Problem of NAC OOB - move users between ports

Hello

I have a problem with an OOB deployment, I am currently working on: when I move an OOB client authenticated from one switch to another, he gets stuck in the auth VLAN. It seems NAC does not correctly detect the new port.

That's what I've done to reproduce the problem in detail:

(1) a computer is connected to the port switch ' a' market 'A' (A [a]). The port is automatically replaced by auth VLAN and authentication and posture assessment are carried out.

(2) the computer goes together, and the port is changed to the VLAN designated access. OOB user appears in the list of users online, and the computer is added to the list of discovered Clients (Wired). All the detailed information on the two pages are correct.

(3) the computer is offline. OOB user is removed from the list of online users, but the computer remains in the list of overdrawn customers.

(4) the computer is connected to the port 'b' switch 'B' (B [b]). It is automatically replaced by auth VLAN and evaluation of authentication and posture successfully passes once more. However, the information contained in the list of discovered customers are not being updated, and in addition, OOB user appears once more in the users online list-, but the specified location to port A [a]!

The end result is that the computer is stuck in the VLAN Auth and NAC Agent authentication dialogue keeps popping out.

I tried the reverse scenario (port B [b] to port A [a]) after clearing manually the user all customer information and the result was pretty much the same thing...

Thank you

Boris

Boris,

These commands allow the mac-move:

MAC-address-table notification mac-move

SNMP-Server enable traps mac-notice change move

HTH,

Faisal

Tags: Cisco Security

Similar Questions

  • How to move files between folders without having to turn off UAC (as admin)

    I am connected to my computer as an administrator (Windows Vista).  I take loads and loads of photos - when I edit that I need to move them between folders or subfolders.  If I have active user account control, the system tells me that I don't have permission to do so.   I had the same problem with Windows XP.  Please tell us how can I fix this.  I'm not invited to passwords.

    Hello

    Here are some easy ways to Take Ownership and Grant Full Admin Control

    Add 'Ownership' to the Menu Popup Explorer in Windows 7 or Vista
    http://www.howtogeek.com/HOWTO/Windows-Vista/add-take-ownership-to-Explorer-right-click-menu-in-Vista/

    How to add appropriate to the context Menu in Vista
    http://www.Vistax64.com/tutorials/112795-context-menu-take-ownership.html

    Take and Grant Full Control permissions and ownership in Windows 7 or Vista right click Menu
    http://www.mydigitallife.info/2009/05/21/take-and-grant-full-control-permissions-and-ownership-in-Windows-7-or-Vista-right-click-menu/

    --------------------------------------------------------------------------------------------

    How to take possession of an item in Vista
    http://www.Vistax64.com/tutorials/67717-take-ownership-file.html

    How to change the permissions on the folders
    http://www.Vistax64.com/tutorials/157304-folder-permissions.html

    ===================================================

    From a post by Rehman F.

    Here are the steps to change the ownership and permissions of files and folders:

    1. right click on the file or folder, click Properties, and then click the Security tab.

    2. click on advanced and then click the owner tab.

    3. click on edit and then do one of the following:

    ·    To change the owner to a user or group that is not listed, click other users and groups, and in the box type
    the object name to select (examples), type the name of the user or group, and then click OK.

    ·    To change the owner to a user or a group is listed in the change owner to box, click the new owner.

    4. If you want to take ownership of the contents of the folder, select the replace the owner of sub containers and objects check box.

    5. click OK and then click Yes when you receive the following message is displayed:

    You are not allowed to read the contents of directory folder name. You want to replace the directory
    permissions with permissions granting you full control?

    All permissions will be replaced if you click Yes.

    Note folder_name is the name of the folder you want to take charge.

    6. click on OK and then reapply the permissions and security settings that you want for the folder and its contents.

    Additional considerations

    7· An administrator can take ownership of any file on the computer.

    8· Affecting the ownership of a file or a folder might require that raise you your permissions using user access control

    I hope this helps.

    Rob - bicycle - Mark Twain said it is good.

  • Questions of FindMe Provisioning/user between TMS & VCS

    Hello

    I have what seems to be a problem in service between TMS and VCS.

    Using TMS to import users from AD (from 2 domains of x), everything seems to work, and can see the users in the provisioning of TMS directory. MOVI users use AD authentication which connect properly.

    User login also works very well on the VCS (with connection LDAP AD). However when to call the findme users address VCS does not recognize the configured users? If you navigate in user accounts, the user is not displayed, if you run a search on VCS (users account address name or findme) findme VCS find the user. Once the user has been found and open if you click on save button (without changing details), the user will then appear in the VCS user accounts section and findme works correctly.

