browser it works fine. And even if I disable security on the HTTP source, it produces the same error.
    I have tried a local HTTP source as well as the same source running on Amazon EC2.
    Any ideas?

    Thanks for the help.
    I am new to crystal reports, so I do not understand your suggestion. Both of those points look like they are related to Adobe Flash.
    I am trying to create a report using the standard report creation wizard:
    1) new, standard report
    2) create  new connection
    3) xml and web services
    4) xml data source
    When using the sample from the SAP site, it works fine:
    http://resources.businessobjects.com/support/downloads/samples/cr/customer_db/customer.xml
    When connecting to my source from a browser, it works fine. When using my source as a local document instead of over http it works fine. It is only when connecting to my source over http that I get the failed logon error.
    Kelly

  • LW 16/600 Fails POST when Connected to Network

    I have an Apple LaserWriter 16/600 that I bought in 1992. When I power it up, it goes through the POST OK but if it's connected to the network, the leftmost light flashes instead of turning solid green.
    When I disconnect the network adapter (I'm using a Farallon EtherWave), the leftmost light stays solid green.
    I have powered the printer off and back on, including leaving it off for about a week.
    Anyone have any insight on this.
    Also, anyone know of a company that repairs the 16/600?
    Thanks for any info.

    After the Power-On Self Test, the green light flashing indicates that it is accepting a print job. Most folks would not consider that a malfunction.

  • ASSERT failed error when connect room closed?

    Anyone more that have experienced this error message when closing a meeting room - and have a solution?

    As a copy of this query has been posted to the CR design forum at 11:21, assuming this is indeed a design question.
    Thus setting this thread as answered.
    - Ludek

  • Hyper-V vSwitch external connection not working when connected to 100mb switchport

    I added 2 new servers to my existing Hyper-v 2012 server core failover cluster and there are many physical network connections on these servers.  One of the network connections on the new servers goes to a switch that doesn't have any additional 1gb
    connections and only has 100mb ports available.  The existing servers are connected to 1gb ports and they work fine.  The new servers are connected to the 100mb ports and when the host is setup with an IP on that network, I can ping other devices
    just fine but when I setup a vswitch connected to this external network adapter and share it with the host, I can ping between a Guest VM and the host but I can't ping on the external network.  So it appears that a Hyper-v vswitch doesn't autonegotiate
    with an external network connection that is set for autonegotiate on the switch but limited to 100mb.  I switch the cables between a server that ha 1gb connection put it into the new server and it communicates just fine but the old server won't communicate
    on 100mb port.
    Does anyone know how to setup the vswitch external network connection so that it will communicate on a 100mb external network?

    Hi Sir,
    >>The new servers are connected to the 100mb ports and when the host is setup with an IP on that network, I can ping other devices just fine but when I setup a vswitch connected to this external network adapter and share it with the host, I can ping
    between a Guest VM and the host but I can't ping on the external network. 
    First , please try to test (I assume that there is no vlan settings in your LAN):
    1. create an external virtual switch and click "Allow management operating system to share ... " without Vlan setting
    2. do not connect any VM to this external virtual switch just Host's virtual NIC
    3. try to access other computer in the LAN
    Any further information please feel free to let us know .
    In addition , please check if there is any configuration on that 100Mb switch port .
    Best Regards,
    Elton Ji
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] .

  • Why "A connection to the server has failed."?

    I am facing an issue getting "A connection to the server has failed." when deployed in web logic but not in IDE.
    In my case I am using JDev 11.1.1.3.0, I insert many records (say 50,000 or heigher) at once and also update another table same time before calling "Commit" operation in the bean.
    I have AM locking mode "optimistic".
    The error does not come with small amount (say 1000) of inserts.
    I use AMImpl methods to insert using createRow() and insertRow() methods.
    Can anyone please tell me why this error comes and how to resolve?
    Thanks

    John is talking here also about this problem. I believe there are Oracle PMs in the forum who knows this issue? Can anyone please help?
    http://kr.forums.oracle.com/forums/thread.jspa?threadID=2168715&tstart=0&messageID=9347290
    John Stegeman wrote:
    If you need assistance from Oracle on this - the most reliable and appropriate place to go is https://support.oracle.com The Forums here are good - but if none of the community has seen the error before and the few Oracle PMs don't know the answer, you'll not get much of a response, unfortunately - but that's how community forums work.
    I've never seen the error before personally.
    Best,
    JohnEdited by: PR on Jul 29, 2011 1:32 AM

  • Question about cisco nac agent

    When I deploy Cisco NAC appliance, the main different between using cisco nac appliance with or without agent? I see Cisco NAC agent has two function: scan and remediation. If Cisco NAC appliance without agent, Cisco NAC server will scan device and remediation. That is right?
    Please answer me early. Thank you for your answer.

    Sorry, I believe daldden is correct, without the agent you can still scan using the built-in Nessus scanner.
    We don't use the Nessus scanner, but these are some things to consider if you use the scanner. These are from memory though so anyone who actively uses the scanner may be able to give more up to date or complete info:
    1) You have to decide which vulnerabilities you want to scan for.
    2) The more plug-ins you enable, the longer (obviously) the scan takes.
    3) There are configuration steps for many of the plug-ins
    4) Your users will still need to go to a login page in order to be scanned.
    5) You have to configure the remediation information (URL, steps, etc) for each plug-in you enable.
    From our view point, the only reason we would enable the scanner is if we were looking for a specific vulnerability, perhaps a new threat that didn't yet have a patch. If it had a patch, we would watch for the patch using the agent (installed or web based).
    It was much easier for us to use the agent, to scan their system and make sure that the MS critical hot fixes were installed and/or an AV system was installed and up to date. As mentioned, if there is a patch for a vulnerability, you can use the agent to make sure that specific hot fix is installed.
    Remember that there is also a web agent. The web agent is an ActiveX or Java (you pick which one you want to use) applet that is loaded onto the person's machine, the system scanned, then the applet is unloaded.
    Of course, the agent is only for MSoft (with some MAC options), so if you have Linux systems, the Nessus scanner would be your only option.

