Table of Contents
Cisco NAC Appliance Switch and Wireless LAN Controller Support
Cisco NAC Appliance Switch Support Matrixes
Known Issues with Switches/WLCs
Cisco Catalyst 3550/3560/3750 and NAC Appliance In-Band Central Deployment
Stacked Cisco Catalyst 3750 Switches and NAC Appliance Out-of-Band Deployment
Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs) and DHCP
Preventing Loops on Central Switch for VGW/Central Deployments
OOB Switch Trunk Ports and Upgrade
Switch Support for CAS Virtual Gateway/VLAN Mapping (IB and OOB)
Switch Support Overview
For all switch models/NMEs, Cisco recommends checking for limitations and verifying support for MAC notification and/or linkup-linkdown SNMP traps for the switch OS version you intend to use. See Known Issues with Switches/WLCs for further details.
Administrators update switch and Wireless LAN Controller (WLC) support object IDs (OIDs) using the update function in the CAM Device Management > Clean Access > Updates web console page. For example, if a new model of a supported switch family is released, Cisco NAC Appliance administrators only need to retrieve an update to ensure the latest support for switch OIDs. (That is, you are not required to upgrade the CAM/CAS software image, itself). The update switch OID feature only applies to existing models. If a new switch series is introduced, administrators will still need to upgrade to ensure OOB support for the new switches. Refer to the “Switch Management” (OOB) chapter of the Cisco NAC Appliance - Clean Access Manager Configuration Guide for details.
Cisco NAC Appliance is agnostic to switch/router platforms and versions. IB deployments can be Layer 2 (L2) or Layer 3 (L3):
- For L2 deployments, user MAC/IP addresses need to be visible to the CAS
- For L3 deployments (i.e. where the CAS can be one or more hops away from the user), the CAS differentiates users by IP address
For Out-of-Band (OOB) Deployments
With Cisco NAC Appliance Out-of-Band deployment, the CAS is inline with user traffic only during the process of authentication, assessment and remediation. Following that, user traffic does not pass through the CAS. In an OOB deployment, the Clean Access Manager (CAM) uses SNMP to control switches and set VLAN assignments for ports. When the CAM/CAS are set up for OOB, the CAM can control the switch ports of supported switches/NMEs with the corresponding minimum IOS/CatOS versions listed in the collection of switch family support tables in Cisco NAC Appliance Switch Support Matrixes.
Cisco NAC Appliance Switch Support Matrixes
The following tables include all Cisco switch models supported with Cisco NAC Appliance for both In-Band and Out-of-Band deployments:
- Table 1 “Supported Cisco Catalyst 2900 XL Switches”
- Table 2 “Supported Cisco Catalyst 2940 Switches”
- Table 3 “Supported Cisco Catalyst 2950 Switches”
- Table 4 “Supported Cisco Catalyst 2955 Switches”
- Table 5 “Supported Cisco Catalyst 2960 Switches”
- Table 6 “Supported Cisco Catalyst 2970 Switches”
- Table 7 “Supported Industrial Ethernet 3000 Switches ,”
- Table 8 “Supported Cisco Catalyst 3500 XL Switches”
- Table 9 “Supported Cisco Catalyst 3550 Switches”
- Table 10 “Supported Cisco Catalyst 3560 Switches”
- Table 11 “Supported Cisco Catalyst 3650 Switches”
- Table 12 “Supported Cisco Catalyst 3750 Switches”
- Table 13 “Supported Cisco Catalyst 3850 Switches”
- Table 14 “Supported Cisco Catalyst 4000/4500 Switches”
- Table 15 “Supported Cisco Catalyst 6000/6500 Switches”
- Table 16 “Supported Cisco Catalyst Express 500 Switches”
- Table 17 “Supported Cisco Etherswitch Service Modules”
- Table 18 “Supported Cisco Wireless LAN Controllers for Wireless Out-of-Band”
![]()
Note Starting from NAC Appliance Release 4.9(0), switches having OID starting with “1.3.6.1.4.1.9” are added to CAM DB as Cisco supported switches. The Cisco switches that have OID starting with “1.3.6.1.4.1.9.xxx” are supported by CAM starting from release 4.9(0).