    We use the TMS 13.1.1 and VCS x7.0.2 (Cluster).

    I would like to know if you have solved your problems or you are still having problems? Any suggestions for help would be appreciated.

    Thank you

    Matt

    Hi Matthew.

    Findme users must fill in the "user accounts".

    But you must make sure that the VCS 'Cluster name' matches the 'SIP server address' in TMS.

    TMS:

    VCS:

    I hope this helps.

    / Magnus

  • Move windows between multiple monitors

    Move windows between multiple monitors

    You can easily extend your Windows desktop across multiple monitors. A display that spans two monitors or more significantly increases your screen area so that you can drag windows and program icons anywhere on the desk of theextended.

    By default, when you connect another monitor, the image of your desktop appears on each monitor display. Before you can drag a window from one display to another, you must change your display setting toExtended. For more information, see Set up multiple monitors.

    I can't do it in my compuer whay?

    You can't do that if you are under Vista Home Basic.

    http://Windows.Microsoft.com/en-AU/Windows-Vista/troubleshoot-multiple-monitor-problems

    Solving the multiple monitor problems

    Here are solutions to some common problems with connecting, setting up and working with multiple monitors.

    http://Windows.Microsoft.com/en-AU/Windows-Vista/multiple-monitors-frequently-asked-questions

    See if the information above helps you.

    See you soon.

    Mick Murphy - Microsoft partner

  • How can I move user folders to another drive

    My C: drive is to fill to the top and my drive H: is almost empty.  I would like to move all my pictures and music on the H: drive.  I can do this in an eay way?

    http://www.vista4beginners.com/move-user-files-folders-to-another-partition

    "Move your files and user files to another partition.

    The tutorial above should help you solve the problem.

    See you soon.

    Mick Murphy - Microsoft partner

  • DVD burning problem: I burn the movie on widescreen PAL on a DVD-R disc. I managed it burned without menu. Now, I've added a "Pan and Zoom" menu with a main marker at 00:00:00:00, 21 scene markers, and a stop at 01:29:32:17 (th

    DVD burning problem: I burn the movie on widescreen PAL on a DVD-R disc. I managed it burned without menu. I have now added a "Pan and Zoom" menu with a main marker at 00:00:00:00, 21 scene markers and a cleat to 01:29:32:17 (the end of the film). The combustion is interrupted with a message to watch a C:\Users\ianle_000\Documents\20151206160446.iso file. There is no file. The message also provides a link for an explanation. This Web page is impossible to obtain. I'm running on a PC with Windows 8.1.

    Thank you once again. I burned the DVD!

    It is the first film for which I have reached the stage of burning. I'm not sure why she didn't in the first place. I tried to burn the "no menu" version, but at the time, was shot the DVD itself - I wonder when he reached this point?

    So, I burned the "no menu" version to another DVD, that worked, then the version of menu, with no cleat to a third DVD, which reads perfectly.

    Now that I have a successful routine, I'll stick to it.

    Thanks for all your help.

    I'll close this discussion now.

  • My USB to ethernet adapter works only if plugged into my MacBook Pro. I tried to use to start an expander USB (power strip), but this has not--a problem when you have only TWO USB ports ports! Any suggestions?

    My USB to ethernet adapter works only if plugged into my MacBook Pro.

    I tried to use to start an expander USB (power strip), but this has not--a problem when you have only TWO USB ports ports!

    Any suggestions?

    Juice what 'expander' did you use?

    What model of MacBook Pro?

    This is the Office Mac Pro forum. I asked that your post be moved to the MacBook Pro laptop forum.

  • How to move photos between albums of physically?

    IOS9.3 has the ability to physically move photos between albums or is it still all pointers right back to a file master photo?

    It is always fair to pointers back to the original - so if you remove the original photo, it is also removed albums you "copied" in

  • How can I merge albums / move photos between albums photos?

    I upgraded Mavericks in El Capitan and therefore iPhotos to Photos. In Photos, my iPhotos events are all stored in an album named iPhoto events. In iPhotos I could merge the events and move individual pictures between events. How do I do this in Photos? Thank you

    . In Photos, my iPhotos events are all stored in an album named iPhoto events.

    It should have a folder named "iPhoto events" created, with a separate album for each of your previous iPhoto events. Is this not happen?

