NAC 4.7.2 ever validity

I have a setup of the NAC, which has 1 server and 1 Manager. Everything is runing and fine.

I use the free sign generated by Manager and the server certificate. The validity of the certificate is just 3 months. Can I increase the validity of the

certificate. I worked on an earlier version as 4.6,4.5 4.7.1 it validity were about 5 to 10 years.

Is it of any other workaround.

Talha,

No way, but you can generate certificates using openssl and install them on the NAC devices.

I'm including the output from my example class that I did just to give you an idea of what should look like the race. What I typed is red:

[[email protected] / * / ~] # mkdir NewCertDirectory
[[email protected] / * / ~] # cd NewCertDirectory
[[email protected] / * / NewCertDirectory] # openssl genrsa 1024 > NewPrivateKey.key
Generate an RSA private key, modulates long 1024 bits
...........++++++
.............++++++
e is 65537 (0 x 10001)
[[email protected] / * / NewCertDirectory] #.
[[email protected] / * / NewCertDirectory] # openssl req - new - key NewPrivateKey.key - out NewCertificate.csr
You are about to be asked to enter information that will be incorporated
in your certificate request.
What you are about to enter is what is called a distinguished name or a DN.
There is a certain fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the area will be left blank.
-----
Name of the country (2-letter codes) [to THE]: U.S.
State or Province (full name) [Some-State]: NC
Locality name (for example, City) []: RTP
Name of the Organization (e.g., company) [Internet Widgits Pty Ltd]: Cisco
Organizational Unit Name (eg, section) []: TAC
Common Name (eg, YOUR name) []:www.Your_CAS_Name_Here.com (this is the host name or the domain name of your certification authorities for which you generate the certificate. In the case of the AH, that would be the name which resolves to the VIP of the SCA)
[] E-mail address:

Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
A business optional name []:
[[email protected] / * / NewCertDirectory] #.
[[email protected] / * / NewCertDirectory] # openssl x 509 - req-days 1000 - NewCertificate.csr - signkey NewPrivateKey.key - out NewCert.crt

OK signature
subject = / C = US / ST = NC/L = RTP/O = Cisco/OU = TAC/CN =www.Your_CAS_Name_Here.com
Get the private key

[[email protected] / * / NewCertDirectory] # cat NewPrivateKey.key > NewCert.crt

Now you can take this NewCert.crt file and install it on the NAC devices using the GUI. Use WinSCP to copy the

file.

HTH,

Faisal

Tags: Cisco Security

Similar Questions

  • ACS + NAC-L2-IP & 802. 1 x

    Hello! I implement NAC now, I knew of the NAC Framework configuration guide, I can use the NAC-L2-IP for posture validation, but this model (technology) does not provide the identity of the user. So the question is - at the same time we use the NAC-L2-IP for the validation of the posture and 802. 1 x for authentication of the user (using MS-CHAPv2) on Catalyst 3560 G and with ACS 4.1?

    Thank you in advance!

    Yes, this can work. If you are migrating at some point to have NAC with 802. 1 X, well, you will get are studying twice on the ports configured for two well.

  • Count the hours between the times of the day

    Hello

    It is a timesheet, calculation of payment:

    I'm trying to find a way to calculate how many hours is between two specific times of the day.

    I enter a start time and an end time (in 2 different items), I calculate the number of hours that is. What I can understand.

    Then I need to know how many hours is between 16:00 and 22:00.

    The reason is that there is an additional extra payment for those hours.

    So: "payment on time' X ' total hours work in a day ' + 'bonus' X ' hours between 16 and 22" = "total wages for a day" "»

    Thank you

    Enter the full date and time in columns A and B (for example ' 12 Sep 2016 8:00 AM "or you like the what ever valid date time value):

    C2 = B2−A2

    D2 = C2−DURATION (0, 0, 24 × MAX (TIMEVALUE "(04:00 PM)") −TIMEVALUE (A2), 0)) −DURATION (0, 0, 24 × MAX (TIMEVALUE (B2) −TIMEVALUE (' 22:00 "" "), 0))

    Select cells C2 and D2, copy

    Select cells C2 at the end of column D, dough

    If you prefer the values in column D as decimal hours use the formula:

    dur2hours (D2)

    or replace the formula earlier as follows:

    D2 = dur2hours (C2−DURATION (0, 0, 24 × MAX (TEMPSVAL ("04:00 PM") −TIMEVALUE (A2), 0)) −DURATION (0, 0, 24 × MAX (TIMEVALUE (B2) −TIMEVALUE (' 22:00 "" "), 0)))

  • Bindings.Size (ObservableList) is not updated when the item is deleted

    I have code like this:
              myLabel.textProperty().bind(new StringBinding() {
                   {
                        super.bind(Bindings.size(myList));
                   }
    
                   @Override
                   protected String computeValue() {
                        int s = myList.size();
                        return s + " item"+((s == 1)? "":"s") +" left";
                   }
              });
    When I run my application and load data in my list, via myList.setAll (otherList), I see the text of the label update.
    But when I call myList.remove (someItem) the text of the label is not updated.
    Am I missing something?

