NAC CAS & CAM version ?

Ask a question
If we use different version from CAS and CAM , is it work OK ?
thanks

No.
Upgrade the CAS first.
Please read the release notes for version 4.6 to see the latest information:
"Starting from Cisco NAC Appliance release 4.1(6), the Clean Access Manager and Clean Access Server require encrypted communication. Therefore, you must upgrade CASs before the CAM that
manages them to ensure the CASs have the same (upgraded) release when the CAM comes back online and attempts to reconnect to the managed CASs. If you upgrade the Clean Access Manager
by itself, the Clean Access Server(which loses connectivity to the CAM during Clean Access Manager restart or reboot) continues to pass authenticated user traffic only if the CAS Fallback Policy specifies that Cisco NAC Appliance should “ignore” traffic from client machines."
Hope this helps.

Similar Messages

  • How to schedule script to automate backup of CAS/CAM

    Hi Team,
    I want to configure automate backup of CAS/CAM Device on any free server available in network.
    Is there any script or setting we can configure on these devices

    Hi Amir,
       You can take the Create SSAS database XMLA script and run the job to create the cube. The script contains the Metadata definition of the Database and it does not contain the actual data. 
    Pros: Since you are only creating an empty cube the script will run faster 
    Cons: You still need to process the created cube to use it for reports.
    Fastest option is to take the backup of the cube and restore wherever necessary.
    And you can also use TFS source control to deploy the cube and process it later.
    Regards,
    Venkata
    Venkata Koppula

  • CAM Version 6.2.0.13 and OOB

    Hi,
    I'm having issues with our Storagetek 6140 and an error "Lost OOB communication with 6140".
    I was reading previous threads about this subject and only 1 issue had come up before, and the fix was to upgrade to CAM Version 6.1. Since we are well above 6.1, is this still a bug or something new?
    Thanks
    -Guycamero

    This event "Lost OOB communication" isn't specific to one bug. This is a general event indicating that CAM lost the communication with the array, however the root causes might be different for every issue. Yes there was a bug in a previous release, but now if you still encounter this issue with the latest version of CAM, this means that you are suffering another issue which isn't necessarily a bug, this may be an issue with your array and your network topology.
    Such event requires an investigation by collecting the logs from the array, from CAM and also to analyze the ethernet network topology.
    Regards
    Nicolas

  • How much is the ipod nano camera version worth? its 'as new'

    how much is the ipod nano camera version worth? its 'as new'

           8gb or 16gb. If its in great condition, and nevrer opened i would say about $130 for the 16gb and $100 for the 8gb. Look on craigslist for the best deals!

  • NAC 4.7.1 CAS CAM Login issues

    Hello,
    I upgraded from 4.5.1 to 4.7.1. I am having trouble with the communication between the CAS and the CAM
    Here is an outline of the issue
    1.       After Authentication, DHCP, ACS ok, WALL !!!
    2.       Nac Online Users = 0
    3.       Ping the CAM HA service ip
              Client = NO
              CAS = Yes
    4.       Things are broken at the moment where the Agent/Web Broswer has to communicate with the Nac Manager… it just times out.
    5.       Attached are pics of where it hits the 1. wall and the 2. error that pops up.
    Notes
    Cam Service IP Web UI > Cas Service IP is connected
    Certs from the Cam imported into TCA on Cas and vice versa @ ver 4.5.1 then upgraded
    DNS working
    Login & remediation was working with ver 4.5.1
    Any help would be greatly appreciated
    Thank you Kindly

    Desperately I decided to check everything et voila FIREWALL. With 4.7.1 the CAS needs access to the DNS server. I’m not sure exactly why. It was a fast one liner in the firewall among all the logging but it was the CAS being denied access to the DNS? Added the rule BANG all is good.
    The problem was the login works (inconsistently) for a few moments right after I upgraded or changing the cert… this really was misleading. Just got hung up on the cert being the problem.
    If anyone can tell me why the CAS need to talk to the DNS server i'd appreciate it
    Cheers