    Photos does not have events, but the moments that are created automatically, and you cannot move photos between moments.

    If you want to have an album for each of the imported pictures, select all the new photos in the album "last import. Then press the ⌘N key combination to create a new album from selected photos. If you reveal the sidebar with ⌥⌘S, you can easily drag albums between folders and add photos to an album to a different album by dragging photos to the album in the sidebar.

  • {run DLL} There is PROBLEM BEGAN of runDLL "C/USERS/OWNER".

    I get this error message... why?  "

    {run DLL} There is PROBLEM BEGAN of runDLL "C/USERS/OWNER".

    I understand that you get a relative to a runDLL error message.

    What is the number of product of the laptop?  This can is usually located on the label on the underside of the laptop or in the battery compartment.  This label should also contain the serial number.

    NOTE: Provide NOT the serial number.

    What OS is the system using?  For example, Windows 7 or Windows Vista.

    What happened after that a particular program has been installed or uninstalled?

    RunDLL errors can be the result of malware.  Do you have scanned the system for malware using an updated anti-virus program?

    It happens in a clean boot state?  This document explains how to enter in a clean boot state.

  • Creation/move user to another player data files.

    I install Vista on a new hard drive to 500 GB. I am partitioning the drive into two and want to keep records of data of the user on the D: half. Suggest you creating accounts and then moving them or the definition of the default location on the D: drive?  What are your suggested steps?  Thank you, in advance.  -Hank

    http://www.vista4beginners.com/move-user-files-folders-to-another-partition

    The tutorial above should help you with your questions.

    See you soon. Mick Murphy - Microsoft partner

  • Shortcut keys to move applications between monitors?

    I need a better way to move applications between monitors in Windows 7 - if all goes well, there are a few obscure hotkey for it.   Even something that leaves me with the button straight on the taskbar icon and say to poster would do the job.

    Currently, the only way I can do that wastes an incredible amount of time:

    1.) toggle the maximized unmaximized soft.

    2.) drag it to the desired monitor

    3.) expand the app again.

    This process is bad enough most of the time... but sometimes I see only one of the monitors.   My second monitor is my TV and I could, for example, have a football match played on it when I open an application - and sometimes opens on the TV instead of my main screen.   When this happen the process of moving from the app to my main screen becomes much longer:

    0.) turn on/off TV so that it displays input from the PC instead of the game of football.

    1.) 2) 3.) top

    4.) TV to switch to the football game.

    When I have to go through this process in 5 steps, it takes 102 seconds (Yes, I've timed it) where it should be a simple matter of using a keyboard shortcut or simply right click on the taskbar icon and say things to move it to the other monitor.

    One would think would improve with each generation of Windows multi-monitor support, but I think it has reached a peak with Windows 2000 and my old Matrox cards and has been downhill since then.   And nothing of what Microsoft has done compared to multi-monitor support, I loved it in OS/2 3 and 4.

    (1) do not switch unmaximized until you can drag. You can do it simply, even if it's already maximized.  Try it.  It works on Windows 7 +.

    (2) you can also use a keyboard shortcut, such as +arrow to line up on the side, or +SHIFT + arrow to send to the next screen.

    I could go on.  Everything what you asked above already exists, you did not.

  • Channel Port LACP with VMWare ESXi IP hash Message: % SW_MATM-4-MACFLAP_NOTIF: < MAC > host in the vlan 1 is flapping between port

    Hello

    Currently I have a VMWare ESXi host with 2 network including 6 cards (3 of each) ports are connected to a X 3750.  I configured LACP on the switch and the Port of vDS group road based on IP Hash (802.3ad), my looks of config as follows:-

    src-dst-ip port-channel load-balance

    Interface Port-channel15

    switchport trunk encapsulation dot1q

    switchport mode trunk

    !

    interface GigabitEthernet1/0/15

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    !

    interface GigabitEthernet1/0/16

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    !

    interface GigabitEthernet1/0/17

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    !

    interface GigabitEthernet1/0/18

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    !

    interface GigabitEthernet1/0/19

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    !

    interface GigabitEthernet1/0/20

    switchport trunk encapsulation dot1q

    switchport mode trunk

    bandwidth share SRR-queue 10 70 25 5

    form of bandwidth SRR-queue 10 0 0 0

    priority queue

    MLS qos trust dscp

    spanning tree portfast

    channel-protocol lacp

    active in mode channel-group 15

    Currently I see many MAC beat in the log of the switch.  From my understanding, I expect the MAC address out all ports, because that's what'd ESXi when you use 'route based on the hash of the IP.  I'm worried about the impact this might have on the CPU / switch.

