Reuse the material of the NAC

Is is possible to reuse our equipment of the NAC Server and Manager 3310 with ISE?

Hello

You cannot reuse the NAC 3310, the 33 x 5 and 1121 ACS are the platforms supported for ISE. However existing customers have benefits for the upgrade to ISE. Please join your Cisco partner and if you don't practice you can reach for me and I can help you.

Thank you

Tarik Admani
* Please note the useful messages *.

Tags: Cisco Security

Similar Questions

  • HP ENVY: I took the tape cartridge error color how to protect? cannot reuse the Ribbon that seems.

    I took broadband of the cartridge color by mistake, but I can't reuse the tape. What is the best way to protect?

    Hello

    You can try and hold the Ribbon with a few rubber bands wrapped around the cartridge of thr. Keep in a sealed bag will also help.

    The goal is to keep the print head don't dry out. When kept in a printer, the cartridge is capped when not is use to avoid it drying out.

  • I want to buy the original game of Rhem. The only copy I could find was used. I'll be able to reuse the game cd key to install it on my computer?

    OT:RHEM Cd Key

    I want to buy the original game of Rhem. The only copy I could find was used. I'll be able to reuse the game cd key to install it on my computer?

    Hi Matthew79,

    What edition\version of Windows you are running on the computer?

    Normally the games can be installed any number of times on the same computer with the product key provided. However, if you install the game on another computer be considered wrong licensing.

    Contact the game manufacturer for further information on licenses and buy the game.

    http://www.gotgameentertainment.com/contact.htm

    Thanks and greetings
    Ajay K
    Microsoft Answers Support Engineer
    ***************************************************************************
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • reuse the license of Windows XP from the old office to the new office

    We have 4 old desktop computers with windows xp I want to reuse the license of Windows XP from the old office to the new office

    I bought a HP desktop computer and dell preinstalled with Windows XP. The office has not worked for a few years, he has the processor are P4 and slow work.

    I recently bought a desktop computer and wanted to know can I use the same license key to get Windows XP installed on my new desktop computer.

    Note: I have lost my original installation of windows CD but have the office and Windows XP product code is available to me.

    The old HP desktop and dell came with a license with the sticker on the side.

    Any PC which came with a sticker with a key to activate product on it has a license that is related to this PC (and only this PC) for ever. It is not legal to install on a PC using the key videos from another PC.

    If the PC you want to install XP on still has its sticker, then as much as you have a compatible installation XP CD, XP can be re-installed using the key on the sticker.

    Only commercial versions of XP can be moved from one PC to another. With the commercial versions, the activation key came with the media, not on a label stuck on the PC.

  • Can I reuse the key of Windows 7 Professional?

    Hey,.

    Been using Windows 7 for a few months now and I must say, im absolutely love it.
    The other day, while visiting some dubious sites offering a video converter, I got a virus.
    Now, I tried AVG and an anti-spyware program, and both can detect the virus but not effectively deal with it.
    I find myself with a frustrating user experience which includes Windows crashes, a lot of notifications and general performance slowdown, on what is a fast laptop. I'm tired of trying to patch up things and think that the best method would be to format the HARD drive and reinstall Windows.
    Now, my question is, when I reinstall Windows, my product key will be reusable?
    I picked up my copy of Windows 7 on the offer of £30 student and am concerned about the use of the license.
    Like what I do, can I disable Windows somehow, then reinstall it just use the same key?
    Someone at - it advice on the system would work?
    Thank you.

    Hello

    Product key Windows 7 (license) is constant, it never expires. You can reuse the key as many times as you want, as long as the operating system is installed on a single computer at a time.

    The student version of Windows 7 is the retail version upgrade. You will need to perform the installation in the same way that you did when you originally installed it.

    The product key that you used to activate the first installation is maintained on Microsoft Activation servers. After the reinstallation, you may need to perform a manual activation, which means that you may need to use the phone option when you activate. Here are the instructions for a manual activation.

    1. from the desktop, press the button of the Windows Logo + R. This will bring up the run dialog box.

    2. in the Open: box, type slui 4 and press OK. This starts the manual activation wizard.

    3 select your country from the drop down and click Next.

    4. the wizard displays a toll-free telephone number. Leave the wizard open on the computer and call this phone number.

    You will receive a few saved options. Select the option to speak to a representative.

    The representative will manually activate this system for you.

    Let us know if you have any problems more

    Ronnie Vernon MVP
  • Version of the NAC

    Dear,

    Can what version of the NAC I install VMware?

    Can anyone help please with the above query.

    Thank you

    NAC is not supported on Vmware. Yet people have managed to install NAC4.1 on Vmware, but newer version do not work.

