SNAC-LAN Enforcer Transparent mode
greetings
i have set up SNAC for host integrity check as a LAN enforcer in transparent mode. i have setup vlans on the switch, setup interfaces on the router with routing. pinging from client pc when connected to a guest vlan is successful. when i connect a pc to the switch it fails to authenticate and is moved to the guest vlan that is when Wired AutoConfig service is no running. if i start th wired Autoconfig service it tries to authenticate but fails and does not move pc to guest vlan or quarantine vlan. on the Symantec Endpoint Manager on SNAC settings i have set it to ignore result on host integrity check and action is to open port. i enabled debug on the switch, and when a switch is trying to authenticate it shows a message that the SNAC enforcer is not responding.
The SNAC kernel log shows "[ radproxy.c][ 2846]: Invalid signature from switch 192.168.1.2", but the key password matches. please assist i dont know where im doing it wrong. below is the cisco 2960 switch config:
Comments 14 Comments • Jump to latest comment
Hi;
On the SEPM site you must select use SNAC client as an suplicant for Transparent mode. If you dont select this you will faced with this kind of porblems. And also you must add the IP address of the swith in the Lan enforcer configuration.
And can you please send the configuratşon screens on SEPM for further assistance.
Regards.
Cemile
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
hie
thanks for the help. please find attached the config screens on the sepm.
is there a way to tell if the port 1812 port is open? i tried to telnet to the SNAC ip address port 1812 and its refusing. also did a debug on the switch below is a sample:
Can you please send the data which incluse in the Radius Group.
You must add a dummy radius. With the ip address 0.0.0.0
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
Radius Group must be like this
And the actions must the like this.
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
whats on the screenshots above is how i configured my SEPM. it looks like the Lan Enforcer is not responding to requests. below is a log what could it mean?
Hi;
Can you please upgrade your lanenforcer to the latest version. And also SNAC to 12.1 ru1 mp1.
On one of my case problems solved after upgrade.
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
ok thanks i will upgrade.
just something that has come through my mind. do i have to enable authentication on client pc's when im using transparent mode. for what it does is host integrity. also if so which authentication protocol do i use e.g. peap, md-5 challenge etc
Hi;
if you want to use authentication you muct use full mode not trasnparent mode.
And also you must use raduis (for example IAS or NPS) for user authentication. In that case you can use eap or peap regarding you radius.
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
thanks a lot for the assistance, the Symantec Lan Enforcer is working well when im using the protocol "symantec nac transparent mode". i noticed on the actions tab stated that we ignore the result of "policy check". can i be able to check for policies like if the antivirus is updated etc
Yes.
With Host Integrity policy you can check antivirus updates or any thing you want. Host Authentication measn Host integrity
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
hie
is there a way of starting the wired autoconfig serv ice on computers remotely like via group policy and selecting "Symantec nac transparent mode" as the authentication method?
i have configured my vlans as:
vlan 1 default
vlan 10 quarantine
my switch interfaces are vlan 1 - 192.168.1.2
vlan 10 - 192.168.10.2
i get the error "Jul/11/2012 16:54:23 [ radproxy.c][ 2753]: Failed to find switch profile with IP 192.168.10.2!", what does it mean and how can i resolve this.
also authentication fails.
hey
i noticed it was authenticating but its working perfectly now.
is there a way to grant access to a computer so that it can bypass the nac authentication and access network resources without being moved to the guest or quarantine vlan?
Hi;
Yes you can use MAB ( Mac Authentication Bypass)
You can find the details at the following links.
http://www.symantec.com/business/support/index?page=content&id=TECH91734&actp=search&viewlocale=en_US&searchid=1342126785549
http://www.symantec.com/business/support/index?page=content&id=HOWTO55736&actp=search&viewlocale=en_US&searchid=1342126785549
Regards;
Cemile Denerel
Note: Please mark as solution if its help you.
Would you like to reply?
Login or Register to post your comment.