NAC Profiler integration - cant add filter list on CAM

Hi All,
I have a problem regarding the Profiler - NAC integration for end point profiling.
Here is the situation:
I already created the integration based on the steps on the guide: Configuring Cisco NAC Appliance Integration. I think the configuration is correct because i can do database synchronization between Profiler and CAM. Here is the Profiler server log:
   NAC_SYNC: Task_Queue_Runner starting up
   NAC_SYNC: Profiler / NAC Synchronization END [add 0, upd 0, desc 0, rm 0]
   NAC_SYNC: Profiler / NAC Synchronization START
   INFO: [2010-12-15 11:01:09 (fcapGetHWAddr:49)]  Getting MAC for eth0
I already created end point profile named "Admin" which is based on IP address. I also created NAC events based on the end point profile "Admin".
The NAC event is profiling "Admin" to a NAC role. The purpose for this event is to bypass "Admin" from NAC authentication so that the "Admin" can connect to network automatically to one NAC role.
However when "Admin" connect to network, it is still challanged by NAC. I dont see the "Admin" on the CAM filter list either.
This means that the end point profiling is still failed.
Is there anyone who have any experiences with this?
Thank you for the supports and comments
Imad

Hi,
Ok, so the Profiler will only add devices to the CAM filter list, if a device fals into a profile for which a nac event is configured.
If there is no device on the profile -> No NAC event -> No device added to the CAM.
Is there any device that was assigned to that profile?
Regarding the Active Rule column, it is used to quickly  ascertain which Endpoint Profiles on a system (if any) contain an Active  Rule that will result in the Profiler system doing active collection if  one or more NetInquiry Collector component modules are enabled. Active  profiling rules and active profiling is described in detail in the "Configuration of Active Directory Data Rules" section: http://www.cisco.com/en/US/docs/security/nac/profiler/configuration_guide/311/p_endpt_part231.html#wpxref59325.
HTH,
Tiago

Similar Messages

  • NAC problem. Cant add server.

    Hi all!
    I cant add a nac server to CAM. Error: Failed to add server: Conflicting Clean Access Server with IP address <10.52.244.146> must first be removed.
    I add server with ip: 10.52.244.194. I checked all the settings. This address is not use in the settings of server whit IP - 10.52.244.146.
    In the logs I dont see useful information.
    Why do I have this error on the CAM???

    Jennifer. In CSCtd27095 says: The repair updates only the CAS file locally. The fix/repair should update the CAM's database with the CAS's new SSKey. I reconfigure perfigo service with right SSkey on my CAS (10.52.244.194). Does not help. I cant reconfigure perfigo on my CAM, because 10 servers in work.
    P.S.
    When i delete CAS with IP 10.52.244.146, then i can add CAS (10.52.244.194). But when i just change CAS IP - 10.52.244.194 on, for example, 10.52.244.154 anyway i see this error.
    What create a conflict of these servers?

  • Cant add buddies to my bonjour list

    i have an aim ichat and a mac ichat account but i like using my bonjour but i cant add any of my buddies to my bonjour list. there isnt a button to press to add buddies

    No.
    This auto-discovers other Macs on your LAN with iChat (and the Bonjour part) ON.
    A LAN is a Local Area Network (every computer and router your side of your Modem.
    Bonjour therefore does not work over the Internet.
    10:10 PM Friday; August 28, 2009
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"

  • MAC address gets removed from the CAM 4.8 Filter List??

    Hi,
    we got WLC and NAC integration going. I have a smartphone wi-fi client I would like to exclude from logon and posture assessment, so I add the MAC into the CAM's Filter List. It works fine for a short while and then the MAC gets deleted from the list for some reason. Here’s what CAM log show (roughly an hour between the MAC is manually added and then gets deleted):
    any ideas why it's happening and how to fix this?

    Faisal,
    I looked through the NAC log again, and I did miss another piece of info, so here's how the log looks after adding the MAC in the filter list:
    Administration      2010-11-01 17:53:31       38:E7:D8:0B:42:A3  added to MAC list
    Administration      2010-11-01 18:51:10       38:E7:D8:0B:42:A3  removed from the MAC list
    Administration      2010-11-01 18:51:10       (API removemac): Succeeded!
    So, it looks like there is some process running that removes the MAC from the list every time it's added in raughly an hour?
    Dmitri.

  • NAC Profiler 2.18: Endpoint Profiles Missing

    This is a licensed Nac Profiler which has no canned Endpoint Profiles included.
    I go to Configuration--->Endpoint Profiles---> View/Edit Profile List
    The message I see is "No Profiles Found"
    Please clue me in on what I am missing.
    This is from the install guide:
    "Enabling Existing Endpoint Profiles
    Cisco NAC Profiler ships with a number of predefined Endpoint Profiles that have been created and tested in field deployments. These Profiles can be re-used as-is if desired, or may be modified as the situation dictates. In addition, they serve as templates for creating new profiles as outlined later in this section, and illustrate how different rule types and varying levels of certainty can be used to accurately Profile devices.
    To view the list of Endpoint Profiles that are currently available in the system configuration, navigate to the Configuration tab, and select Endpoint Profiles option from the global navigation menu in the far left hand pane, or select Endpoint Profiles from the leftmost column of the table on the main Configuration page. Select View/Edit Profile List to display the Endpoint Profiles currently saved in the system configuration."
    Thanks.

    To verify that Cisco NAC Profiler is populating entries properly in the Device Filter list of the CAM, log into the CAM as administrator. Select the Filters button under Device Management in the left-hand navigation bar. The following screen displays in the main pane of the browser, enumerating all the endpoints currently on the CAM Device Filter list.
    After configuring the Server module parameters, adding NAC Events, and performing a Synchronization process (full or NAC Event level), the endpoints that are in the Profile(s) matching enabled (and synchronized) NAC events should be populated to the device filter list of the CAM.
    http://www.cisco.com/en/US/docs/security/nac/profiler/configuration_guide/218/p_integration.html#wp1055729

  • Cisco NAC profiler

    Hi,
    I have few doubts if any1 can clear out it will be great. i have NAS OOB real ip gateway deployment in my network.
    Assuming all the ports are Nac_controlled. Hence as soon as the client plugs in they will be in auth vlan.
    now i have a cisco nac profiler in my network which i am going to configure for IP phones and printers.
    for example if the port the ip phone is connected to it will be under auth vlan also.
    hence as soon as ip phone as gets connected it, cisco profiler will see the profile and change the auth vlan to its respective vlan by mapping the profile with nac profile which we have mapped in the profiler and given the vlan in the NAC user profile for the ip phone.
    please correct me if i am wrong, for the understanding of the working. I need to profile ip phones. i am not able to bridge the connection.
    it would be great help if you can help me out.
    thanks in advance.

    Dear Nitesh,
    The IP phones should be configured to work on the Voice VLAN; the NAC Manager on its OOB config can only manage the access VLAN for the switch port.
    Given this, the correct config for the filters for the IP Phones is "ignore", as described here:
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_addSrv.html#wp1092789
    The NAC Profiler can help to add these filters without manual intervention, so you should configure the Profiler with the appropriate NAC event that configures the filter for the IP Phone MAC address to "ignore".
    This won't cause the port to change status NAC wise, as the NAC Manager will simply "ignore" the MAC notification for the IP Phone(s).
    I hope this helps.
    Regards,
    Federico
    If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.

  • I would like to add a new Canon camera profile to the RAW interface

    Hi,  I would like to add a new Canon camera profile to the RAW interface.
    I have recently installed the new camera profile 'Studio Portrait' which i download from here:
    http://www.canon.co.jp/imaging/picturestyle/file/studio-portrait.html
    When I open up a RAW files in Camera RAW, go to 'Camera Calibration', click on the drop down list called
    'Camera Profile'  I only see  'Adobe Standard, Faithful etc etc'.
    My questions are, can i add the same camera profile i put in my camera, into a folder with in photoshop?
    Or is photoshop reading the raw file and only seeing the default camera profiles?
    If I could see the new camera profile listed it would help with work flow.
    Best
    JL-B
    Please help, ive not had a good time waiting on the phone and trying to explain this to a live chat, hours have been wasted. Once i know the answer I can get back to the commission.

    Are you following this
    Apply a camera profile
    To apply a camera profile, select it from the Camera Profile pop-up menu in the Camera Calibration tab of the Camera Raw dialog box. The Adobe Standard profile for a camera is named Adobe Standard. Camera Matching profiles include the prefix Camera in the profile name. The Camera Profile pop-up menu displays only profiles for your camera.
    If the only profile in the Camera Profilemenu is Embedded, it means that you have selected a TIFF or JPEG image. Adobe Standard and Camera Matching profiles work only with raw images.
    Note:  If you have selected a raw file and Adobe Standardand Camera Matching profiles do not appear in the Camera Profilepop-up menu, download the latest Camera Raw update. 

  • How to add a list box with values for a ztable in SM30

    Hello Gurus,
                    I had created a table maintenance for Ztable and added many extra functionality to that. Now i would like to add a list box or check table for a field. Can i do that with out Regenerating my table maintenance. Please help me its..very urgent.

    Have referred this domain to the data element, this should be the Field type in ur table for the particular field.
    Eg: <b>SE11 > table name > fields-ZTEST > fieldtype-ZZTEST</b>
    ZZTEST in the data element > create a domain for this data element and in that specify teh value range.
    Save and activate it.
    Make sure that u regenerate teh table maintenance generator else u cant see the changes.
    Now if u press F4 u can see only thevalues specified, also u will see only the list box with values in SM30.
    Try this,please let me know if u face any difficulties.