    There is a new product called Cisco ISE, which will eventually replace the NAC. Cisco ISE can be installed on Vmware.

  • Ports of the NAC

    Hello Experts,

    Have some questions that came across while doing work of the NAC at one of our subsidiaries. If there is some user ports which are not selected for the profile of the NAC, is it possible (except physical control on the cell phone of the user by allowing all ports & audit) which can be used to track the paths of users without mail for NAC.

    Second, if the user of the NAC port is manually on the vlan user (rather than quarantine or vlan temporary), which is the correct order for that.

    the user on NAC field must be typed manually to vlan user or port profile should try not controlled followed by rebound port & update.

    Apprecite all help, thank you.

    Hello

    See online:

    If there is some user ports which are not selected for the profile of the NAC, is it possible (except physical control on the cell phone of the user by allowing all ports & audit) which can be used to track the paths of users without mail for NAC.

    [Tiago] On the graphical interface of CAM, you can check which controlled uncontrolled ports are. It is the only place where ports can be determined to be managed/no managed.

    Second, if the user of the NAC port is manually on the vlan user (rather than quarantine or vlan temporary), which is the correct order for that.

    the user on NAC field must be typed manually to vlan user or port profile should try not controlled followed by rebound port & update.

    [Tiago] When you perform the configuration of the switch, the switchports can be put on the vlan user or default access vlan. It depends on the port profile settings that you have configured. By default, when a port is managed on the basis, if a client connects, an SNMP trap is sent to the CAM. The CAM check whether the machine is certified or not (check the mac address). If the machine is not certified cam becomes the vlan the authenticated vlan configured on the port profile.

    So, whenever you connect a PC to a switchport, CAM evaluates what is the vlan correct the PC to start and change it accordingly.

    HTH,

    Tiago

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • Support of the NAC Profiler address & ip

    Hello

    I have a layer 3 OOB NAC Profiler deployment and I am trying Profiler some IP phones from a remote location by using the statement of helper-ip address on the interface on the remote router. The problem is that the remote router acts as a dhcp server for the vlan voice and fact not forword DHCP discover for Colectionneurs of the NAC, and I can't phone ip profile. Do you know a way (an order of configuration on the router) to forword the dhcp even though the router acts as a DHCP server for this vlan?

    Thank you

    Victor

    Hi Victor,

    To do this... You must add a SVI for the voice VLAN on the switch behind the router, and then add the IP helper on the new interface VLAN voice.

    -Hassan

  • Actual gateway IP process to strip the NAC

    Hi all

    I did a lot of research, and I can not find good answers to some of my questions. All the big questions are answered for out-of-band configuration, but I find that it is assumed that this understanding in the Strip is taken for granted lol... I guess I'm slow = P

    1. How does the gateway IP In-band real?
    2. What is the point of the 30 subnets?
    3. Are there any access/auth pairs VLAN configurations in the band?
    4. How does quarantine work?
    5. I read that the NAC server cannot send traffic on untrusted port to a VIRTUAL LAN and that you are not allowed to trunk port. This means that there is no support for several VLAN reliable, mapped to a single server at the NAC?
    6. Can you do role with configurations mapping in the band?

    Assistance for all or part of these questions would be GREATLY appreciated!

    Thank you a lot =]

    ~ Xavier.

    Hi Xavier,.

    I'll try to answer your questions

    1. How does the Strip Real-IP Gateway?

    The CASE works in routed mode, if you have different IP addresses (on different subnets) on interfaces approved and unapproved. Because the CASE does not support routing protocols, routing must be configured through static routes

    2. What is the point of the 30 subnets?

    The idea is to have small subnets for your customers so that with this config IP customers in authentication VLAN should through the CASE even to talk to other clients on the same subnet L2.

    Click here for an explanation:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/47/CAs/s_dhcp.html#wp1057889

    3 is there access/auth pairs VLAN configurations in the band?

    If you ask if there is mapping VLAN, then the answer is NO, as the purpose of the VLAN mapping must * bridge * traffic between approved and unapproved mapped VLAN, but in real-IP the L3 routing traffic CASES.

    4. How does quarantine work?

    When a client is quarantined, it works the same way as OOB, as in this phase, the client is always online to the CAs.

    So the concept is assigned to the CASE by the temporary user or the role of midlife and he applies a traffic policy you've set up temporary or the role of midlife.

    5. I have read that the NAC server cannot send traffic on untrusted port to a VIRTUAL LAN and that you are not allowed to trunk port. This means that there is no support for several VLAN reliable, mapped to a single server at the NAC?