Table 1 Supported Cisco Catalyst 2900 XL Switches 1
Cisco Catalyst 2908XL switch with 8 10/100BaseTX ports 2
Cisco Catalyst 2916M-XL switch with 16 10/100BaseTX ports and 2 uplink slots
Cisco Catalyst 2924C-XL switch with 22 10BaseT/100BaseTX and 2 100BaseFX autosensing switch ports; supports port-based VLANs
Cisco Catalyst 2924M-XL switch with 24 autosensing 10/100BaseTX ports and 2 uplink slots
Cisco Catalyst 2924XL switch with 24 10/100BaseTX ports w/o port-based VLANs
Cisco Catalyst 2924XL switch with 24 10BaseT/100BaseTX autosensing switch ports; supports port-based VLANs
Cisco Catalyst 2912XL switch (WS-C2912-LRE-XL) with 12 10BaseS VDSL ports and 4 10/100BaseTX ports
Cisco Catalyst 2918 (WS-C2918-24TC) 24 10/100 ports + 2 dual purpose Gigabit Ethernet ports fixed configuration L2 Ethernet switch
Cisco Catalyst 2912MF-XL switch with 12 100BaseFX ports and 2 uplink slots
Cisco Catalyst 2912XL switch with 12 autosensing 10/100BaseTX ports
Cisco Catalyst 2918 (WS-C2918-24TT) 24 10/100 ports + 2 10/100/1000 ports fixed configuration L2 Ethernet switch
Cisco Catalyst 2918 (WS-C2918-48TC) 48 10/100 ports + 2 dual purpose Gigabit Ethernet ports fixed configuration L2 Ethernet switch
Cisco Catalyst 2918 (WS-C2918-48TT) 48 10/100 ports + 2 10/100/1000 Ethernet ports fixed configuration L2 Ethernet switch
Cisco Catalyst 2924XL switch (WS-C2924-LRE-XL) with 24 10BaseS VDSL ports and 4 10/100BaseTX ports
1.Cisco NAC Appliance supports Cisco Catalyst 2900 XL and 3500 XL only until the product (switch) end of support. For details, refer to http://www.cisco.com/en/US/products/hw/switches/prod_category_end_of_life.html.
Cisco Catalyst 2940 L2 switch with 8 10/100 copper ports, 1 100 FX Uplink port and 1 Gigabit SFP Module slot
Cisco Catalyst 2940 L2 switch with 8 10/100 copper ports and 1 10/100/1000 copper uplink port 3
3.Cisco NAC Appliance 4.1(3) and later supports MAC-move notifications from switches. See MAC-Move Notification Support for details.