    August 6, 09:42:05.700 TSB: % SW_MATM-4-MACFLAP_NOTIF: 0050.569e.0939 to host in the vlan 1 is flapping between port gi1/0/16 and article gi1/0/15

    August 6, 09:42:16.479 TSB: % SW_MATM-4-MACFLAP_NOTIF: 0050.569e.28e4 to host in the vlan 1 is flapping between port gi1/0/20 and 0/article gi1/17

    August 6, 09:42:18.719 TSB: % SW_MATM-4-MACFLAP_NOTIF: 0050.569e.7f6a to host in the vlan 1 is flapping between port gi1/0/19 and article gi1/0/20

    August 6, 09:42:20.766 TSB: % SW_MATM-4-MACFLAP_NOTIF: 0050.569e.0939 to host in the vlan 1 is flapping between port gi1/0/16 and article gi1/0/15

    Is it by design, if so can I disable the message?  If this isn't the case, please can you advise where I can check/change the configuration?

    Thank you

    Peter

    It is really gud who... .you mentioned your solution here.

    Can you please mark this question as answered, thatâ so it can help the other guys.

    Concerning

    Please rate if this can help.

  • Provisiong Movi users using VCS & AD

    Hi all

    How Movi users provisioning works, if the customer has configured all users on AD and linked VCS to AD, but there is no TMS

    I guess that when customer movi connects, it will go to the AD for authentication
    But other then that, without going through the TMS that will contain the configuration data?

    Thanks in advance

    Hello

    Provisionig data always on the vcs. TMS is used to manage the data for manageability but its replicated for vcs.

    If you use provisions without TMS, then I assume you are using VCS Starter Pack. Config templates are incorporated.

    With vcs control, TMS is required to

    perform commissioning.

    / Magnus

    Sent by Cisco Support technique iPhone App

  • "There was a problem starting module specified C:\Users\user\AppData\Local\Temp\fe0_zip.exe is missing."

    When I opened my computer this message pop out... "There was a problem starting module specified C:\Users\user\AppData\Local\Temp\fe0_zip.exe is missing." Hope you can help me. Thank you very much.

    Original title:

    Help, please...

    http://www.Google.com/search?q=there+was+a+problem+starting+C%3A \Users\user\AppData\Local\Temp\fe0_zip.exe&ie=UTF-8#hl=en&sclient=psy-ab&q=fe0_zip.exe&oq=fe0_zip.exe&gs_l=serp.12... 15872.15872.0.16452.1.1.0.0.0.0.43.43.1.1.0.Les%3B... 0.0... 1 c. W0yhBtxgyQo & PBX = 1 & bav = we. 2, or.r_gc.r_pw.r_qf & FP = cd0820781f4eef2e & BIW = 1344 & BiH = 683

Maybe you are looking for

  • Cannot save via TemPro

    Hello! A cannot save my laptop via TemPro. Always say, contact a dealer or other guys!I don't want to make a phone call. I want a support email address! For this great company * is not a public e-mail address * for product registration! Molnár; Józse

  • Qosmio G20, Toshiba Power saver error

    When I turn the Qosmio G20, I have a message "Toshiba Power Saver, fatal error has occurred, this program will end. Code 0 x 2»I click on the 'ok' button and can use the computer, but after using for a while (about 1 hour for example), it becomes ver

  • network controller driver is not installed and is not listed in hp 15-do17tu wireless

    I can't find network control drivers. I use 32 bit windows 7 ultimate which is not listed on the hp Web site! Here's my hardware id PCI\VEN_168C & DEV_0036 & SUBSYS_217F103C & REV_01PCI\VEN_168C & DEV_0036 & SUBSYS_217F103CPCI\VEN_168C & DEV_0036 & C

  • VPN error 868 the name of the remote access server is not resolved

    I use Windows 7 Home Premium and you want to configure a VPN with my office network that uses the Check Point Safe@Office.  I am unable to log in and get the error that does not resolve the name of the remote access server and Windows cannot find the

  • Blue screen Windows 8.1

    Hello First of all, sorry my bad English. I try very hard for my new PC with Windows 8.1.  But nothing works! I get a lot of error mensage. Example: KERNEL SECURITY CHECK FAILED. MEMORY MANAGEMENT; NTFS FILE SYSTEM (Ntfs.sys); 0x000021A; BAD POOL HEA