    The restriction of VLAN "single" for Real - IP CASE applies only to the * trust * side. The CASE may be the default gateway for several subnets VLAN / IP on the * rogue * side.

    Configuring addresses VLAN / additional IP on the unreliable side by using the configuration "managed subnet.

    This is mentioned here:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/45/CAs/s_deploy.html#wp1050938

    The clean access server can manage one or more subnets, with its untrusted interface, acting as a gateway for managed subnets. For more information on the setup of managed subnets, see Configuring managed subnets or static routes page 5-26.

    6. can you do role with configurations mapping in the band?

    Yes, you can do it! However, you cannot assign a VLAN as you do in OOB, but you can assign the different level of access based on IP traffic strategies and bandwidth restrictions that you assign the specific role.

    For example, check here for more details:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/45/cam/m_users.html#wp1040231

    In a Word, regardless of the use of the band vs OutOfBand:

    -customers are InBand before CAs in CASE detection, authentication, the phases of assessment and remediation of posture.

    The main difference occurs when the user is allowed to access the network and that you run the IB role assignment and OOB but... :

    -in customer traffic keeps on inline flowing to the IB CAs, so you can apply different access policies (ACL) and control of bandwidth depending on the role policies (but you cannot assign a VLAN);

    -in OOB, customer traffic bypasses the CASE once it is authorized: in this case, you can apply different VLAN but (given that the CASE is no longer along the way) you cannot apply ACL and/or ensuring the policy in this case.

    I hope that answers your questions.

    Kind regards

    Federico

    --
    If this answers your question please mark the question as "answered" and write it down, so other users can easily find it.

  • Fight against exclusion the NAC mac

    Experts, assuming that few users are now authenticate & viz cisco NAC network access, they be filtered from the NAC to exclude the posture of NAC will be they be disconnected from the network & reconnected since they were connected & now are going to be ignorant of the NAC.

    How it works in this case. users will be disconnected for that to be effective, or will they be disconnected by force before it takes effect.

    Thanks to you all.

    Hello

    There is a port bouncing feature Cisco NAC that accomplishes this task for you. But it depends on your deployment mode, it is not required for each of them. Please see this link:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/48/cam/m_oob.html

    Please indicate if you will find the entrance helpul. Thank you

    Farrukh

  • Activation of the NAC HA puts several hosts and ASA with processor clocked at 100%

    I installed a NAC Manager and a NAC server in OOB without any problems, but when I configured the AP (high availability) with another server, my ASA and several guests in my network started work ant 100% of the cpu.

    I tried to configure each interface of the NAC on a single DMZ and the problem stops there.

    -That someone had this problem (NAC version 4.7)

    TKX

    Miguel Amaral

    Hello Miguel.

    When I started a NAC InBand HA solution I had a similar problem that I solved the heart rate HA configuration to use ETH0 just instead use ETH0 and ETH1.

    Best regards

    Luciano Carvalho

  • Upgrade the NAC of 4.5 to 4.8

    Hello everyone

    I'm about to upgrade to a CNA of 4.5 to 4.8 on an application I do in a bank with 1500 users. The upgrade is due because the Bank makes its migration from PC to Windows 7

    The implementation is in a failover situation (2) and (2) CAM. the design is Out of Band, a virtual gateway and integration with a wireless LAN controller.

    I would like to know if when I upgrade the CAM and CAS´s for version 4.8 can I still use the Agent access own version 4.5 on clients? To perform the migration in several steps

    There is a StubAgent for version 4.8? or already included in the Agent 4.8? I install the StubAgent on all computers of the Bank, because they have no administrative rights.

    What is the best way to perform the upgrade of agents which does not affect users?

    Thanks in advance

    Eduardo Navas

    Hi Eduardo,

    Agent 4.5 is compatible with 4.8 CAM/CASE, although with a few restrictions:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/support_guide/agntsprt.html#wp52084

    For example, see also the following notes:

    "If you use version 4.8 of CAM/CASES with a version of the Agent plus early 4.8.0.32, then either use the requirement of the Distribution link or upgrade the Agent to the latest version to use the Distribution of files".

    "Cisco NAC Agent version 4.5.x is not supported by download version 4.6 (1) CAM because the structure of Agent installation files is different in version 4.5 (x) compared to the support in version 4.6 (1) agents."

    The NAC 4.8 agent has not any component necessary as the previous stub, for example:

    http://www.Cisco.com/en/us/docs/security/NAC/appliance/configuration_guide/48/cam/m_webagt.html#wp1473153

    Kind regards

    Fede

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • Integration of the NAC Profiler - cannot add list of filters on cam

    Hi all

    I have a problem with the Profiler - integration of the NAC for endpoint profiling.

