NAC 4.8 adding to the case because of the cam

Hi all

I threw a half because of the NAC installation and this is my first deployment of the NAC, I feel a little overwhelmed.

I read the installation guide for the devices from the back to the front, but I have a problem after the addition of a case to the cam.

I am able to add the case to the cam successfully, but almost immediately, the case and the cam can no longer ping between them in the cli.

the States of event logs that the heap in connected to the cam, but newspapers then an error that the cam is unable to push the registration to the CAs. from this point, I get several questions of event log indicating that the case is out of sync

I copied a part of the nac_manager.log which show the connection process:

2012-03-09 22:33:06.037 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartServer - SSS - connect: get the new connectorClient of 10.0.0.100

2012-03-09 22:33:36.433 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartManager - SSM - addSecureSmartServer: sleep for 2 seconds to click to restart

2012-03-09 22:33:38.434 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartManager - SSM - addSecureSmartServer: sleep for 2 seconds to click to restart

2012-03-09 22:33:40.436 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartManager - SSM - addSecureSmartServer: sleep for 2 seconds to click to restart

2012-03-09 22:33:42.438 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartManager - SSM - addSecureSmartServer: click on the STOPPED state

2012-03-09 22:33:42.617 + 1100 WARN [TP-Processor24] com.perfigo.wlan.web.admin.SecureSmartPublisher - NAC Server 10.0.0.100 is out-of-sync.

2012-03-09 22:33:42.702 + 1100 [TP-Processor24] ERROR com.perfigo.wlan.web.admin.FilePublisher - FilePublisher - writing: setPath failed...

2012-03-09 22:33:42.793 + 1100 [TP-Processor24] ERROR com.perfigo.wlan.web.admin.FilePublisher - FilePublisher - writing: setPath failed...

2012-03-09 22:33:42.833 + 1100 [TP-Processor24] ERROR com.perfigo.wlan.web.admin.SecureSmartPublisher - SSM publishAccess: impossible to publish the comments sign-up page

2012-03-09 22:33:42.872 + 1100 [TP-Processor24] com.perfigo.wlan.jmx.admin.FileUtil - FileUtil - readFile INFO: /perfigo/control/conf/os-detection.fp

2012-03-09 22:33:42.887 + 1100 [TP-Processor24] ERROR com.perfigo.wlan.web.admin.AccessConf - cannot activate ETH1 on 10.0.0.100

2012-03-09 22:33:42.888 + 1100 [TP-Processor24] ERROR c.perfigo.wlan.web.admin.AdminIpAccessInfoManager - AIAIM - publishAccess: failure

2012-03-09 22:33:42.888 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.ServerConf - SC - stopOobSWissServer()

2012-03-09 22:33:42.905 + 1100 [TP-Processor24] INFO com.perfigo.wlan.web.admin.SecureSmartManager - 10.0.0.100 added to Clean Access Manager

2012-03-09 22:33:46.922 + 1100 [pool-1-thread-1] ERROR com.perfigo.wlan.web.admin.ConnectorClient - Exception of Communication: can't connect with the exception of server access own creation connection to: 10.0.0.100. nested exception is:

java.net.SocketTimeoutException: connect timed out

2012-03-09 22:33:46.922 + com.perfigo.wlan.web.admin.SecureSmartPublisher - SSP - connectAndPublish 1100 [pool-1-thread-1] ERROR: could not connect to 10.0.0.100

2012-03-09 22:34:01.614 + 1100 [pool-1-wire-2] ERROR com.perfigo.wlan.web.admin.ConnectorClient - Exception of Communication: can't connect with the exception of server access own creation connection to: 10.0.0.100. nested exception is:

java.net.SocketTimeoutException: connect timed out

2012-03-09 22:34:01.615 + com.perfigo.wlan.web.admin.SecureSmartPublisher - SSP - connectAndPublish 1100 [pool-1-wire-2] ERROR: could not connect to 10.0.0.100

2012 03-09 22:34:01.627 + 1100 [pool-1-wire-2] WARN com.perfigo.wlan.web.admin.SecureSmartPublisher - NAC Server 10.0.0.100 is out-of-sync.

2012-03-09 22:34:05.628 + 1100 [TP-Processor19] com.perfigo.wlan.web.admin.ConnectorClient - Exception of Communication ERROR: could not connect with the exception of server access own creation connection to: 10.0.0.100. nested exception is:

java.net.SocketTimeoutException: connect timed out

2012-03-09 22:34:20.618 + 1100 [pool-1-wire-3] ERROR com.perfigo.wlan.web.admin.ConnectorClient - Exception of Communication: can't connect with the exception of server access own creation connection to: 10.0.0.100. nested exception is:

java.net.SocketTimeoutException: connect timed out

I've followed all of the installation guides recommendation of the disconnection of the interface untrust on the CASE and there is no HA configuration currently...

What I don't understand is the inability of webcams and cases of ping each other, but they can ping other devices on the network. The SCA and the cam are in different VLANS.

Any assistant to a guru of the NAC would be greatly appreciated.

Thank you

JS

Thanks a lot Man, saved you my day

Tags: Cisco Security

Similar Questions

  • Adding an additional CASE to an existing deployment of NAC OOB 4.7.3

    Hi guys,.

    If I am to add the certificate self-produced my new cases to the authorities of my CAM list existing certificate approved, it just will be added or it will replace the existing trusted certificate?

    Hi Adrien,.

    "Certification authorities" are the certificate of all the CAs root and also self signed certs of the trusts of the CAM case. So whenever you add a root/selfsigned certificate to this list, it is added to the list and does not replace any of the CERT. This link gives more information:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/45/CAs/s_admin.html#wp1092761

    Kind regards

    SOM

    PS: Please mark the same question if it has been answered. Note the useful messages. Thank you

  • BUG: Ops added to the stack of cancellation/reinstatement twice

    Hey, TLF team...

    I see a bug with what is added to the undo stack to combine the composite operation start/end with operations that are performed in the event handlers of start/end flow op for the duration of the op calls composite begin/end.  I filed some bugs through system of Flex SDK bugs earlier and they do not seem to channel through you right now, so I thought I would post it here.  This isn't quite a Blocker for us right now, but we would really like to see this one fixed for immediate if possible release.

    Steps to reproduce:

    1. call the EditManager.beginCompositeOperation ().

    2. call the EditManager.doOperation (OpA).

    3. call the EditManager.doOperation (OpB).

    4 handle FlowOperationEvent.FLOW_OPERATION_BEGIN event for OpB and the event handler called EditManager.doOperation (OpB_PreOp).

    5... usability OpB to do its thing.

    6 handle FlowOperationEvent.FLOW_OPERATION_END event for OpB and the event handler called EditManager.doOperation (OpB_PostOp).

    7. call EditManager.doOperation (OpC).

    8. call the EditManager.endCompositeOperation ().

    Result:

    Observe the CompositeOperation (the stack operations it contained) which is added to the undo stack.  It will contain something similar to this:

    1. CompositeOperation (composite global op created as a result of composite operation of start/end calls)
      1. OpA
      2. OpB_PreOp
      3. OpB_PostOp
      4. CompositeOperation (created as a result of the calls of doOp for managers of start/end of FlowOp)
        1. OpB_PreOp (same obj ref element "b" above)
        2. OpB
        3. OpB_PostOp (same obj ref element 'c' above)
      5. OpC

    As you can see, when we do operations for managers flow of start/end of op AND we are already in a composite operation context, the OPS is for managers of start/end added to the stack of cancellation/reinstatement in two places.

