NAC.OOB.L2.Real IP GW.dhcp-relay issue.

Unanswered Question
Apr 17th, 2008
User Badges:


I have CAM (manager) which is configured as L2 OOB real-ip gateway. central deployment.

ethernet 0 (trusted) is L3. (ip add x.x.x.x)

ethernet 1 (untrusted) is .1q and several authentication vlans (a,b,c,d) are connected to it.

of cause managed subnets are configured for auth vlans on eth1.

Manager is configured as dhcp-relay.

Is it ok that manager changes dhcp packets to the dhcp server so that it's ethernet 0 ip address (x.x.x.x) becomes the source address of the requests to the dhcp server?

how can dhcp server recognize auth vlan a from auth vlan b if all packets have the single source (x.x.x.x)???

Where could be my mistake?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
miklos.andrasi Wed, 04/23/2008 - 01:31
User Badges:

Hello varnavsky!

You have to configure vlan mapping (at the CAM) for all authentication vlan! After the authentication and posture validation, the NAC client won't give a new IP address, so the client has to have an IP address from the proper access vlan. When you configure these vlan mappings CAS always acquire an IP address from the proper range.

By(e) Miki

varnavsky Wed, 04/23/2008 - 06:46
User Badges:

Hi, Mike.

I don't think so. vlan mapping is NOT applicable to Real IP GW.

I've sniffed dhcp-requests from the auth vlans to dhcp server. They are all from the single ip address (NAC Server eth0-trusted). But inside there is the ip address of the untrusted interface - as dhcp relay agent ))

I've solved this issue. It's ok =)

miklos.andrasi Thu, 04/24/2008 - 01:04
User Badges:

Hi varnavsky!

You are right! I thought you are in VGW mode, so I'm sorry.

You mentioned you had solved this problem. How does it work finally?

By(e) Miki

varnavsky Thu, 04/24/2008 - 01:24
User Badges:

Hi, Mike.

Yes, it's done.

If you have any questions try to help you.

Today I'm fighting with AD+SSO+LDAP so that users can get vlan accourding to their OU in the AD. There are still some problems.

And at the next week I'll try vlan mapping in the VGW mode =)


This Discussion