I am using a 3000 series concentrator to enforce network admission control for remote clients comming in VIA vpn. We are using Cisco NAC framework using ACS 4.1 but we notice posture validation takes a long time and the downloadable filter is not applied allowing access to the network for several minutes. Is there anything I can trouble shoot or tune to speed this process up. It should be noted that the clients are trying to ping through the sensor as soon as the tunnel is up so the EAP challenge should take place straight away. We are also using Cisco's CTA on the clients
think your problem is indicative of the EAP type not being enabled in the authentication settings. If you are using the Network Access Profiles in your ACS configuration, then the EAP type being used needs to be enabled within the Authentication settings of that NAP. Following link may help you
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...