    In addition, we compile with "CONFIG::debug = true' during development, and in this case get the assertion error 'a non-contiguous composite operation operation add' during the finalizeDo for OpB_PostOp for parentOperation.addOperation (op) call."  The reason of the assertion error is that when we call parentOperation.addOperation (OpB_PostOp), ops parentOperation table contains only OpB_PreOp, which endGeneration does not correspond with the beginGeneration of OpB_PostOp due to changes in the model performed during execution of OpB.

    Expected result:

    OpB_PreOp and OpB_PostOp must be added to the stack of cancellation/reinstatement in one place.  Since we are already in a composite operation in this case, perhaps the composite wrapper created for OpB/OpB_PreOp/OpB_PostOp is not necessary, and OpB could be added to the appropriate location in the stack of PAHO.  Otherwise, preventing the pre/post OPS to have added to the composite op external looks he would set also.

    Note:

    In cases where we do an operation as a result of flow op start event, if another event manager call preventDefault(), we would prefer that our "pre-op" you not executed either--or he would get immediately cancelled when the edition Manager realizes that the original op could not.  Basically, we get this behavior by default with post ops, as end of stream op event never fires in this case.  Our solution for now is to use headphones to lower priority for managers who make pre ops we can check for defaultPrevented ourselves until we actually do the pre op.  We also saw some problems with the stack of cancellation/reinstatement broke up because of the generation numbers gaps in some cases where we do pre ops and then prevent by default on the original op, but we haven't really gotten to the bottom of these questions yet.  I realize is that everyone will want "pre" avoided ops if the original op is avoided.  We can still have specific cases where this is true.  I have no good ideas right now about how something like that could be treated, but I just wanted to throw out there.

    Thank you

    Brent

    We will study it in - I see that these problems could make life difficult.

  • Problems with duplicate DATA when the data file was added after the backup completes

    Hello

    I am facing a problem when running of duplicate database with the command of database duplicate RMAN on a 10 g database. If I have the duplication from a full backup that is missing a data file that has been added to the database after the full backup of preforms, I get the following error message:
    Starting restore at 10-10-2009 18:00:38
    
    released channel: t1
    released channel: t2
    RMAN-00571: ===========================================================
    RMAN-00569: =============== ERROR MESSAGE STACK FOLLOWS ===============
    RMAN-00571: ===========================================================
    RMAN-03002: failure of Duplicate Db command at 10/10/2009 18:00:39
    RMAN-03015: error occurred in stored script Memory Script
    RMAN-06026: some targets not found - aborting restore
    RMAN-06100: no channel to restore a backup or copy of datafile 43
    Redo log which was Pond at the time of the creation of 43 of the data file is also available in the backups. It seems that RMAN cannot use the log information archived redo to restore the content of the data file 43. I guess that because failure is already reported in the RESTORATION and not in the RECOVERY phase, so again the archived logs are not available yet. I get the same message even if I do another backup of the data file 43 (so a backup that is not in the same backupset as the backup to all the other data files).
    The script, the command duplicate product, I guess that RMAN reads the contents of the source database controlfile and trying to get a backup that contains all the data files to restore the database Assistant - if such a backup is not found, it fails.


    Of course, if I try to perform a restore/recovery of the source database, it works without problem:
    RMAN> restore database;
    
    Starting restore at 13.10.09
    using target database control file instead of recovery catalog
    allocated channel: ORA_DISK_1
    channel ORA_DISK_1: sid=156 devtype=DISK
    
    creating datafile fno=43 name=F:\ORA10\ORADATA\SOVDEV\SOMEDATAFILE01.DBF
    channel ORA_DISK_1: starting datafile backupset restore
    channel ORA_DISK_1: specifying datafile(s) to restore from backup set
    restoring datafile 00001 to F:\ORA10\ORADATA\SOVDEV\SYSTEM01.DBF
    .....
    The 43 data file is re-created and then redo is applied to the course.

    So, does anyone know if the duplicate database can use archived redo logs to recreate the contents of a data file, as does a normal restore/recovery? If this is the case, then it is necessary to perform a full backup before each duplicated if a data file has been added after such a backup database.

    Thanks in advance for any answers.