    Yes, the problem is that you have created a link (Bindings.size (myList)) but you never go to this link. This binding therefore will be cancelled once, and because it is never accessible, even once, it will become ever valid.

    Try this code instead:

         myLabel.textProperty().bind(new StringBinding() {
                    private IntegerBinding sizeBinding = Bindings.size(myList);
                   {
                        super.bind(sizeBinding);
                   }
    
                   @Override
                   protected String computeValue() {
                        int s = sizeBinding.get();
                        return s + " item"+((s == 1)? "":"s") +" left";
                   }
              });
    
  • Trying to receive a code of validation on my cell phone, but I never text message.

    My Live account has been restricted for a reason any and I have a request to confirm my account with a validation code that will be sent to my phone in a text message.  After several tries, I ever text message.  The phone # seems good (but it doesn't have a 1 on long distance in front of it).  Is there another way to validate my account?

    HI Neil,

    Thanks for posting your question in the Microsoft answers Forum. For any question about Windows Live accounts, please see the following link:

    http://windowslivehelp.com/forums.aspx?ForumID=d3fda415-1e53-4007-8e0c-2a77180ffb1d

  • Validity Sensor (VFS301) does not not portable dm4

    Just bought a Pavilion laptop provided with the scanner of validity Fingerpring dm4. As soon as I bought the laptop, I was quick to install Windows 7 Pro 64-bit because my job requires additional features in Win 7 Pro. The BONE that was preinstalled was Win 7 Home Premium

    So, here is my problem, the scanner fingerpring does not work. I have the correct driver installed on the site of hp (found here) and after the reboot, it still does not work. I installed the hp Support application that scans my notebook for the latest drivers and found no update needed. I have not tried roll back driver option is unavailable (one pilot has ever been installed anyway) and I also tried to uninstall the driver, reboot, reinstall the driver, reboot, and it still does not work. I also tried to do the same thing just previously mentioned but this time as an administrator (right click, "run as Administrator") running of the facility. Still nothing... I tried also to navigate to the folder of the driver on C:\ then runing the application as an administrator, but always come up short handed...

    Sometimes the light as his work, but when I use to register my fingerprints, it just won't do anything.

    Is there another piece of software in addition to the driver I need to install to get this working?

    Please help, thanks!

    -Jacob

    Click Start , type device in the search box, and select Device Manager from the list of search results.
  • I am YOA 70 and have used windows 2000 XP Prof. from the arch, too late to change. Not worried about support, this is the best OS ever. I have a copy of old 180-day evaluation. Can I use it or get another copy.

    What I can tell, the problem is simple... The solution cannot be more simple!

    "Can I use it or get another copy."

    After the expiry of 180 days would be illegal to continue using it without a valid license, even using worarounds or reinstalling the operating system.

    The windows 2000 and Windows XP are different products, but the answer is the same, they are abandoned products would be very difficult to buy a license. You can search the remaining stocks, would be not easy but possible to buy it.

    "best OS ever."

    Tried the 7?

  • I received an email telling me that I was charged for something I've ever had.

    Original title: billing

    I received an email telling me that I was charged for something I've ever had

    It might be spam.

    (1) the validity of the sender (name, phone number, mailing address, etc.)

    (2) check if they understand your credit card or checking account numbers in the Email.

    If they then contact your banking company or credit card on the possible actions you can take if you think that it is a fraudulent attempt to get the $$$

    J W Stuart: http://www.pagestart.com

  • Base installation of Cisco NAC

    Hello

    I bought a Cisco NAC server and a Cisco NAC Manager.  I have it in the laboratory to test for the moment, but I would extend approximately 200 users possibly on campus lan.  I just check that a user is valid on active directory.  Perhaps the best way I can do that is by making a discovery on the server of the NAC to valid mac addresses.

    What is the best way to do this? That is to say

    user connects to a port on the campus lan

    Active directory checks that they are a valid user on the domain

    they get their usual dhcp address once they are authenticated

    If they are not a user validates on the field that they will not be authenticated

    I'm not worried about the verification of the antivirus, pc built... for now

    For the moment, I installed the server of the NAC and the NAC Manager and both can access it through a layer 3 switch.

    Thank you

    Kevin

    Kevin,

    Essentially, you ask for advice on how to do this. As I just pulled out of 1000 users NAC L2 VG OOB (who looks like, it's what you want to do) and a 3000user of the NAC L3 RIP OOB as well as OOB wirless and looking IB VPN right now. My best advice would be to buy the next book.

    Cisco NAC Appliance 'Host security with clean Access Application' by James Heary for about $60. (available on Amazon)

    This covers all deployment scenarios and is invaluable for me when I created the NAC. What it does is put in the necessary steps and is easier than flitting back and forth between the CAM and CASE manual.

    Hope that helps

  • Profiler in the NAC 2.1 to 3.1 upgrade

    Hi guys,.

    I'm setting up a Profiler from the NAC that accompanies 2.1 installed. I upgraded to 3.1, prayed and installed the license without any problems, but I always get this message: "ERROR: [2010-12-08 09:25:01 (main: 668)] valid no key not found [no such file or directory]" "

    The license file exists, and on the interface Web Profiler from the NAC, the State of the license is OK.

    A single line in the license file gives me this information: 'cisco 2.1 INCREMENT CCA-MANAGER countless Permanent '.

    Does anyone know if the license is linked with the version of Profiler?

    The upgrade from 2.1 to 3.1 is allowed or it is necessary to purchase a new license 3.1?

    Best regards

    Hello

    So I guess you spotted the problem here...

    You have a collector's license?

    You need 2 licenses: 1 to the server profile, and one for the collector.

    Basically, the mac address you provide is the same (eth0 ot Server Profiler), but you need a PAK Server Profiler to generate the license Server Profiler (the one you already have) and a PAK for license collector (which is missing).

    You have the collector PAK?

    If Yes, then just go to the license page and submit this PAK and the mac address.

    HTH,
    Tiago

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • NAC 4.1.3

    Hello friends,

    I installed a new NAC 4.1.3. When users connect they get the popup of the certificate press the button YES, I generated the certificate in the Manager and the server according to the user's guide,

    where I m missing something? I think that something in the certificate. The certificate that I generated will be valid until when?

    Thank you

    Estela Hi,

    4.1.3 use perfigo signed certs and it is a matter of import perfigo root certificates to get rid of this error popup from your PC. You may need to find ways as window GPOS to automate this task. But given that CA perfigo is a non-standard certificate authority, it is recommended to buy a 3rd party cert CA such as verisign, godaddy etc and install on the heap. Most / All PC's will have this installed by default CA cert and they see this popup error also.

    Thank you

    Mani

  • NAC L3 OOB does not not on WAN

    I'll put up proof of lab validation for installation of the NAC.

    I use Cisco Catalyst 3550 and 2950 switches (the real environment is using 3750 and 2960 and 2950 switches) and have defined NAC in Central L3 OOB configuration. In this configuration, I have a SIN and NAM "MAIN_SITE" and then two sites branch "BRANCH1" and "BRANCH2.

    On the main site, the OOB works very well, and when a user logs in, the port is moved from the VLAN authenticated (290) role service VLAN (200) However, in the 'branches' switches do not put the port in the role in function of VLAN, or if a port is in VLAN 200 and a PC is connected to this port don't switch port to 290 of VLAN (unauthenticated).

    Sniff traffic with Wireshark, I see SNMP sets sent by the NAM to the switch to tell it to place the port VLAN 200, but the switch does not.

    My writing strings are configured correctly and the NAM is able to implement initial orders on the switch for the NAC ('mac-added notification of snmp trap' orders for the ports).

    Can we say what is the problem?

    Sachin

    Sachin,

    Must be at least 12.1 (14) EA1

    Visit this link for all the switches you need for OOB and supported codes: http://bit.ly/SwitchSupport

    HTH,

    Faisal

  • How to check Qlogic NAC (C-200-M1) in ESX 4.0

    Hello

    I work with C-200-M1 server with 1 Qlogic FCoE, CNA. I just installed ESX 4.0 Update 1, but I'm not shure if ESX acknowledged the Qlogic NAC as an adapter of storage or only as a network adapter.

    I have attached a few screenshots. I'll be very grateful if someone can help me.

    Thanks in advance

    Lenin

    I have not followed or used VMware install notes, only readme

    Notes on the driver download page Qlogic ESX and. I have

    only ever loaded the latest drivers to ESX 4.0 U1 or U2, both worked well

    http://driverdownloads.QLogic.com/QLogicDriverDownloads_UI/SearchByProduct.aspx?ProductCategory=322&product=1102&OS=167

  • Cisco NAC server and check active number? Would this work?