  • CAS/CAM logs

    Hello,
    Just wanted to know is there any way to turn on additional logging on CAS let's say? I have enabled logging on CAM, it sends to local syslog daemon which is really useful. In this log I can see what is going on after agent is downloaded.
    I'd like to see: connection attempts from different IPs, CAS triggers for Radius accounting packets (something like: packet is accepted, users is valod now), assigning to User Role process would be really helpful on deployment stage, etc. In fact we have only tomcat logs, which is not so bad as staring point but definately not enough.
    Am I such a dreamer?
    Misha

    Misha,
    Most of the information is recorded in the log files under tomcat. You can tune up the level of logging by going to the CAS admin page directly (https://IP_ADDRESS_OF_CAS/admin) and changing the values to either TRACE or ALL under the support logs page.
    As for syslogging, unfortunately that isn't available on the CAS yet. If it's something you really value, talk to your account team and they can file a feature request for you, to be added in the later versions.
    HTH,
    Faisal

  • NAC- CAS Requirements

    we have a main site that contains (1)CAM and (1) CAS and 250 users. we have 5 remote sites that connect to an ASA 5520 via DSL point to point VPN connections. There is no internet at these sites locally, they all access the internet through the main site. The remote sites have the same vlan setup as the main site. my core switch is a 3750 stack and all switches at remote sites are 3750's.
    my question is do I need to place a CAS at each one of these locations or is there a possiblity to use the CAS at the main site. also if you could give recommedation on IB or OOB for this deployment. thanks

    we have the main site. the main site has an asa for internet access. a cisco stack that contains our distrubution and access client. this is where our cam and cas connect. we have another ASA 5520 that is doing point to point connections to the 5 sites. those remote sites all have asa 5520's and are configured to use the vpn asa at the main site as thier default gateway.
    we swithed the nac to real IP mode from oob today to start attempting the remote sites tomorrow.
    That is exactly what we are planning, routing all traffic from the untrusted vlan to the main site CAS interface using PBR.
    is this going to work with the ASA's?
    what is the downside of doing it this way? do you see any issues or can you give any examples. some of these links are low bandwidth links.
    thanks for all your help

  • I use a Nikon d610 and my Photoshop Elements 10 won't open in camera raw. How can I fix it? The camera version is 6.7.0339

    i'm using a Nikon D610 now and Photoshop Elements 10 won't open files in camera raw. How can I fix the issue? The version of camera raw is 6.7.0339

    Hi,
    The D610 requires camera raw 8.3 which is not compatible with your PSE 10.
    You need to upgrade to PSE 12 (or later) or use the free Adobe DNG converter. The converter will take a flder containg your NEF files and converte them to DNG files. The DNG files can then be used by PSE 10.
    DNG  Converter 8.7
    Mac – http://www.adobe.com/support/downloads/detail.jsp?ftpID=5858
    Win – http://www.adobe.com/support/downloads/detail.jsp?ftpID=5864
    Useful Tutorial
    http://www.youtube.com/watch?v=0bqGovpuihw
    Brian

  • NAC Appliance: CAM Failover

    Hello -
    If I only purchase one CAM, is there a way to backup/restore in case of a failure?
    Thanks!

    You can create a snapshot then export the database.
    In the CAM main menu its under:
    Administration -> Backup
    You can then export and import if you have any issues

  • NAC-CAS vs. NAC-NM

    Hi,
    I have central site with 50 users, without branches. Can I deploy just NAC-NM instead of CAS and if I use NAC-NM in 2811 ISR is there any bandwidth limitation when it is compared to CAS solution? In general, what is throughput for CAS (3310) and what for NAC-NM ???

