NAC Inband RealIP-Gateway address

Hi Experts,
I want to configure NAC appliance in INBAND-CENTRAL DEPLOYMENT-REAL IP GATEWAY.
In this scenario, my clients are in different VLANs say 2 & 3. To all my clients the default gateway should be the IP Address of NAC. Correct?
Where I will configure this IP address in the NAC box so that this IP Address will be the default gateway for my clients.
I know that the "managed subnet" option in the NAS is for ARP resolution only and not this IP can be used as default gateway for Clients.
Do i have to create some virtual IP address in the NAC Ethernet card?
Please help me by sharing your thoughts
Sairam

Hi Sairam,
I put some configure samples about L2 IB for you:
interface GigabitEthernet1/33
description To Trusted
switchport
switchport trunk encapsulation dot1q
switchport trunk native vlan 998
switchport trunk allowed vlan 31,40,110
switchport mode trunk
interface GigabitEthernet1/34
description To Untrusted
switchport
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport trunk allowed vlan 41,311,400
switchport mode trunk
There are some notes you should know:
1) NAC server -> core sw: trunking (see details on the above configuration)
2) Authen VLan: 311, 400 (these should NOT have SVI (Layer 3) interface anywhere on the network)
Access Vlan: 31, 40
You should map 311 -> 31, 400 -> 40 on NAC server.
3) CAS is going to be the default gateway for users
Hope this help!
NamNT

Similar Messages

  • NAC Inband Layer 2 VG

    Hello Dear's,
    My company ordered NAC and ACS 1120 My question is Can i configure 802.1X security through ACS server and NAC in layer 2 Inband Virtual Gateway.for campus switches.
    Is it the good design to have double security for switch ports. 1st is 802.1X and 2nd is NAC in layer 2 INBAND VG
    Thanks.
    Message was edited by: estela mathew

    Hello Dears,
    Any suggestion please Experts,

  • When they ask for the gateway address on the Tv what number is that or what number should I be looking for?

    When they ask for the gateway numbers on the TV, what number is that or what should I be looking for? I am trying to connect my wifi network on my Samsung smart TV.

    The "Gateway" address would be the Private (LAN-side) IP address of your Internet router. If you are using an AirPort base station for that router, the default gateway IP address would be: 10.0.1.1

  • How To Get Network Adapters & Gateway Address

    Hi,
    I need to get and alter the local PC's IP address and Gateway address.
    I know how to get the IP address using InetAddress, but I have a few questions.
    1) Is is possible in Java to change the local PC's IP address?
    2) Is it possible and if so how do I obtain the local PC's Gateway IP address
    3) Is there a way of showing all the Network adapters within a PC?
    This will be used on Windows XP operating system if ths makes any difference.
    Many Thanks

    2/ Hello I've submitted a method to retrieve the gateway ip on [http://forum.java.sun.com/thread.jspa?threadID=5289135|http://forum.java.sun.com/thread.jspa?threadID=5289135] , it does work under windows and linux (I haven't tested on other os yet)

  • SMTP Gateway address

    Hi,
    Where we configure the SMTP Gateway address for external mailing?
    Best regards
    Zied

    At transaction SCOT
    Read,
    http://help.sap.com/saphelp_nw04/helpdata/EN/af/73563c1e734f0fe10000000a114084/frameset.htm
    Regards
    Juan

  • Time Capsule, DHCP not providing correct gateway address

    I have gone back and forth between my AP Extreme and Time Capsule and have determined that Time Capsule is not providing the proper gateway address to my wireless clients. Instead of providing the correct gw address it provides the address I assigned the base station. This is contrary to my Airport Extreme which provides the proper gw address to my wireless clients. Sounds like a bug in the DHCP base station software. Any thoughts?

    I have a very similar problem. I originally had cable broadband and a Airport Extreme (AE) upgraded to 7.3.1 all worked fine. The AE was being used as a DHCP server to distribute the dynamic IP address provided by the ISP. I then replaced the AE for a Time Capsule (TC) and installed a new 802.11n Airport Express. I upgraded the TC and AExpress to 7.3.1. The TC was setup identically to the now replaced (disconnected and switched off) AE.
    Unfortunately the TC failed to work as a DHCP server. It did not recognize the ISP provided dynamic IP address and replaced it with an 'Invalid' IP address which of course meant no internet access. I then replaced the TC with the original AE (identically set up) and all worked fine, including the AExpress.
    While I wait for Apple to fix the TC firmware I am running the AE as the DHCP Server and the TC as a wireless bridge to the AExpress. Time Machine is recognizing Time Capsule and backups from two macs are working fine.