    Kind regards
    Swear

    Hi swear,.

    I got exactly the same problem during replication.
    Because we backup archive logs every 6 hours with rman, I added an additional block of running this script.
    run
    {
    backup incremental level 0
    format "% d_ % s_ %%t p_ bk_ '.
    filesperset 4
    database not saved;
    }

    (I also hit a bug in the catalogue which was resolved by patching up the dbs catalog 11.1.0.6, 11.1.0.7 for.)

    This will restrict the data not making file not part of any backup rman 6 hours while jumping for which there is already a backup of data files.

    Kind regards

    Tycho

  • functions of YouTube works do not (such as adding to the playlist comment)

    Hello.
    functions of YouTube works do not (such as adding to the playlist comment) has stopped working, they are still working for the same account on chrome or another browser. (when it happened I didn't update or downgrade programs, addons, plugins that run in firefox or chrome, I don't see why all of a sudden).
    so I can't like videos, I get the message 'feature not available try later', can't add videos to the playlist (whole playlist including fav, as: Watch more later playlist pre made by youtube) and can't comment, for these 2 functions, I get the message 'invalid request '.
    all this happen again and many times, they stop or I can't make it work with reboot, refresh, try again.
    I did a fresh install of firefox and all it's the addons, plugins, same installation fees of adobe and divx, vlc products (which have the plugins or addons in firefox)
    After installing I could like comment add to playlist, before the snap all the addons, but I could only play HTML5 in youtube, any video that had no HTML5 support required at adobe. (after that I installed adobe it worked until I restarted the browser).
    now it does not work yet. (to disable, uninstall all the addons, plugins does not affect the problem)

    Some issues may also occur because of ProxTube - at least, I realized that I was was instantly redirected to the first film in the playlist on youtube - having no chance to see the entire playlist. It works when I disabled ProxTube.

  • How to check if the menuitem application has already added to the application menu?

    Hi all

    I want to insert some menutime at the request of RIM, for example,

    I have create a new menuitem Application named customizedMenuitem and add it to the request Message RIM.

    Since then, each time when my application is started, it will add again.

    So I want to check if it has already been added, if so, ignore to add it. If this isn't the case, application adds one more time.

    I called removemenuitem before system.exit (0) when quiting my request, however, it doesn't seem to work.

    That's why I check menuitem before I add.

    Source code like this,

    Constructor()

    {

    Super();

    If (the _appMenuitem is not added to the RIM Application) {}

    create a new menuitem application

    ApplicationMenuItemRepostory.addMenuItem (int, applicationmenuitem)

    }

    }

    Any word would be much appreciated!

    Thanks in advance!

    The most common way to deal with this is to store a value in the store of Runtime.  Your application can save a value when it adds the ApplicationMenuItem, and then check to see if it is there when it is run a second time.

    The Runtime store is erased when the BlackBerry is reset, which would coincide with the ApplicationMenuItem being deleted.

  • NAC agent does not parameter of customization of the CAM download

    Hello

    I would use the option of additional NAC 4.8.0 Agnet.

    Based on the 'Clean Access Manager Configuration Guide' is the branding.tar.gz of neccesery containing the custom nac_logo.gif, the nac_login.xml, the nac_Srings_xx.xml (in our case here in Hungary: nac_Srings_HU.xml). The package updet the cam has been successful.

    However, Agents do not update themselves.

    Other related settings on cam:

    Option: "the current NAC Agent is a mandatory upgrade" is checked in.

    I tried to put the files customized to the customer appropriate on a machine mannualy folder. After the next startup of the Agent, the changes are busy.

    What could be the couse that customers don't refresh themeself automatically by the CAM/CAS.

    Thank you very much

    Csaba

    Hi Csaba,

    I confirm that the document is false, so that personalization information are only after a (re) installation of the Agent.

    Allow me to connect to a documentation bug to fix this...

    Thank you for this comment.

