Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

OOB deployment Cisco Aironet Access Points on NAC appliance without WLC


is there any way to deploy Cisco Aironet Access Points in OOB on NAC appliance without using a WLC such as VLANs configuration on Access-points via Radius Server or any other way?


  • Other Security Subjects

Re: OOB deployment Cisco Aironet Access Points on NAC appliance

The Clean Access Manager (CAM) manages out-of-band Clean Access Servers (CASs) and switches through the admin network. The trusted interface of the CAS connects to the admin/management network, and the untrusted interface of the CAS connects to the managed client network.

When a client connects to a managed port on a managed switch, the port is set to the authentication VLAN and the traffic to/from the client goes through the Clean Access Server. After the client is authenticated and certified through the Clean Access Server, the port connected to the client is changed to the access VLAN. Once on the access VLAN, traffic to and from certified clients bypasses the Clean Access Server.

In most OOB deployments (except L2 OOB Virtual Gateway where the Default Access VLAN is the Access VLAN in the Port profile), the client needs to acquire a different IP address from the Access VLAN after posture assessment.

For Real-IP/NAT-Gateway setup, the client port is bounced to prompt the client to acquire a new IP address from the admin/access VLAN.

The below URL describe the configuration steps needed to set up your OOB deployment:

•Configure Your Switches

•Configure OOB Switch Management in the CAM

•Configure Access to Authentication VLAN Change Detection