NAC L2 OOB VG Design for wired

Hi all

I need help of the NAC 2 OOB virtual layer for wired users design bridge . On Cisco documentation configuration only example is present, but it is for wireless users who is not applicable to my case (wired users); Here are the details; Please correct me if the design does not at any time;

1: create a virtual local network (241) for the management of the CAM on the kernel.

2: create a virtual local area network (240) for the management of CASES on the kernel.

3: the IP addresses of both (10.10.240.1) E0 and E1 (10.10.240.1) for the CASE will be on the same subnet and same ip address.

4: create all Trusted SVI's VLAN (vlan 10,20) on the kernel.

5: configure manage subnets for vlan not reliable (100, 200) on CASES

6: create a vlan mapping n/b approved and not approved (10 to 100, from 20 to 200)

7: core connected to the CAs: E0, trunk allowed vlan 10, 20, 240

8: core connected to the CAs: E1, trunk allowed vlan 100, 200

9: another typical configuration

I don't have a LABORATORY to test. I'm just confused if I missed something as implementation will be critical, and I'll try to avoid all risks.

Please give me suggestion and best practices. Also please let me know if I need a config added?

Kind regards

Abdul Majid Khan

Abdul,

Port profiles are used to determine if a port is managed or not managed, so you will need at least a port profile. Here you can define what will be the VLAN initial of the switchports that the final VLAN will be etc etc.

More details here: http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/48/cam/m_oob.html#wp1083087

HTH

Faisal

Tags: Cisco Security

Similar Questions

  • NAC L2 OOB VG issue with wired user

    Hi all

    Need your favour, I tried to do L2 OOB virtual door of entrance to the NAC for wired user with the following text:

    The two interfaces of certification authorities are trunk with only the VLANS respective authorized.

    CASE is added to the CAM.

    Switch is added to the CAs.

    Mapping VLAN is configured as 50 (untrusted) was located in 60 (trusted)

    Port profile is configured.

    The CASE switch port is configured with the profile of this port

    QUESTIONS:

    When I connect my client to Auth vlan 50 so should I give the static IP address to my NIC or he should get the IP address of the DHCP server (for VLANs both auth and access)

    First of all, I gave auth static vlan 50 but normally connected port and doesn't show any web page of NAC.

    Next, I set up DHCP for access vlan 60 and put the client port in vlan auth 50, but still don't ask me page of posture of the NAC.

    When I check discovered the clients then it shows my MAC laptop.

    Am I still missing something?

    Kind regards

    The captive portal of the NAC is able to provide 3 options: use Cisco NAC webagent, download Agent access clean and restricted access.

    "Agent access own download" allows the user to download the agent, without using the webagent first. The user is only required to open a session.

    The button "Download Cean access Agent", is available for all the roles that are required to use the clean access agent. This is configurable to: device management > access > General Setup > Agent Login.

    For more information, see the Installation and Configuration Guide (chapter 10)

  • Is it possible to use an application designed for iPhone/iPad on my iMac or (older) instead of the iPod touch?

    Sorry, I don't have an iPhone and I'm not a user app.  But I found one that I really want to get.  The description says that it is designed for an iPhone or an iPad.  Can I download it on my iMac and use iTunes to put on my older iPod touch?  Or just use it on my iMac?  Here is the app in question.  Thank you!

    iTunes does not sell at apps for your computer.  All applications are for iPhone/ipad/ipod.

    You will need to check the requirements for the application know what version of iOS is required if you want to use on your iPod.

  • Sa20-S103 can't install software designed for Windows XP

    Because I installed a service pack II - I had a problem with the installation of some software on my SA20.
    Even with software designed for Windows XP. We have several PC's desktop and my SA20 is a laptop. All PCs have the same XP version with the same updates.

    So in my widows case gives the following warning:
    C:\WINDOWS\SYSTEM32\CONFIG. NT. This file system is not appropriate to run MS-DOS or Microsoft Windows applications. Select a button 'Close' to terminate the application activity.

    Microsoft told me: Sorry, it's a problem with Toshiba Windows XP under System. They explained that in this case service pack II can work not properly in contact with the XP system redesigned for Toshiba. Who can help me?

    Rafal

    Hello

    Check this link http://support.microsoft.com/?kbid=324767 please. I hope that there is the solution for you.

  • choice of the model of design for data acquisition system

    Hi all

    I have a problem on the selection of the model design / architecture for a data acquisition system.

    Here are the details of the desired system:

    There are data acquisition hardware and I need to use by looking at the settings on the user interface.

    the period of data acquisition, channel list to analyze must be selected on the user interface. In addition, there are many interactions with the user interface. for example if the user selects a channel to add scanlist, I need to activate and make it visible to others on the user interface.