  • Excel ActiveX: Server Execution Failed Error

    I'm using my own ActiveX VIs to control Excel. I take a text file and create a chart from some of the columns, then print the chart. I'm getting a "server execution failed" error when I call PrintOut on the chart object. I understand this error stems from the fact that I'm developing on Excel 2007 and testing on 2003, but upgrading all of the computers that will use this software is not going to happen.
    I've fixed all other incompatibilities between versions, and the chart is created correctly, but when the PrintOut method is reached, I get the error. Has anyone ran into this and worked around it? Is my only solution to downgrade my machine to Office 2003?

    Here's a few details on that particular error, both of these articles have some workarounds:
    Error -2146959355 When Using ActiveX or the Report Generation Toolkit
    Error 2146959355 When Running Exe on Machine With Different Version of Office
    Tim W.
    Applications Engineering
    National Instruments
    http://www.ni.com/support 

  • Cisco Persistent Chat error when connecting to DB server

    When we want to configure it and check the connection it says, is in menu Messaging --> external setup --> external databases (in IM Presence Administrator). We use a postgresql server on linux and can connect to the db via other clients as test. What can be wrong? We did not enable ssl for this connection, you cannot even select ssl, is grayed out!
    Verify external database server connectivity (database connection check)
    The following Cisco Unified IM and Presence Service node to external database server connections failed:
    xxxxx.xxxx.xxx >> pchat (Persistent Chat)
    With message:
    One or more parameters are invalid. Please check them once again.
    If the 'Enable SSL' field is unchecked and the External Database chosen in the 'Database Name' field is SSL enabled, please check the 'Enable SSL' field and choose the certificate that corresponds to the chosen External Database and save your changes.
    If the 'Enable SSL' field is checked on the External Database Settings page then the following steps could help resolve the connectivity issue:
    Please try refreshing the page after 60 secs of saving the changes.
    Please verify if the Certificate chosen in the 'Certificate Name' field is valid and corresponds to the chosen External Database in the 'Database Name' field.
    If the problem persists, please restart the Cisco XCP Config Manager Service.

    Hi,
    As mentioned in the following configuration article, for earlier versions of SQL Server where MARS was not an option, the way to configure is to have server-side cursors configured.
    (check out the tabulated column next to MARS_Connection for details)
    http://www.easysoft.com/products/data_access/odbc-sql-server-driver/manual/configuration.html
    To use server-side queries in the connection URL, pls go through this link
    http://www.oracle.com/technology/products/jdev/howtos/bc4j/bc_psqlserverwalkthrough.html
    But please note that server-side cursors does have a performance overhead.
    Let me know if you need more information.
    HTH,
    Lakshmi.

  • Hi there, I am trying to connect to my server at work from home using a vpn connection. It connects fine and the time ticks along, but when i click go - connect to server, it comes up with connection failed. Please help!

    Hi there, I am trying to connect to my server at work from home using a vpn connection. It connects fine and the time ticks along, but when i click go - connect to server, it comes up with connection failed. Please help!

    ... when i click go - connect to server, it comes up with connection failed.
    If you're trying to connect to a Bonjour server on the remote network, that won't work over a layer 3 VPN. Use something like Hamachi or one of the SSH-tunnelling Bonjour proxy apps for that.

  • I have internet connection but my incoming email does not appear.  When I try to access new email it says, " connection to server has failed"  Help

    I have internet connection but myh incoming email does not appear.  When I try to access new emails it says, "connection to server has failed".  Help

    What did your email provider say about it when you contacted them?

  • Connection to the server failed appears when synching email through Microsoft Exchange.

    The message, 'Connection to the server failed', appears when synching Groupwise email through Microsoft Exchange on my IPhone 4S. A long string of numbers and letters appears where INBOX should be. The downloading 'wheel' keeps spinning, and the battery is drained quickly as a result. I also get numerous no sender emails with the date 12/31/69 that cannot be deleted. Calendars also are not synching.The exact same settings work for my IPad2. The server works for other IPhone users. It is very strange and frustrating.

    What device does your husband have?  What email server does he use?
    All I can tell you is what Microsoft is saying right now.
    If any other email systems (like gmail, yahoo) work on your device, odds are that your device is fine.

Maybe you are looking for

  • Safari icon Pops up on the left side of the dock, how to turn it off

    I'm constantly getting this icon popping up on the left side of my Dock on my iMac at work. When clicking the Safari icon, it will open a webpage where one of my colleges is working on. How can I turn it off because it constantly shifts the icons  on

  • How to create a logon process in iWeb

    My version of iWeb does not appear to have the universal password protect of the webpage function [even thought the Apple documentation says you can]. Has anyone created a iWeb page which requires a user to logon with a user name and password [it can

  • How can I output iMovie '11 back thru Sony DVCM-DA2

    I am able to import video into iMovie '11 thru the firewire port using a Sony DVCM-DA2 media converter box, but I need to play it back thru my Sony DVCM-DA2. Is there a setting the I can set to play it back thru the firewire port? Thanks, Robb

  • How to use j_security_check

    Hi, I am using j_security_check servlet to set up Form authentication for my simple web app in WebSphere 5.1. The web app is simple, and only contains login.jsp and error.jsp. I also include a servlet in this web app and it's a protected resource. Cu

  • What package do I need to install quicktime?

    I am able to download quicktime, but I CAN NOT  install it, the message says " the installation package could not be opened". What do I need to do to install quicktime?