  • I have original ipad and however I cant add my phone number to lmessage it will only take an email address . Is this correct ?

    I have original ipad and however I cant add my phone number to lmessage it will only take an email address . Is this correct ?

    I copied this from an Apple Support article.
    If your phone number is not listed on an iPod touch or iPad, follow these steps:
    Update to the latest version of iOS.
    Verify that you're using the same Apple ID that you are using on your iPhone.
    On your iPad or iPod touch, sign out of your Apple ID in the following locations:
    Settings > Messages > Send & Receive. Tap your Apple ID, then tap Sign Out.
    Settings > FaceTime. Tap your Apple ID, then tap Sign Out.
    Sign in to your Apple ID with FaceTime and iMessage.
    If your phone number is still not listed, follow these steps:
    Sign out of your Apple ID on all iOS devices, including your iPhone, in the following locations:
    Settings > Messages > Send & Receive. Tap your Apple ID, then tap Sign Out.
    Settings > FaceTime. Tap your Apple ID, then tap Sign Out.
    Sign in to your Apple ID on your iPhone.
    When activation is complete, your Apple ID and all verified email addresses should be visible in Settings > Messages > Receive At and also in Settings > FaceTime.
    Now sign in to your Apple ID on your other iOS devices.
    This is the website for the support article.
    http://support.apple.com/kb/HT5538

  • Cant add folder to library

    I just reset my computer and re installed itunes 11 and I cant add folder to library but can add files but have 5k songs and that will be a PAIN, and I looked on google and apple for 3hrs now and still cant find a solution. I been having a ipod and itunes for about 6 years now and never had a problem like this.

    The main differences between iTunes 11 and earlier versions are the loss of coverflow and ability to have multiple windows open. Other familiar features have been hidden but can be revealed...
    You can restore much of the look & feel of iTunes 10.7 with these shortcuts:
    ALT to temporarily display the menu bar
    CTRL+B to show or hide the menu bar
    CTRL+S to show or hide the sidebar
    CTRL+/ to show or hide the status bar (won't hide for me on Win XP)
    Click the magnifying glass top right and untick Search Entire Library to restore the old search behaviour
    Use View > Hide <Media Kind> in the cloud or Edit > Preferences > Store and untick Show iTunes in the cloud purchases to hide the cloud items. The second method eliminates the cloud status column (and may let iTunes start up more quickly)
    If you don't like having different coloured background & text in the Album (Grid) view use Edit > Preferences > General and untick Use custom colours for open albums, movies, etc.
    Use Edit > Preferences > Show list views for all media to do just that
    From iTunes 11.0.3 you can enable artwork in the Songs view from View > Show View Options (CTRL+J) making it more like the old Album List view
    View > Show View Options (CTRL+J) also contains options to change the sorting of grid based views
    tt2

  • After installing FF 5.0 I am receiving a list of incompatible Add-Ons. I go into 'Extensions' and click to remove them, exit FF and lauch FF again, the same incompatible add-ons list appears. Is there a way to permanently remove the old Add-ons?

    After installing FF 5.0 I am receiving a list of incompatible Add-Ons. I go into 'Extensions' and click to remove them, exit FF and lauch FF again, the same incompatible add-ons list appears. Is there a way to permanently remove the old Add-ons?

    Thanks but I don't think this will help. Like I said, all of my add-ons were working fine and compatible until after running a previous version of FF. I am sure they are still compatible, but they are not working at all.
    I even checked my profile folder and all of the extensions' data is all still there but FF5 is just not reading it correctly. (like adblock plus... I see the folder for it but FF5 doesn't have it on the add-on manager page when I run FF5)

  • Contacts file, cant add or delete!

    Ive a curve 8900 one year old, had a few small problems with it fixed by the 02 shop but now I cant add or edit contacts, but I can delete (which doesnt help) even from a text or call I cant save their number, have updated software recently but it didnt help.  Have 2 week waiting list to see a guru at the shop.  Any ideas?

    Hi VictoriaRose10,
    Have a look at this article for more information on the possible causes of this issue. http://bbry.lv/qVxr8x
    Hope this helps,
    -FS
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.
    Click Solution? for posts that have solved your issue(s)!

  • How to add ordered list, subscript in RichtextEditor?