    Hi all

    A client has achieved a question when we introduced Cisco NAC today.  They wondered, lets say, a client of Cisco NAC agent installed may be connected to the network switch. It has all valid requests and patch levels on his machine (posture validation check pass)

    However, even if the customer takes the position of all the parameters, they want to know that if the host name of the client (for most Windows laptops) does not exist in their active database (this database is a database of estate number which is in a similar format or .csv) posture validation must fail.

    Have you met such request like this before? Is there a function on the NAC server which checks a field against an external database as an active database?

    See you soon.

    Dumlu,

    Currently, it is not possible. You can create controls who can check values locally, but not against external data warehouses, so for this card against your thinking, NAC would have to know all the names of workstation before hand and then check against that. It is unwieldy and very very difficult to scale.

    If it's something you and your client think would be a good addition (and it sounds like a good idea) Please engage with your account team and ask them to request a feature for you.

    Thank you

    Faisal

  • Agent of the NAC this SSL error

    Running

    CAM: 4.5.0 lite

    Current Windows clean access Agent Version: 4.5.0.0

    Current Windows clean access Agent Patch Version: 4.5.0.0

    Agent Macintosh's own access current version: 4.5.0.0

    Course Cisco NAC Web Agent Version: 4.5.0

    (Clean access windows agent installed on the host (Vista Business) is version 4.5.1.0)

    CAS mode: L2 virtual OOB GW

    The installation program is in conditions of laboratory for a proof of concept.

    The following scenario occurs each time a new authentication is attempted from a vista host running the agent access.

    -------------

    I plug the host on the controlled NAC switch port

    I get an ip address although my pool of vlan and dhcp auth

    Agent of Cisco clean access is displayed on the screen according to the normal

    I enter my user and pass and click login

    I get a "security alert" pop up indicating "the revocation information of the certificate for this site is not available. Do you want to continue? »

    There are 3 buttons to choose: Yes, no, display certificates

    I click Yes, but the error message does not disappear,... no matter how many times you click on Yes,... the error remains on the screen, keep you from making the connection.

    If I click on no.

    The clean access agent then says "network error!, detail: Certificate SSL REV failed [12057]."

    My only option is to click on the "Close" button so I don't

    This closes the agent clean access, but the agent instantly appears buck on my screen asking again user them and pass.

    I enter the right user and pass and click login

    I receive a new security alert pop up stating "this page requires a secure connection which includes server authentication." "The issuer of certificate for this site is unknown or unreliable, making you go?

    My click Options, Yes, no, view the certificate or more information

    I click on Yes, the security alert disappears and own access now States that I managed to connect to the network.

    It refreshes my IP address and puts me in the vlan correct based on the role of my user name.

    -------------

    I checked the event logs, all my access attempts are accepted, (on the 2nd try of course), but there is no errors in the cam on this SSL problem.

    However, I get a warning red text on the summary page of the cam, which stipulates the following, which I do not know if it has any impact on my problem.

    "WARNING: the end-entity certificate issued by"www.perfigo.com"is suitable for laboratory environments only." You must import a certificate of third party entity end for your own Access Manager and own access servers before the Cisco NAC Appliance deployment in a production environment. Please check your own access servers and ensures Clean Access Manager for similar messages.

    WARNING: The current "www.perfigo.com" trusted certification authority is suitable for laboratory environments only. Cisco recommends to import a third-party certification authority. Please check your own access servers and ensures Clean Access Manager for similar messages. »

    My questions are,

    -Why used the CAA accepts the first authentication attempt?

    -How can I remove the first security alert?

    -How can I set the CCA so that I login just once without having to click on no and wait for CAA to appear a 2nd time?

    Thank you all

    The fundamental problem is that the customer is unable to check the root certificate for your CASE.

    I guess that since you have always the perfigo warning that you have not installed a certificate valid on the job. If you did, you must remove the certificate of perfigo. If you install a valid certificate, you must remove the Perfigo cert.

    Once you have a valid cert installed, make sure that the client can access the certificate server root of the AUTH VLAN. That should get rid of these two messages.

    If you cannot provide access to the certificate server, then you cannot get rid of the second message, but you can get rid of the first message (the one that sticks you in a loop).

    This message (the first one) is due because the check certificate revocation in Internet Explorer has been enabled. This option has been disabled by default in XP, but is enabled by default in Vista. The option is disabled in Internet Options > Advanced tab > check the CRL.

Maybe you are looking for