    Here's the situation:

    I have already created the integration based on the steps in the Guide: Setup Cisco NAC Appliance integration. I think that the configuration is correct, because I can do database synchronization between the Profiler and CAM. Here's the log of server profile:

    NAC_SYNC: Task_Queue_Runner commissioning
    NAC_SYNC: Profiler / END of synchronization of the NAC [add 0, upd 0, desc 0, rm 0]
    NAC_SYNC: Profiler / START the synchronization of the NAC
    INFO: [2010-12-15 11:01:09 (fcapGetHWAddr:49)] is for eth0 MAC

    I have already created a profile of endpoint named "Admin" which is based on the IP address. I also created the NAC events based on endpoint profile 'Admin '.

    The event of the NAC will present 'Admin' profile to a role of the NAC. This event aims to circumvent 'Admin' of the legalisation of the ANC visa so that the "Admin" can connect to the network automatically to a role of the NAC.

    However, when 'Admin' to connect to the network, it still is challanged by NAC. I don't see "Admin" on the filter of the CAM or the list.

    This means that the endpoint profiling is still broken.

    Is there anyone who have experience with this?

    Thanks for the support and comments

    Imad

    Hello

    You cannot add devices manually on the profiler.

    The Profiler has to detect automatically (it is the concept of profiling).

    How this Profiler detects endpoints use the modules of collector.

    Each module has endpoints detection means.

    You will find the description of each collector module here:

    http://www.cisco.com/en/US/docs/security/nac/profiler/configuration_guide/311/p_intro231.html#wp1062345.

    HTH,

    Tiago

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • In the NAC MAC address filter list

    How are Faisal Hi, you? I have a question about this list of filters in the unit of the NAC. I want to do those recognized unit of the NAC mac addresses are to be get the network. However if a workstation's mac address is not in the filter list, would it not able to do the network. Is that the NAC has the ability to do? Please let me know. Thank you.

    Richard

    I'm not Faisal, but...

    You want to make additional (such as LDAP or such) or any authentication simply based on the MAC address?  If you want to only via the MAC, you can add them to the list of filters and then either set to 'allow' to allow all traffic, 'role' to put them in a specific role, or "check" to apply the evaluation of posture and then put them in the role.  If no other server authentication is configured, users who were not in the list of filters would not be able to authenticate, and they would be stuck in the authenticated VLAN.

    Thank you

    Lauren

  • Configuration of the switch of the NAC

    Hello!!

    I bought a NAC server and a manager of the NAC, to centrally manage the vlan where users connect to based on authentication.

    I have several sites, but the NAC server will be at Headquarters.

    When a remote user authenticates, NAC must configure the user switch port for the vlan right.

    What is an out-of-band solution?

    Do need me a specific license for out-of-band?

    Best of look,

    Miguel Amaral

    Hello

    It's the same pattern: Yo uneed 2 licenses, one for the CAM and the other for CAs.

    One cam sets the number of cases you can add.

    That case defines how many users is supported.

    So either the CASE PAK has been lost, or never bought.

    In both cases, you will need to contact the entitiy that sold devices and demand for the PAK CASE.

    HTH,

    Tiago

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

Maybe you are looking for

  • How to remove DriverCure from my office?

    I is NOT DriverCure but he himself planted in my task bar of the Office on the bottom of my desktop PC. Apparently not tho in my 'programmes', so it is not installed. I stopped to recording the DriverCure tho. I can only "exit" the DriverCure its bor

  • How to put the bar Google search on the main screen of the House?

    Hi people, I removed the main home screen Google search bar and now I can´t recover. I can add it as a normal widget on each home screen, but not at the high point of the homescreen homepage, where it was before. I remember that there was a notificat

  • Did I lose my library if I download a new version of Windows Media Player?

    I can't open my Windows media player. I click it and run as administrator, but it does not open if Im trying to download a new version of Windos Media Player but I want to know that if I do, will I lose all my music and photos?

  • HP Officejet 5510 all-in-one drivers for Snow Leopard (10.6)

    Just for you interested in getting the support of driver for HP Officejet 5510 all in one for Mac OS X 10.6 (to add to the growing list by the look of things!) I have a HP Officejet 5510, which is (about 5 years) worked flawlessly on Leopard Surprise

  • How to remove the Panel from the office toolbar

    I use the Desktop toolbar to hold my clear office icons, but on Windows 7, it's a shortcut to control panel that I can't get rid of.  It does not appear on my real desk, so I don't know why it appears in the toolbar.  How can I get rid of this shortc