    Hi,
    In the richtexteditor I need to add the ordered list button(like the bullet) and a button for subscript, is ther any way to that.
    I have the information how to add a Find/Replace button.
    Also can anyone provide me the format for ordered list.
    Help me regarding this.
    TIA

    Hi,
    Try this :
    super.processRequest(pageContext, webBean);
    OADefaultListBean list =
    (OADefaultListBean)createWebBean(pageContext, OAWebBeanConstants.DEFAULT_LIST_BEAN,
    null, "popuplist");
    list.setListViewObjectDefinitionName("oracle.apps.per.selfservice.competency.profile.server.CompSearchVO");
    list.setListValueAttribute("compType");
    list.setListDisplayAttribute("compType");
    list.setMultiple(true);
    list.setName("poplist");
    OAMessageComponentLayoutBean listboxlayout = (OAMessageComponentLayoutBean)webBean.findIndexedChildRecursive("searchFiltersRN");
    if(listboxlayout!=null)
    listboxlayout.addIndexedChild(list);
    Check for the correct id of the OAMessageComponentLayoutBean as this is the correct code to add the list bean.
    Thanks,
    Gaurav

  • NAC Profiler DNS Name Queries

    Hi Guys,
    I'm having an issue with NAC Profiler 3.1.1_18 when trying to profile servers using DNS Name.
    I have one collector configured to  do DNS Collection with Zone transfer enabled.
    If I do a search with string *.server.*, the system returns me just servers with the word "server" in dns name. This is working fine.
    But when a create a profile (named Servers) and add a rule to match dns server names with the string *.server.*, profiler will put in the Servers' profile all devices that has any data on DNS Name field. no matter if it has the word "server" in the name or not.
    Any idea about what I'm forgetting?
    NetInquiry Configuration
    Module Status:
    Running
    Maximum allowed workers:
      (default = 5)
    Enable DNS Collection:
    Zone Transfer:
    Domain Name:
    Network blocks (one per line):
    10.0.0.0/8

    Hi Luciano,
    You may wanna test quickly by using the following string in the DNS Name field: /server/i
    Regards,
    Fede
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • How to add a list bean in seeded region?

    Hi All,
    I am working on "employee self service" responsibility addcompetency page.on which I have a requirement to add a list bean. Fro that I have extended CO and added folowing code in that co.
    super.processRequest(pageContext, webBean);
    OADefaultListBean list =
    (OADefaultListBean)createWebBean(pageContext, OAWebBeanConstants.DEFAULT_LIST_BEAN,
    null, "popuplist");
    list.setListViewObjectDefinitionName("oracle.apps.per.selfservice.competency.profile.server.CompSearchVO");
    list.setListValueAttribute("compType");
    list.setListDisplayAttribute("compType");
    list.setMultiple(true);
    list.setName("poplist");
    OAMessageComponentLayoutBean listboxlayout =
    (OAMessageComponentLayoutBean)webBean.findChildRecursive("searchFiltersRN");
    pageContext.putDialogMessage(new OAException("Hello" + listboxlayout));
    But It is returning null in Dialogue message.The Id is Also right.
    Please Help.
    Regards,
    SHD

    Hi,
    Try this :
    super.processRequest(pageContext, webBean);
    OADefaultListBean list =
    (OADefaultListBean)createWebBean(pageContext, OAWebBeanConstants.DEFAULT_LIST_BEAN,
    null, "popuplist");
    list.setListViewObjectDefinitionName("oracle.apps.per.selfservice.competency.profile.server.CompSearchVO");
    list.setListValueAttribute("compType");
    list.setListDisplayAttribute("compType");
    list.setMultiple(true);
    list.setName("poplist");
    OAMessageComponentLayoutBean listboxlayout = (OAMessageComponentLayoutBean)webBean.findIndexedChildRecursive("searchFiltersRN");
    if(listboxlayout!=null)
    listboxlayout.addIndexedChild(list);
    Check for the correct id of the OAMessageComponentLayoutBean as this is the correct code to add the list bean.
    Thanks,
    Gaurav

Maybe you are looking for

  • IPhoto 11 - Saving/Exporting Photos Edited in iPhoto 11

    I just updated to iPhoto 11 from what I think was iPhoto 09. In my previous version of iPhoto, I would import photos from my camera, edit (crop, straighten, adjust, etc) and then I would FILE/Export photo in .jpg format to my hard drive for backup an

  • User Name and Password for SQL*Plus

    Please tell me how can I the right user name in password in the SQLPLUS

  • Partial payment for invoice

    Hi what settings needs to be done to activate partial payment of invoice ? During MIRO, where we can maintain the invoice for partail payment? Thanks Manoj

  • Some question for experts !! Urgent

    I have following queries: 1) When a copy fucntion fails, if i get an error message saying a variable could not be determined. Can i change the text for the same to make it user friendly. 2) If i have a fucntion geeting executed before display of layo

  • How to intigrate the web services?

    Hi Experts. I created internt services in SE80 and activated using SICF,I'm able to test individaul service working fine, I wanted to call one service from others and estblish a flow, How we can do this ? Thanks Naveen