Cisco VPN 3000 Concentrator and NAC

Unanswered Question
Apr 30th, 2007

I am using a 3000 series concentrator to enforce network admission control for remote clients comming in VIA vpn. We are using Cisco NAC framework using ACS 4.1 but we notice posture validation takes a long time and the downloadable filter is not applied allowing access to the network for several minutes. Is there anything I can trouble shoot or tune to speed this process up. It should be noted that the clients are trying to ping through the sensor as soon as the tunnel is up so the EAP challenge should take place straight away. We are also using Cisco's CTA on the clients

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
aghaznavi Fri, 05/04/2007 - 10:36

think your problem is indicative of the EAP type not being enabled in the authentication settings. If you are using the Network Access Profiles in your ACS configuration, then the EAP type being used needs to be enabled within the Authentication settings of that NAP. Following link may help you

http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs40/user/sp.htm#wp1123517

Actions

This Discussion