    When the user completes the channel selection, then he will press the button to start the data acquisition. Then, I also need to show the values scanned on a graph in real time and save them in a txt file.

    I know that I can not use producer consumer model here. because the data acquisition loop should wait for the settings to scan channels. and it works on a given period by the user. If the loop of user interface makes higher then loop (loop data acquisition) of consumption. This means that queue will be bigger, larger. If I use notifier this will be some data loss comes from the user interface.

    y at - it an idea about it? is there any model of design suitable for this case?

    Thanks in advance

    Best regards

    Veli BAYAR

    Software for embedded systems and hardware engineer

    Veli,

    I recommend the model producer/consumer with some modifications.

    You might need three loops.  I can't tell for sure from your brief description.

    The loop of the User Interface responds to the user for configuration entries and start/stop of acquisition.  The parameters and commands are passed to the Data Acquisition loop via a queue. In this loop is a machine States that slowed, Configuration, Acquisition and stop States (and perhaps others). The data is sent to the processing loop through another line. The processing loop performs any data processing, displays the data from the user, and records to file. A registrant can be used to send the Stop command or stop the loop of the UI for other loops.  If the amount of treatment is minimal and the time of writing files are not too long, the functions of processing loop might be able to happen in the case of the UI loop timeout structure of the event.  This makes things a little easier, but is not as flexible when changes need to be made.

    I'm not sure that there is a type of design for this exact configuration, but it is essentially a combination of the models Design of producer/consumer (data) and producer/consumer (events).

    Lynn

  • Laptop computer (NEC) designed for windows XP problem.

    My aunt give me a phone NEC which is purchased from the Japan. It is designed for windows XP, now the problem is that my laptop does not work so what I did, I installed the windows 7 starter edition, it installed successfully but I can't put any hardware such as printers, Cam, USB, mouse, high connection throughput or even my helmet. I don't know what's going on, or maybe my laptop is really designed for windows XP. I need help, what I really need to re install Windows XP? or there is a way to solve this problem. Thank you

    Go to your computer manufacturer's support web site and search for Windows 7 drivers for your specific model number.

    If there are Windows 7 drivers, then to download to a folder on your hard drive and install all of them, starting with the card drivers mother/chipset, LAN, Audio, USB, SATA, etc, and so on.

    List of computer manufacturer support sites:
    http://Windows.Microsoft.com/en-us/Windows/help/contact-support/computer-manufacturers

    If you have an Intel motherboard, you can try the Intel driver update utility: http://www.intel.com/support/detect.htm?iid=dc_iduu

    Tips for solving common driver problems
    http://Windows.Microsoft.com/en-us/Windows7/tips-for-fixing-common-driver-problems
    Vista: http://windows.microsoft.com/en-US/windows-vista/Tips-for-fixing-common-driver-problems

    J W Stuart: http://www.pagestart.com

  • Running a program designed for x 32 bit machine Windows XP x 64

    Hello

    I try to run a program designed for Windows 32-bit on a 64 bit machine x x. I installed the program and moved the directories in the directory Program Files (x 64) in the regular Program Files directory - it's where shortcuts have been pointing.

    When I run the program I get an error message "" an unhandled win32 exception occurred in "PROGRAM NAME" ". Is there a way I can run this program on this machine?

    Good reading this forum:

    http://www.SevenForums.com/virtualization/11173-Windows-XP-32-bit-Windows-7-64-bit-OS.html

    If it takes you get launched, you can probably get a 32-bit virtual machine running.

  • System Restore error: file spp.dll is not designed for windows or there is an error.

    Original title: download spp.dll

    My SPP.dll file is 0 kb.  When I try to access the system restore, it indicates that the file spp.dll is not designed for windows or there is an error.

    How can I get another spp.dll file? I can download one from the internet.  I tried but just keep getting a service offering public fixit. I bought RegUtility, but it did not fix the file.

    Try to run the System File Checker:

    http://support.Microsoft.com/kb/929833/en-us

  • WMCE54AG - dialog box 'Site not designed for Media Center'

    I just bought WMCE54AG media extender on ebay and it connected to my PC Windows XP Media Center.  It seems to work fine except that I can't access Online Spotlight.  I get a dialog box saying "Not designed for Media Center Site" and asks me to view them later / now display / Cancel.  I select view now and get the Online Spotlight menu options, but can't do anything with it.  This feature works fine on my PC.  Is there some setting I have missed on the Extender?  I tried to update the firmware, but when I have intalled, it says I have a newer version, so I cancelled it.  Any help would be greatly appreciated.