  • HH3 Gateway Address Problem

    Hi,
    I have just had Infinity installed and have an issue with the BT homehub3.  
    The hub has an IP 192.168.1.254 however when it assigns an IP address to either my desktop or laptop using DHCP  it assigns the gateway address as 192.168.1.1 and consequently I can’t get an internet connection. If I set the IP and gateway manually it works fine.
    Any ideas as to why it isn’t setting the correct gateway?

    Does it work if you set the IP address manually e.g
    IP Address          192.168.1.50
    Subnet Mask       255.255.255.0
    Default Gateway  192.168.1.254
    DNS                   192.168.1.254
    There is no advantage in using DHCP, unless your computer is used on other networks. Static addressing is quicker and more reliable.
    If you need to use DHCP, then make sure the subnet mask is set to 255.255.255.0
    There are a couple of DHCP pools within the home hub, one is reserved for the BT Openzone/FON VLAN connection.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Get Default Gateway Address from BB app

    Hi,
    I need to get the WIFI default gateway address from an application. I searched in all the forum without a positive result. Some people talks about using WLanInfo but it does not provide the default gateway address.
    Can anyone help me?
    Thanks!

    same question as before... are you developing an application?
    http://supportforums.blackberry.com/t5/Downloaded-applications-for/Get-Default-Gateway-Address-from-...
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • RSV4000 DHCP Gateway address problem

    I have an RSV4000 which I'm using as a gateway. I changed the default 192.168.1.0/24 network to 10.255.255.0/24 and configured the DHCP address pool to use 64 host addresses starting at 10.255.255.64
    Every so often users on VLAN 1 get a gateway IP address of 192.168.1.1 even though they received a DHCP address of 10.255.255.64, 65, 66, etc.
    I ran a packet capture and the RSV4000 is actually giving out the wrong gateway address.
    I have to power cycle the RSV4000 and it works until some random point in time, then starts giving out the wrong gateway address again.
    Is Cisco going to fix this?
    I'm running version 1.3.2.0 and I do not have the V4 model so I can't run v2.0.0.3

    Hey mdoldan,
    Were you the one that upgraded the firmware of 1.3.2.0 on the router or did you receive it like that.
    This is a very odd case, where it is giving out ip address on the default lan even though you changed it.
    Have you tried reflashing the firmware, factory resetting the router and reloading the configurations back to it.
    I would try that and see if the problem persist.

  • Get default gateway address

    Dear all
     i saw a function in TCP library that can get the host address.  but do somebody now how to get the default gateway address ?
    e.g
    IP  192.168.0.4            ( this ip can obtain by get host address function )
    subnet 255.255.255.0
    deault gateway 192.168.0.1
    B.R
    Gerry
    Solved!
    Go to Solution.

    Hey Gerry -
    To get the default gateway, you'll want to use the Win32 IP Helper API.  Unfortunately, this portion of the Win32 API is only available to users of the Full LabWindows/CVI package. 
    To retrive IPV4 information about your network adapters, you can use the function GetAdaptersInfo.  If you need IPV6 information, you'll need to use GetAdaptersAddresses.  I wrote a quick example of using GetAdaptersInfo and attached it, you can see the output below:
    Let me know if you have any questions -
    NickB
    National Instruments
    Attachments:
    DisplayIPInfo.c ‏3 KB

  • Get IPv6 gateway address on Windows XP

    Hi guys,
    Windows XP supports IPv6, but if I want to get the IPv6 gateway address linked to an adapter I've a big problem:
    GetAdaptersInfo can get the gateway address but works only with IPv4
    GetAdaptersAddresses works with IPv6 and can get the gateway address, but the related parameter FirstGatewayAddress of its structure ip_adapter_addresses was added only on Windows Vista and later
    Win32_NetworkAdapterConfiguration WMI class can retrieve IPV6 gateway address but it is available only from Vista
    What can I do?

    No simple way, basically, on XP+ use GetAdaptersAddresses, it adds ipv6.
    XP has been end of support by MS, so maybe upgrading OS is a better way to promote things forward.
    Best Regards,
    Please remember to mark the replies as answers if they help

  • HT204023 Gateway address

    How do I find my gateway address ?

    Good point!
    No, this would not work on a non-Apple router.
    Thanks.

  • Gateway Address ???

    I have an iMac which is connected via an AirPort router. I have no problems getting online. However, I am trying to connect a blu-ray player to the network and it asks for the Gateway Address. I can't find it anywhere. Can anyone help?

    danbee46 wrote:
    I have an iMac which is connected via an AirPort router. I have no problems getting online. However, I am trying to connect a blu-ray player to the network and it asks for the Gateway Address.
    I believe it's the LAN address of your AirPort router, such as 10.0.1.1.