Catalyst 2960C 8 10/100 POE ports + 2 Gigabit Ethernet POE+ PD ports fixed configuration Layer 2 Ethernet Switch
Catalyst 2960C 8 10/100 ports + 2 Gigabit Ethernet PD ports fixed configuration layer 2 Ethernet Switch
Catalyst 2960C 8 10/100 FE ports + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2 Ethernet switch, Lan Lite only
Catalyst 2960C 8 10/100 FE ports + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2 Ethernet switch
Catalyst 2960C 8 10/100 FE with PoE + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2 Ethernet switch
Catalyst 2960C 12 10/100 FE with POE + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2 Ethernet switch
Catalyst 2960C 8 10/100/1000 ports + 2 dual purpose Gigabit Ethernet ports fixed configuration Layer 2 Ethernet Switch
Catalyst 2960X 48 Gigabit Downlinks, 2 SFP+ uplink, 2 x 10G stacking module, POE+ support for 740W
Catalyst 2960X 48 Gigabit Downlinks, 2 SFP+ uplink, 2 x 10G stacking module, POE+ support for 370W
Catalyst 2960X 48 Gigabit Downlinks, 2 SFP+ uplink, 2 x 10G stacking module
Catalyst 2960X 24 Gigabit Downlinks, 2 SFP+ uplink, 2 x 10G stacking module, POE+ Support for 370W
Catalyst 2960X 24 Gigabit Downlinks, 2 SFP+ uplink, 2 x 10G stacking module
Catalyst 2960X 48 Gigabit Downlinks, 4 SFP uplink with support for a 2 x 10G stacking module, POE+ support for 740W
Catalyst 2960X 48 Gigabit Downlinks, 4 SFP uplink with support for a 2 x 10G stacking module, POE+ support for 370W
Catalyst 2960X 24 Gigabit Downlinks, 4 SFP uplink with support for a 2 x 10G stacking module, POE+ support for 370W
Catalyst 2960X 48 Gigabit Downlinks, 4 SFP uplink with support for a 2 x 10G stacking module
Catalyst 2960X 24 Gigabit Downlinks, 4 SFP uplink with support for a 2 x 10G stacking module
Catalyst 2960X 24 Gigabit Downlinks, 4 SFP uplink Non Stackable
Catalyst 2960X 48 Gigabit Downlinks, 2 SFP uplink Non Stackable, POE+ support for 370W
Catalyst 2960X 24 Gigabit Downlinks, 2 SFP uplink Non Stackable, POE+ support for 370W
Catalyst 2960X 48 Gigabit Downlinks and 2 SFP uplink Non Stackable
Catalyst 2960X 24 Gigabit Downlinks and 2 SFP uplink Non Stackable
Catalyst 2960S 48 Gigabit Downlinks and 2 SFP+ uplink with support for a 2 x 10G stacking module. POE support for 370W
WS-C2960-24 6
Catalyst 2960 24 10/100 ports + 2 dual-purpose GE ports fixed configuration L2 Ethernet switch
Catalyst 2960 8 10/100 Power over Ethernet ports + 16 10/100 Ethernet ports + 2 dual purpose Gigabit Ethernet ports fixed configuration Layer 2 Ethernet switch
Catalyst 2960 8 10/100 ports + 1 dual purpose GE port fixed configuration L2 Ethernet switch
Catalyst 2960 44 10/100/1000 ports + 4 dual-purpose GE ports fixed configuration L2 Ethernet switch
Catalyst 2960 7 10/100/1000 ports + 1 dual purpose GE port fixed configuration L2 Ethernet switch
Catalyst 2960 8 10/100 ports plus 1T PD port Layer 2 Ethernet switch
Catalyst 2960 24 10/100 ports plus 2 dual purpose GE ports fixed configuration Layer 2 Ethernet switch
Catalyst 2960 24 10/100 ports + 2 10/100/1000 ports fixed configuration L2 Ethernet switch
Catalyst 2960 48 10/100 ports + 2 dual-purpose GE ports fixed configuration L2 Ethernet switch
Catalyst 2960 8 10/100 ports + 1 dual purpose Gigabit Ethernet port fixed configuration Layer 2 Ethernet switch
Catalyst 2960 20 10/100/1000 ports + 4 dual-purpose GE ports fixed configuration L2 Ethernet switch