    Kind regards

    Federico

  • NAC v4.7.1 - cannot add CASE to CAM - SSL error

    I have a CAM and CAs who was photographed with the newly recreated v4.7.1 image.  On this, I am unable to add the CASE to the CAM.  So far, I've worked with TAC and they can't seem to understand the question either.

    A substance that has been done after the installation:

    -Installed CAM and LICENSES

    -Guarantees self-generated SSL certificate DN of the point to the IP address of the device (if the CAM that point to the IP of the CAM...)

    -Under the confidence of the Board, CAM and CASE lacked the Perfigo entry.  Imported Perfigo of different certification authorities CA entry he already had.

    [email protected] / * /, CN =www.perfigo.com, OU = product, O = "Perfigo, Inc.", L = San Francisco, ST = California, C = US

    -CAM and CASES point to a DNS server that has the entries advance DNS configuration and back to the cam and the CASE

    -Checked CAM can ping by IP and host name ca and the FULL domain name

    -Check that the time on the cams and CASES are synchronized and are OK

    -Verify that the secret password on CAM and CASE by looking at the file /root/.perfigo/secret (also /root/.perfigo/master) and ensuring the matching strings

    Newspapers of throwing what follows:

    Could not connect to 10.1.2.19

    SSLManager: certificate of the server failed to check the string CN = 10.1.2.19, OU = XXX, O = XXX, L = XXX, ST = XX, C = XX:No found secure certificate

    Any ideas?

    Hey,.

    Cisco NAC Appliance version 4.7 (0) no longer contains the "www.perfigo.com" CA in the. Image ISO or upgrade. Directors, requiring the "www.perfigo.com" CA in the network must manually import the CA of a local after installation or updated computer to upgrade to version 4.7 (0).

    In order to establish the secure communication channel initial between a cam and the CASE, you must import the root certificate of each device in the store of trust of the other device so that the CAM can trust the certificate CASE and vice versa.

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/Release_notes/47/47rn.html#wp826817

    Kind regards

    Parminder Sian

  • All my photos suddenly have the extension .cfog added to the end of the name, and I can't open them. That's happened?

    All my photos suddenly have the extension .cfog added to the end of the name, and I can't open them. That's happened?

    Hi David,

    It's because you have installed CloudFogger, which protects your files in enrcytpt them to ensure safety for DropBox or GoogleDrive. Probably, you have not installed the program, that's why it shows all files with the extension .cfog I you Explorer.
    Re-install the program and you connect to your account back on your files.
  • Country code of blackBerry Smartphones added to the address book

    Someone has experienced the problem that my daughter is with his BlackBerry that a + 1 is automatically added to the numbers in his address book and because it is not in America, the number can not connect.  How does she stop + 1 to be added.  Remove the number or who return in the address book makes no difference.

    Press the green phone dialing > Options > Smart Dialing.

    Remove the + 1 in this configuration screen. It should enter the country code and national number length for the country, she is in.

  • JSessionId token is added to the URL

    We use the adf security to ensure our product.

    Recently when scanning using Burp security vulnerabilities, there is an problem where JSessionId token is added to the URL.

    This happens only once if my browser has cookies. Here are the steps:

    1. open the new browser.

    2 hit root url of the product for example http://localhost:7001 / applicationName

    3. we use forms to adf based authentication redirects to the login page, which looks like:

    http://localhost:7001/ApplicationName/faces/login.jspx

    4. during step 3, he made a few (observed of the violinist) internal requests, see below:

    ResultURL
    302http://localhost:7001 / application1
    200http://localhost:7001 / application1.
    302http://localhost:7001 / application1 /; jsessionid = G3KhgjgY2jwUaiMeoohXhOfmB3LwMgyLVLWxu_ZbToLGlDNRQ6L6! 592651143? _afrLoop = 881430891901473 & _afrWindowMode = 0 & _afrWindowId = null
    302http://localhost:7001/Application1/adfAuthentication?_adf.authenticate=true & _afrLoop = 881431524035093
    200http://localhost:7001/Application1/faces/login.JSPX

    A few questions:

    1 Why is - what add us 'jsessionid' in the parameter request instead of send in the cookie (as all other applications)?

    2. is there a way we can force adf to send 'jsessionid' ALWAYS in cookie?