  • NAC Inband Trunk on Untrusted Interface

    Hi,
    I am query regarding inband implementation of NAC server.
    Is it possible to have multiple vlans to terminate on the untrusted interface of the NAS in real gateway mode?
    Is this is the case, how can  I add an IP address to each vlan ID on the untrusted interface.
    The aim is to implement the following deployment.
    The network architecture is a collapsed Core, Distribution/Core on the same 2 switchs with SVIs on the distribution switchs for all the vlans. Since the network may not have all cisco switchs, I am forced to use Inband deployment.
    I wanted to trunk required vlans to the NAC untrusted interface, remove the SVIs on the Distribution Switchs forcing vlan clients onto the NAC.
    The trusted NAC interface will be connected to a SVI vlan or L3 interface on the distribution switch.
    Since the NAC is in real gateway mode, DHCP pool or DHCP relays need to configure on the NAC server as well.
    As a summary, can you please advise if it is possible to create something like SVIs on the NAC untrusted port and define DHCP relay on those SVIs on the untrusted interface.
    Thanks,
    Ashley

    never mind,
    I didn't add VLAN 111 to the VLAN database.
    not it is working.
    thanks
    Alex

  • Default Gateway address for multiple VPN users/clients

    Hello,
    We need some help with a VPN setup for a school project.
    What we want to do:
    We would like to have aprox. 10 different VPN uses that can connect to our Windows Server 2012 R2 which is setup as a VPN server, by the Role called Remote access. And the VPN server is working and we are able to connect to it from another location/computer.
    Our current setup:
    We have a Cisco router, that are configured with 10 Vlans, from Vlan 10 to Vlan 20, and a managament Vlan called Vlan 100.
    The Cisco router is also acting as DHCP server, so inside each Vlan the DHCP gives IP addresses to that specific Vlan, Ex: Vlan 10 has a 192.168.10.0/24 network. Vlan 11 has a 192.168.11.0/24 network, and so on. Vlan 100 has 192.168.100.0/24 This Vlan 100
    has connection to all the Vlans.
    We have internet connection on the Router on port 0 and each Vlan are connected to the internet.
    We have setup the VPN server with a static IP configuration so it is inside Vlan 100 with a Default gateway, like 192.168.100.1 So the VPN server is connected to the internet.
    In AD we have created a User and assigned a static IP address in the user properties, under the Dial-In tab. Here we give this user this IP 192.168.10.225
    Now when we connect to the VPN server useing this user, we have no connection to any of the Vlans (ping) and no internet. When we in cmd write ipconfig we can see that our VPN connection has this IP 192.168.10.225 but a Subnet called 255.255.255.255 and
    a Default gateway called 0.0.0.0
    We would like the user to recieve the correct IP settings like: If we connect with our user, it should recieve the IP as it does, but also a subnet called 255.255.255.0 and a default gateway called 192.168.10.1
    How is this achieved?
    The reason we want this is: We want to create a VPN user for each Vlan. So a user with permission to access Vlan 10 but are not able to see the other Vlans, and then a new user to access Vlan 11 but not able to see the other vlans, and so on.
    Hope someone is able to help us to understand how this is done.
    Thank you in advance.

    Hi,
    In brief, we can't achieve this. Normally, we would not do this.
    Usually, we use firewall or ACL to restrict the remote users.
    For example, 192.168.10.100 is assigned to user1 and 192.168.10.101 is assigned to user2. We can use firewall to restrict 192.168.10.100 to access 192.168.10.0/24 and 192.168.10.101 to access 192.168.11.0/24.
    Best Regards.
    Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Maybe you are looking for

  • Can i use two iphone on one account

    is there a way that i can use my itunes for two iphones 1 is a iphone4  and a 3sg i want to update the 3sg but it wants me to setup a whole new acct. do i realy need to do this.........

  • A/R Credit Memo   --  G/L Account

    Hi All, when i am adding an A/R Credit memo into the B1 system the error message appearing as follows : "A/R Credit Memo - Document Number, G/L Account is missing" What could be the reason ? thanks Venkat

  • Installing apps to macbook pro help

    I'm new to the macbook world, and wanted to know if I can install my purchased iphone or ipad apps to my macbook pro, and more importantly how to do it. I've read some info but still having a little trouble. Have moved app to the applications folder,

  • Controlling external displays

    When using a secondary display with my macbook pro is it possible to choose what is viewed on that external display? say i could be running a presentation on the external display but be looking at another program on the macbook pro without it being s

  • Halp with photos

    Can any one tell me what kind of cable I need to get to be able to connect my ipod to my camera. I found this one that looks close Apple iPod Dock Connector to FireWire Cable. I am going out of the country and I don't want to have to take my laptop.I