    Well, after trial and error, I finally understood what the problem
    a. the Linksys Extender is not compatible with IE7. After rolling back to
    IE6, I could see online focus in the media extender. As a note of
    careful, I had upgraded to IE8 beta 2 and Spot online has stopped working on
    my media center PC as well. I had the same error as I did on my extender. This
    in the end is how I realized that the problem was with the IE version.

  • How to run programs designed for Windows 3.1

    How can I get vista to rum a program designed for windows 3.1

    How can I get vista to rum a program designed for windows 3.1

    I found 2 sources of information for your question:

    1. it is a tutorial from eHow:
    How to run Windows 3.1 on Vista
    http://www.ehow.com/how_6915732_run-Windows-3_1-Vista.html

    2. it is a response dated October 6, 2010, this MS Answers forum.
    http://social.answers.Microsoft.com/forums/en-us/vistafiles/thread/caa2cea4-9088-42f7-BDA4-1da12cc667ec

    I have no technical knowledge of the object. Simply provide references.
    If you have any other questions, you will have to wait for the experts. For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • Create a disc of the Encyclopedia Britannica, which is designed for up to Windows XP with Vista work. Is this possible?

    Create a disc of the Encyclopedia Britannica, which is designed for up to Windows XP with Vista work. Is this possible?

    Hi Silas Martin,

    I have not used Britannica for many years now, but I suppose there is a program of "installation"? If so, try compatibility mode.

    1 / locate the setup.exe (or install file) for the program of Britannica

    2 / right click on the file setup.exe or install.exe, and in the drop-down menu, select Properties.

    3 / in the Properties window, click the Compatibility tab

    4 / on the Compatibility tab place a 'TICK' in the box beside the box "run this program in compatibility mode for", then select the operating system Windows XP (Service Pack 3). This should automatically appear in the box under the run this program in compatibility mode for option. If Windows XP is not visible, then click on the arrow down to see a selection of the available operating system options.

    5 / click OK

    6 / the installation program will now begin to install the program in compatibility mode for Windows XP

    7 / once done, you should be able to run the program as if you were using Windows XP

    This forum post is my own opinion and does not necessarily reflect the opinion or the opinion of Microsoft, its employees or other MVPS.

    John Barnett MVP: Windows XP Expert associated with: Windows Desktop Experience: Web:http://www.winuser.co.uk;  Web: http://xphelpandsupport.mvps.org;  Web: http://vistasupport.mvps.org;  Web: http://www.silversurfer-guide.com

  • WIN 64: The application is valid but was designed for a different system (32-bit).

    I have an application written in Toolbook 4.0 (WIN 95 to 1996). It works fine in XP 32-bit. When I try to run in XP 64, I get the error message "the application is valid but was designed for a different system" is at - it an emulator or a way to make a 64-bit computer to run 32-bit code? I know that this application is old but it works fine in XP 32 and I can't replace it witout totally re - develop from scratch.

    There are several options depending on your operating system.

    For XP/Vista: You can use Microsoft Virtual PC 2007 and run Windows XP x 32 inside your x 64 system.

    http://www.Microsoft.com/downloads/details.aspx?FamilyId=04d26402-3199-48A3-afa2-2dc0b40a73b6&displaylang=en

    For Windows 7 (Pro and Ultimate only): you can use Windows Virtual PC, which comes with a copy of Windows XP on the inside to run legacy applications.

    http://www.Microsoft.com/Windows/Virtual-PC/default.aspx

  • Compatibility of software designed for windows 95 with Windows 7

    Dear team,

    Plan course multimedia order to learn the flute (link: http://www.one-world-trading.com/bansuri_guru.shtml). According to the interaction that I had with the seller, this course and the software was designed for windows 95 and it may or may not work on windows 7, which is currently installed on my system. As this course is now out of new creation/editing/printing, I can't it anywhere except from the link above.

    Please let me know what is the possibility of this software running on Windows 7 or higher version and if I can order this.

    Your advice would be really helpful.

    Kind regards

    Elisha SP

    E-mail address is removed from the privacy *.

    E-mail address is removed from the privacy *.

    India

    It could work according to the architecture of Windows 7 installed. If you have Windows 7 64 bit installed, it may not work because the software could have 16-bit code not supported by 64 bit versions of Windows.

    To determine if you have Windows 7 64-bit:

    Click Start, right computer

    Click on properties

    Go to the section Type System

  • 64-bit windows 7, I was able to install my programs probably 3 20 I used before, why is this? Ive tried the 64-bit versions designed for windows 7 and I tried compatibility modes.

