Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 119

Network Interface Card (NIC) Driver Not Supported, Resetting and Restoring an Unreachable Clean

Page 119 highlights

Chapter 3 Installing the Clean Access Manager and Clean Access Server Troubleshooting the Installation Step 3 Step 4 Use service perfigo config to "reconfigure" the CAM/CAS initial configuration, accepting the previous values for all settings other than the master secret, which, in the case of an HA peer, you specify to match the other appliance in the HA pair. If deployed as part of an HA pair, bring the HA-Primary CAM/CAS back up, and then bring the HA-Secondary CAM/CAS back up. Database synchronization between active and standby CAMs takes place automatically, restoring the proper master secret in both the database and file system. Network Interface Card (NIC) Driver Not Supported For complete details, refer to the "Troubleshooting Network Card Driver Support Issues" section of the Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access). Resetting and Restoring an Unreachable Clean Access Server If incorrect network, SSL certificate, or VLAN settings have rendered the Clean Access Server unreachable from the Clean Access Manager, you can reset the Clean Access Server's configuration. Note that resetting the configuration restores the Clean Access Server configuration to its install state. Any configuration settings made since installation will be lost. To reset the configuration: Step 1 Step 2 Step 3 Connect to the Clean Access Server by SSH. Delete the env file: # rm /perfigo/access/bin/env Then reboot using: # service perfigo reboot You can now add the CAS to the CAM. See the Cisco NAC Appliance - Clean Access Manager Configuration Guide, Release 4.8(3). Enabling TLSv1 on Internet Explorer Version 6 Cisco NAC Appliance network administrators managing the CAM/CAS via web console and client machine browsers accessing a FIPS-compliant Cisco NAC Appliance Release 4.8(x) network require TLSv1 in order to "talk" to the network, which is disabled by default in Microsoft Internet Explorer Version 6. To locate and enable this setting in IE version 6: Step 1 Step 2 Step 3 Step 4 Got to Tools > Internet Options. Select the Advanced tab. Scroll down to locate the Use TLS 1.0 option under Security. Click on the checkbox to enable the Use TLS 1.0. option and click Apply. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 3-49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

3-49
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 3
Installing the Clean Access Manager and Clean Access Server
Troubleshooting the Installation
Step 3
Use
service perfigo config
to “reconfigure” the CAM/CAS initial configuration, accepting the
previous values for all settings other than the master secret, which, in the case of an HA peer, you specify
to match the other appliance in the HA pair.
Step 4
If deployed as part of an HA pair, bring the HA-Primary CAM/CAS back up, and then bring the
HA-Secondary CAM/CAS back up. Database synchronization between active and standby CAMs takes
place automatically, restoring the proper master secret in both the database and file system.
Network Interface Card (NIC) Driver Not Supported
For complete details, refer to the “Troubleshooting Network Card Driver Support Issues” section of the
Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access)
.
Resetting and Restoring an Unreachable Clean Access Server
If incorrect network, SSL certificate, or VLAN settings have rendered the Clean Access Server
unreachable from the Clean Access Manager, you can reset the Clean Access Server’s configuration.
Note that resetting the configuration restores the Clean Access Server configuration to its install state.
Any configuration settings made since installation will be lost.
To reset the configuration:
Step 1
Connect to the Clean Access Server by SSH.
Step 2
Delete the
env
file:
# rm /perfigo/access/bin/env
Step 3
Then reboot using:
# service perfigo reboot
You can now add the CAS to the CAM. See the
Cisco NAC Appliance - Clean Access Manager
Configuration Guide, Release 4.8(3)
.
Enabling TLSv1 on Internet Explorer Version 6
Cisco NAC Appliance network administrators managing the CAM/CAS via web console
and
client
machine browsers accessing a FIPS-compliant Cisco NAC Appliance Release 4.8(x) network require
TLSv1 in order to “talk” to the network, which is disabled by default in Microsoft Internet Explorer
Version 6.
To locate and enable this setting in IE version 6:
Step 1
Got to
Tools > Internet Options
.
Step 2
Select the
Advanced
tab.
Step 3
Scroll down to locate the
Use TLS 1.0
option under
Security
.
Step 4
Click on the checkbox to enable the
Use TLS 1.0
. option and click
Apply
.