Security

Reply
Occasional Contributor I
Posts: 5
Registered: ‎11-08-2016

Wired-health-check in NAC

Hello

 

My company network working in NAC system. We have different VLAN's configured in our network.

 

We have made a wired-check-policy as under:

  1- check user name in AD, if its ok then send it guest network and go further

  2- check health of system, if its healthy then go further otherwise guest network

  3- if system healthy then then again verify user name and mac address in our database the join this system our internal network.

 

Result:    policy perfect work with all systems.

 

Problem: I got a problem in one system. this system using a two different users.

 

user 1: 8:00 to 12:00

user 2: 12:00 to 5:00

 

when user 1 log in to system then NAC send him to guest network.

when user 2 log in to system then NAC send him to internal network

 

I thought may be problem with user account. Then I try log in with user 1 in different system. NAC send him to internal network. That means its not a problem with user account.

 

I have also checked the time of system. Its also correct.

 

Error :  clearpass onguard service can't enable user 1 but with user 2 automatice enable.

 

Kindly can anyone tell me what should I check.

 

Thanks 

 

Tariq

 

 

    

     

 

 

MVP
Posts: 992
Registered: ‎04-13-2009

Re: Wired-health-check in NAC

 

What does the access tracker say? 

 

Also what is occurring in step 3 and if this step fails does the user just get guest access?

 

"3- if system healthy then then again verify user name and mac address in our database the join this system our internal network."

 

Can you post the enforcement policy for this step?

Cheers
James

-------------------------------------------------------
-------------------@whereisjrw-------------------
------------------------blog-------------------------
ACCX #540 | ACMX #353 | ACDX #216
-----------Mobility First Expert #11----------
-------------------------------------------------------

If a reply adequately addresses your issue, please click on the "Accept as Solution" and "Give Kudos" button so this information can benefit other users via search.
Occasional Contributor I
Posts: 5
Registered: ‎11-08-2016

Re: Wired-health-check in NAC

Hello

 

Thank you for your replay.

 

I have attached a docx file. In this file you can find a service and access tracker status.

 

regards

MVP
Posts: 992
Registered: ‎04-13-2009

Re: Wired-health-check in NAC

OK, so it's just a single computer that's failing to health check prior to authentication.

 

FIrstly I'd recommend reinstalling the OnGUard client on that machine.

 

If the issue continues I'd recommend logging it with TAC. They're the best people to analyse the OnGuard logs for you.

Cheers
James

-------------------------------------------------------
-------------------@whereisjrw-------------------
------------------------blog-------------------------
ACCX #540 | ACMX #353 | ACDX #216
-----------Mobility First Expert #11----------
-------------------------------------------------------

If a reply adequately addresses your issue, please click on the "Accept as Solution" and "Give Kudos" button so this information can benefit other users via search.
Occasional Contributor I
Posts: 5
Registered: ‎11-08-2016

Re: Wired-health-check in NAC

Hello Dear

 

Thank you for your replay.

 

I just uninstall clearpass onguard and reinstall and problem was finished.

 

Now I can see this user in specifiek network.

 

Thanks en regards

 

Tariq

Search Airheads
Showing results for 
Search instead for 
Did you mean: