We had problems a year ago with Cisco 3750 switch stacks. CCA would
change the VLAN on the wrong port.

Two things fixed this issue

1. An update to the IOS version on the switch stacks.

2. Our Clean Access database had been corrupted. We had to rebuild by
hand from a _clean_ install (Darik's Boot & Nuke & then install).
Updating 30 machines is not fun :( The CCA installer does not fully
erase the disk before install, even though it says it is formatting the
disk.

I hope your problem is resolved easier.


Bruce Osborne
Liberty University

-----Original Message-----
From: Cisco Clean Access Users and Administrators
[mailto:[EMAIL PROTECTED] On Behalf Of Bill Davis
Sent: Friday, January 18, 2008 4:53 PM
To: [email protected]
Subject: [CLEANACCESS] Incorrect vlan & switch assigned to user in
Certified Device list

We are running Clean Access v4.1.2.1 with Agent v4.1.2.2 in OOB virtual
gateway mode.

We have been seeing several users today associated with incorrect access
vlans that prevent them from logging in fully.  The Agent just keeps
popping up.

The certified device list will show an incorrect configuration for the
auth/access vlan.  The auth vlan is correct but the access vlan appears
randomly chosen from other existing access vlans.  In addition, the
switch
and port associated with the user is incorrect, but this incorrect
switch/port info does correlate with the incorrect access vlan.

The switch/port the user is actually connected to does indicate that the
user has not been changed out of the auth vlan.  The switch does not
assign
the incorrect access vlan.

While the user is found in the certified device list with the correct
mac
address, they are unable to get full access.

Has anyone seen this behavior before?  Is this a known issue?

-Bill
Bill Davis
Network Security Administrator
Housing Technology Services
Colorado State University

Reply via email to