    I don't think I can answer that because I don't see anything out there that says "throughput is this".. It's all about simultaneous users. I did find something that referencecs the fact that the module does connect over HIMI feature which is a gig connection to the router from the service module.
    http://www.cisco.com/en/US/prod/collateral/modules/ps2797/ps8788/prod_qas0900aecd806bfe39_ps6128_Products_Q_and_A_Item.html
    You can check this article on 2811 performance..
    http://www.smbdesignweb.co.uk/bbt/download/CiscoISR_2811_v1.pdf
    HTH
    -C

  • NAC CAS HA Pair issue

    I had to rebuild the primary CAS. I have both up and running and was configuring the HA on the rebuilt CAS.
    Scenario is CAS17 (primary that was rebuilt) shows OK [ACTIVE]   Peer Server (CAS18) OK
    CAS18 shows OK ACTIVE         Peer Server (CAS17) DEAD
    *note- I have not plugged in my untrusted interfaces yet.

    I just fixed the issue. There was an issue with the rebuilt's hostname. It looked right, but obviously
    wasn't. When I copy pasted it from the standby to it and rebooted both. They came online like they should.
    Thanks for your suggestion.

  • NAC CAS HA question

    Hello,
    I currently have an IB and OoB VG environment. Both CAS are working fine, but now I want to add HA to both. Looking at te documentation (CAS user guide 4.1.3) I see I need two Service IP Addresses, one for the trusted interface and one for the untrusted. In my case since they ar running in VG mode, iwould normally have the same ip address in the trusted and untrusted sides. Does the same apply for the Service IP Addresses? should I use the same service ip on both sides??
    Do I need in total three IP's 1 for both int's of the IB CAS, 1 for both int's of the OoB CAS, and 1 for both Service IP Addresses??
    Thanks in advance for any info...

    For a VGW solution, you would use the same IP address for trusted and untrusted.
    You will need three IP addresses: Real Primary, Real Secondary, Service IP. This is per system not per interface.

  • Where does the agent live on the CAS/CAM?

    My host is prompting me that agent update 4.8.2.3 is available. I do not see this as an option for download via CCO. what is the dir on the server where the MSI lives ?

    Great news! The location is /perfigo/control/data/upload on the Mgmt server.

  • NAC encoding problem

    I'm configuring NAC requirements at the NAC Manager and want to use Russian language in the Description field, to display user PC check problems at Russian language.
    By default, Clean Access Agent display text using Win1251 encoding (as I understand). In NAC Manager I enter description of the requirement via Internet Explorer, using same Win1251 encoding.
    But, all Russian text, entered in NAC Manager are not correctly displayed at Clean Access Agent. I suppose, that this is encoding problem.
    How can I reconfigure Apache HTTP server to display Russian text correctly?? Or, if problem not in Apache, how can I solve this problem?
    CAS/CAM version: 4.1.2.1
    Clean Access Agent version: 4.1.3.2

    You may be running into bug CSCso73630
    http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCso73630
    This looks to be corrected in 4.1.6.

  • Installing and configuring NAC/CAM/CAS/COLLECTOR

    Hi everybody,
    I have been new to this community and I just joined this.
    I need some help regarding CISCO Nac profiler.
    I have 3 cisco nac appliances as below.
    1. 3355
    2. 3315
    3. 3315.
    My question is that when I power on these devices CAS is pre-configured in it but I have to install profiler, CAS, CAM.
    Got 5 hardware total of cisco which are as follows.
    1. CISCO NAC 3355.
    2. CISCO NAC 3315
    3. CISCO NAC 3315.
    4. CISCO Router.
    5. CISCO Switch.
    I have to installed these devices into a network.
    But the confusion is that whom to make profiler server, CAM, CAS and Collector.
    Please help me on this if you have a simple document describing about NAC profiler server, NAC profiler collector, CAS, CAM and how to configure these devices.
    Please help me on this its urgent

    Abuzar,
    Welcome.
    As for your questions, you can install the Profiler, CAM and CAS on any of these devices. Which ever device you make the CAS can act as a collector also. I would suggest making the biggest box you have (3355) the Profiler, and putting CAM/CAS on the 3315s.
    As for a simple document, I'm afraid no such thing exists. NAC installations are complex by nature and you really have to have a very good idea of what you're looking to accomplish before you even touch the first piece of hardware.
    HTH,
    Faisal

Maybe you are looking for