    Hello

    Have you added the name of cookie in weblogic.xml?  Please try to add and reproduce the problem. By default, WebLogic Server assigns the same name to cookie ( JSESSIONID ) for all Web applications.

    AnyNam cookie

    In this case, Weblogic Server will not use JSESSIONID and _WL_AUTHCOOKIE_JSESSIONID , but the name you mentioned in step above and _WL_AUTHCOOKIE_NameofCookie to serve the same purpose.

    Ref: http://docs.oracle.com/cd/E23943_01/web.1111/e13711/thin_client.htm#SCPRG139

    Thank you

    Amey

  • When I saw my site to load there is extra space added on the left hand side

    When I saw my site and load until there is an extra space is added on the left hand side and I don't know why or hot to fix it. I have attached two picture to show what I mean. Any help would be great.

    My workspace

    Screen Shot 2016-01-18 at 8.49.39 PM.png

    My overview

    Screen Shot 2016-01-18 at 8.49.58 PM.png

    This may be because of the frame of image outside the area of the page, any other content outside page page, any empty container etc.

    Thank you

    Sanjit

  • When multi-process will be added to the CC 2015

    Hello

    If someone knows when multi processing will be added to the CC 2015? We are about to downgrade to 2014 CC because the latest version is useless with heavy comps and large resolutions.

    Of course, we do not want to change an office full of machines and a farm in rendering if an update will be released soon.

    Any help is very appreciated.

    Gavin

    The entire architecture of EI is rewritten making multiple images rendering at the same time unnecessary. It has always been awkward and subject to problems and incompatibility anyway. Do not have the opportunity to come back, but expect performance to improve in the next version.

  • Modify the effect parameters when it is added via the advanced action

    Hello

    Is it possible to change a path of a fly when an effect is added via the advanced action?

    When an effect is added via right mouse click on > 'Effect apply', and then modifying a path is easy:

    edit a path1.png

    But when the same effect is added via advanced actions, so I can not understand how do...

    edit a path2.png
    What I wanted to achieve are a form this is the flight in/out on click. Sorting of a table of contents, but with instructions on how to complete the task. So far, I have:

    1. step 1 - nb shape. 1 is visible

    1.png
    2. step 2 - after clicking on "Hide" (on the screen above) 1st form flies out. Instead, I have form nb. 2 (this screen below)

    2.png

    3. When you click on 'Show' (on the screen above), form number 2 goes to hidden. On its place form 1 shoud appear, but it doesn't. I know they are there :) because when, for testing purposes, I stuck them on the left side of the screen, they were visible, but completely displaced.

    Here are two simple actions that I created:

    actions.png

    Any ideas?

    Pawel

    There is no video, it's a blog post. Sorry, seems I posted a wrong link: effects reset in Captivate 6 - Captivate blog

  • Photo not added to the quick Collection when you click marker

    Recently I have not been able to add photos to a quick collection, when you click on the marker. The marker provides information, but the photo does not appear in the quick collection. This problem occurred at the same time, I couldn't remove the photos in the quick collection that had been added. I had to remove these photos using the menu system. I've upgraded to the new version of Lightroom 5 yesterday thinking that would solve the problem. I still have the problem so I wonder if this is a setting that I missed. Quick collection markers button is enabled in the display options and the button and change when you click them... The thumbnail of the photo is not added to the quick collection.

    It seems that you no longer have the quick Collection, referred to as a collection of target. Is there a small symbol '+' next to the name of the collection? If this isn't the case, you have another collection in your designated collection list.

    To fix, right-click the name of the quick Collection and click the option "set as target Collection.

Maybe you are looking for