    I don't really have much to say... ive got 64 bit and ive tried almost everything I can. Some examples of what I can't install that are designed to work for it: itunes, logitech g19 keyboard drivers, Alex Feinmans iso recorder. also one of my cd drives doesn't let me do anything, like install stiff from a disc or copy a cd, if theres encryption at all. my other cd drive not... Skype does not, or ventrillo. Steam and all games run so far, and crysis works but its editing tools only and designed for 64-bit only. I don't like windows 7 and I do not think that its faster, but what's the point of speed if I can't run anything?

    Drivers are specific, because 64-bit drivers are needed for 64-bit and X 86 (32-bit) systems drivers for this type of system.  X 86 applications run well on 64-bit if it does not involve drivers and software. You seem rather unlucky or unhappy.  What could have been encrypted by another user on another machine will most likely depending on what type of encryption, you talk about the problems.

    Often the trick to get installed programs is to right click on the configuration file and select the "Run as Administrator" option.  Another often overlooked trick is to disable temporarily the scanner in time real and other similar programs during installation.

    32-bit and 64-bit Windows: frequently asked questions
    http://windowshelp.Microsoft.com/Windows/en-us/help/41531554-d5ef-4f2c-8fb9-149bdc5c8a701033.mspx

    How to troubleshoot a program that does not run as expected once it is installed on Windows Vista
    http://support.Microsoft.com/kb/931362/en-us

    Make older programs in this version of Windows
    http://windowshelp.Microsoft.com/Windows/en-us/help/bf416877-c83f-4476-a3da-8ec98dcf5f101033.mspx

    Windows Vista Compatibility Center
    http://www.Microsoft.com/Windows/compatibility/details.aspx

    Windows 7 Compatibility Center
    http://www.Microsoft.com/Windows/compatibility/Windows-7/en-us/default.aspx

    Windows 7 Upgrade Advisor
    http://www.Microsoft.com/downloads/details.aspx?FamilyId=1b544e90-7659-4BD9-9e51-2497c146af15&displaylang=en

    Virtual PC 2007
    http://www.Microsoft.com/downloads/details.aspx?FamilyId=04d26402-3199-48A3-afa2-2dc0b40a73b6&displaylang=en&TM

    Windows Virtual PC
    Download Windows XP Mode
    http://www.Microsoft.com/Windows/Virtual-PC/Download.aspx

    Windows XP Mode (Windows 7 only, but not one of the Home versions) "you are not eligible to download Windows XP Mode. You must have Windows 7 Professional, enterprise or full to run Windows XP Mode."

  • Additional applications of blackBerry Smartphones No. designed for your device found

    Hello

    I get the, msg "no additional applications designed for your device not found" when trying to install new software via my Desktop Manager. I read a thread that says I have to install BlackBerry software for the current device.   It seemed to work for the individual with the question.

    The post office is: http://supportforums.blackberry.com/rim/board/message?board.id=BlackBerryDesktopSoftware&message.id=...

    Well, I would like to download the software for mine, but my carrier/provider don't showup on the BlackBerry site.  My carrier is AlaskaDigitel.  Is there some generic download that I could use?  My Office Manager can show what software is installed on my device, like Google Maps, etc.. He simply refuses to install the software. The things I installed were facilities OTA.

    Here is a little info that can help you to understand what I see:

    I have a BB 8130 Pearl
    v4.3.0.127 (Platform 3.1.0.73)

    I think that there is something wrong & I just don't recognize the simple fix for it. Could someone help me?.
    I opened the Desktop Manager, click on the Office Manager & watch the
    Tab 'general '.
    BB Desktop manager: 4.3.0.15

    "Components" tab
    BBDevice Manager: 4.3.0.7
    BBDevMgr: 4.0.0.1
    RIM USB driver: 4.0.0.2
    RIM USB Serial Driver: 2.1.0.4
    Application loader: 4.3.0.13
    RIMProgram: 1.0.1.35

    There is nothing in the tab "Device Software"<=Is this="" the="">

    Everything "Looks" right to me, but I am very, very new to this.
    Thank you
    ~ Roystreet

    Yes, that's the problem.  You need the OS installed on the computer (so it will show in the tab of the device software) in order to get rid of this error.  You can use any OS for your device model, regardless of the carrier.

    Use the link below to find a carrier CDMA which offers the 8130 and has a download for 4.3.0.127.  Download it, install it on your computer.  Then go into c:\program files Research in motion\apploader and delete the file named "vendor.xml."  This file prevents the installation of your device carrier operating systems.  Deleting the file will allow DM recognize as valid for your device.  It does nothing else, so it is safe to delete.  Once you have deleted the vendor.xml file reconnect the device to the PC and launch the Desktop Manager/Application Loader.  You should be good to go.

    http://www.BlackBerryFAQ.com/index.php/BlackBerry_Operating_System_Downloads

Maybe you are looking for