cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

NAC AAA rule assentment .

NAC AAA rule assentment .

Frank11
New Contributor
NAC 6.3.0.168, Wireless V2110 9.21.09.0004
I have a strange issue with devices not using the right AAA rule in the NAC even though when checking the device via the NAC evaluation tool tells me it should be using the right rule.

The NAC is setup for proxy Radius to a windows NPS server. When I run the NAC evaluation tool I get the correct information below with the correct rule "BYOD-test" passed.

f9b222598dd94c1bb00290714c7aaa31_RackMultipart20160531-125329-2alla9-BYOD-Rule_inline.jpg


BUT looking at the NAC end-systems data for that device it goes to the end "catch-all" rule, not the rule the evaluation tool displays.

f9b222598dd94c1bb00290714c7aaa31_RackMultipart20160531-79076-nrg4wl-BYOD-Rule1_inline.jpg



Any idea's where to look or are there other tools I can use for testing?
8 REPLIES 8

Frank11
New Contributor
Just a update. Problem found and fixed.

Like to thank everyone for showing me the way to looking at the extended logs. I did not know they existed. From the logs I found the BYOD rule was skipped by the NAC when it was processing the rule order. From this I assumed I did run "Enforce all" on the NAC when I first created the rule but it seems I did not. Enforced the rule and now working as intended.

James_A
Valued Contributor
That happened to me just the other day. It'd be nice if the config evaluation tool detected you had unenforced appliances and put up a big warning.

TylerMarcotte
Extreme Employee
If you show the End System Group that you're keying off of and the User Group that would help with troubleshooting. Otherwise, like Zdenek said, you can get seem more diagnostics from the NAC appliance itself.

Jeremy_Gibbs
Contributor
Yes, you need more logging. What is NAC seeing in the RADIUS packet? Is it sending all the info you expect? What does it look like from a NAC perspective (if you search for the end system and view its "status" ?
GTM-P2G8KFN