10-08-2008 06:50 AM - edited 02-21-2020 03:02 AM
Dear Support,
We have Cisco CAM & CAS that is deployed for OOBVG mode when connecting the client machine and trying get web access the client is already in the authentication vlan due to switch management port profile settings but the client cannot get an ip address through dhcp so is there any configuration to be done on the switchs or core to enforce authentication vlan to be directed to the access vlan as i configured the port profiles and vlan mapping and managed subnets what can i check to get the correct access connectivity
10-14-2008 06:59 AM
For In-Band clients and Out-of-Band clients which are still assigned to the Authentication VLAN, the Clean Access Agent uses SWISS discovery packets to verify connectivity with the CAS. Once a client machine is on the out-of-band network and no longer communicates directly with the CAS, additional configuration is required for the client to determine whether it is still on the Access VLAN or moved to the Authentication VLAN.To ensure OOB users are able to maintain network connection when the Cisco NAC Appliance administrator is forced to "kick" users out (and move the session back to the Authentication VLAN), you can configure the Cisco NAC Appliance system to have the Clean Access Agent renew the IP address via DHCP release/renew.
10-14-2008 10:00 AM
10-15-2008 06:13 AM
Did you configure DHCP relay mode for the CAS?
Device Management > CCA Servers > List of Servers > manage(your cas) > DHCP
for more information on this, refer to the "CAS installation and configuration guide"(page 126)
10-15-2008 09:34 AM
Dear Drienties;
for virtual gateway mode dhcp is passthrough.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide