ā09-08-2021 08:26 AM
Hello all,
We have some troubles with NAC configuration on our x440 switches. Weāve created service rule that deny traffic to some destination subnet. Letās say 10.0.0.0/24, but when client is connected directly to the switch (via ethernet connection) rule doesnāt work! On WiFi everything works completely fine.
Command āshow policy capabilitiesā issue on switch shows us that IP Destination Subnet is supported on this device.
Does anyone know how to resolve this problem?
Thanks in advance,
Marcin
ā09-08-2021 09:06 AM
I switch to āPermit trafficā works the same as contain to vlan. Switch is synced with domain, everything is applied, i also checked directly on the switch if rules are there, and everything looks fine.
Here is policy role, itās create for testing purposes. Iāve try to block traffic also by IPDstSocket, doesnāt work either.
ā09-08-2021 08:57 AM
Iām not 100% sure if service rules are applied if you use ācontain to vlanā instead of āPermit Trafficā or āDeny Trafficā. I only used one of the latter when denying access to certain subnets via service rules.
Can you maybe try to use āPermit Trafficā?
Can you go to Policy ā Devices ā Right-Click the switch and hit āVerifyā to check if the policy is correctly applied?
Can you share a screenshot of the policy role?
ā09-08-2021 08:38 AM
Hi Stefan,
Yes and yes. Switch is part of the policy domain, and nac role is configured, proper service that supposed to block traffic is also added to role.
Role action is contain to VLAN
ā09-08-2021 08:34 AM
Hi,
is the switch part of the Policy domain?
Is there a NAC rule configured that applies the correct Role?
Regards
Stefan