Catalyst 2960S 24 Gigabit Downlinks and 2 SFP+ uplink with support for a 2 x 10G stacking module. POE support for 370W
Catalyst 2960S 24 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module. POE support for 370W
Catalyst 2960 24 10/100 ports, 8 PoE and 2T ports Layer 2 Ethernet switch
Catalyst 2960 24 10/100 PoE ports plus 2 dual purpose GE ports Layer 2 Ethernet switch
Catalyst 2960 24 10/100 Power over Ethernet ports + 2 dual purpose Gigabit Ethernet ports fixed configuration Layer 2 Ethernet switch
Catalyst 2960 48 10/100 PoE ports + 2 10/100/1000 Ethernet Ports + 2 SFP fixed configuration Layer 2 Ethernet switch
Catalyst 2960 48 10/100 Power over Ethernet ports + 2 10/100/1000 Ethernet ports + 2 SFP fixed configuration Layer 2 Ethernet switch
Catalyst 2960 48 10/100 ports plus 2 dual purpose GE ports fixed configuration Layer 2 Ethernet switch
Catalyst 2960 48 10/100 ports + 2 10/100/1000 ports fixed configuration L2 Ethernet switch
Catalyst 2960 48 10/100 ports + 2 10/100/1000 Ethernet ports fixed configuration Layer 2 Ethernet switch
Catalyst 2960S 24 Gigabit Downlinks and 2 SFP+ uplink with support for a 2 x 10G stacking module
Catalyst 2960S 24 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module
Catalyst 2960S 24 Gigabit Downlinks and 2 SFP uplink, Non-stackable module
Catalyst 2960S 48 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module. POE support for 740W
Catalyst 2960S 48 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module. POE support for 740W
Catalyst 2960S 48 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module. POE support for 370W
Catalyst 2960S 48 Gigabit Downlinks and 2 SFP+ uplink with support for a 2 x 10G stacking module
Catalyst 2960S 48 Gigabit Downlinks and 4 SFP uplink with support for a 2 x 10G stacking module
Catalyst 2960 48 Ethernet 10/100/1000 ports + 4 1 Gigabit Ethernet SFP uplink ports
Catalyst 2960S 48 Gigabit Downlinks and 2 SFP uplink, Non-stackable module
6.Cisco NAC Appliance 4.1(3) and later supports MAC-move notifications from switches. See MAC-Move Notification Support for details.
Catalyst 2970 24 10/100/1000 ports + 4 SFP ports L2 Ethernet switch
Catalyst 2970 48 Ethernet 10/100/1000 PoE ports and 4 Small Form-Factor Pluggable (SFP) uplinks
7.IE 3000/3010 switch series are running the same baseline IOS as Catalyst 2960. To add or configure this switch on the CAM, choose Cisco Catalyst 2960 series from the drop-down in the CAM Switch Management > Profiles > Switch > New > Switch Model web console page.
8.For further details on Cisco Industrial Ethernet 3000 / 3010 Series Switches, refer to http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps9703/data_sheet_c78-440930.html and http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps9703/datasheet_c78-637080.html
Table 8 Supported Cisco Catalyst 3500 XL Switches 9
Cisco Catalyst 3508G-XL switch with 8 GBIC Gigabit ports 10
Cisco Catalyst 3512XL switch with 12 10/100BaseTX ports and 2 GBIC Gigabit ports
Cisco Catalyst 3524XLEn switch with 24 10/100 ports and 2 GBIC gigabit ports
Cisco Catalyst 3524XL switch with 24 10/100BaseTX ports and 2 GBIC Gigabit ports
9.Cisco NAC Appliance supports Cisco Catalyst 2900 XL and 3500 XL only until the product (switch) end of support. For details, refer to http://www.cisco.com/en/US/products/hw/switches/prod_category_end_of_life.html.
Cisco Catalyst 3550 10 GBIC + 2 10/100/1000 BaseT ports, fixed configuration layer 2/3 Ethernet switch (WS-C3550-12G)
Cisco Catalyst 3550 12 1000 BaseT ports fixed configuration Layer 2/Layer 3 Ethernet Switch (WS-C3550-12T)
WS-C3550-24 11
Cisco Catalyst 3550 24 10/100 ports + 2 Gigabit uplinks fixed configuration Layer 2/Layer 3 Ethernet Switch (WS-C3550-24)
Cisco Catalyst 3550 24 10/100 BaseTX ports + 2 Gigabit uplinks fixed configuration Layer 2/Layer 3 Ethernet Switch with DC power (WS-C3550-24DC)
Cisco Catalyst 3550 24 10/100 Multimode Fiber ports + 2 Gigabit uplinks fixed configuration Layer 2/Layer 3 Ethernet Switch (WS-C3550-24-MMF)
Cisco Catalyst 3550 24 10/100 ports with inline power and 2 Gigabit uplinks fixed configuration Layer 2/Layer 3 Ethernet Switch (WS-C3550-24-PWR)
Cisco Catalyst 3550 48 10/100 ports + 2 Gigabit uplinks fixed configuration Layer 2/Layer 3 Ethernet Switch (WS-C3550-48)
11.Cisco NAC Appliance 4.1(3) and later supports MAC-move notifications from switches. See MAC-Move Notification Support for details.
Catalyst 3560C 8 10/100 with PoE + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2/Layer 3 Ethernet switch
Catalyst 3560C 12 10/100 with PoE + 2 Gigabit Dual Media Uplinks fixed configuration Layer 2/Layer 3 Ethernet switch
Catalyst 3560C 8 10/100/1000 POE ports + 2 dual purpose Gigabit Ethernet ports fixed configuration Layer 2/Layer 3 Ethernet Switch
Catalyst 3560c 8 10/100/1000 ports + 2 dual purpose Gigabit Ethernet ports fixed configuration Layer 2/Layer 3 Ethernet Switch
Catalyst 3560C 8 10/100/1000 with PoE and 2 Gigabit Copper PoE+ Uplinks fixed configuration Layer 2/Layer 3 Ethernet switch
Catalyst 3560 48 10/100 ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 8 10/100 PoE ports + 1 dual purpose GE port fixed configuration L2/L3 Ethernet switch
Catalyst 3560E 12 SFP Gigabit Ethernet ports + 2 10 Gigabit Ethernet (X2) ports
Catalyst 3560E 24 10/100/1000 PoE ports + 2 X2 ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560E 24 10/100/1000 ports + 2 X2 ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 48 10/100 ports + 4 Ethernet Gigabit SFP ports fixed configuration L2/L3 Ethernet Non-stackable switch
Catalyst 3560E 48 10/100/1000 PoE ports + 2 X2 ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560E 48 10/100/1000 ports + 2 X2 ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 24 10/100/1000 PoE ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 24 10/100/1000 ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 48 10/100/1000 PoE ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 48 10/100/1000 ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560X 24 10/100/1000 Ports + 4 SFP Ports + 2 SFP+ Ports Layer 2/Layer 3 Ethernet Switch
Catalyst 3560X 24 10/100/1000 PoE Ports + 4 SFP Ports + 2 SFP+ Ports Layer 2/Layer 3 Ethernet Switch
Catalyst 3560X 48 10/100/1000 Ports + 4 SFP Ports + 2 SFP+ Ports Layer 2/Layer 3 Ethernet Switch
Catalyst 3560X 48 10/100/1000 PoE Ports + 4 SFP Ports + 2 SFP+ Ports Layer 2/Layer 3 Ethernet Switch
Catalyst 3560E 12 10/100 PoE ports + 1 dual purpose GE port fixed configuration L2/L3 Ethernet switch
Catalyst 3560 24 10/100 ports + 2 Ethernet Gigabit SFP ports fixed configuration L2/L3 Ethernet Non-stackable PoE switch
WS-C3560-24PS 12
Catalyst 3560 24 10/100 PoE ports + 2 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 24 10/100 ports + 2 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 24 10/100 ports + 2 Ethernet Gigabit SFP ports fixed configuration L2/L3 Ethernet Non-stackable switch
Catalyst 3560 24 10/100 ports + 2 Ethernet Gigabit SFP ports fixed configuration L2/L3 Ethernet Non-stackable switch, DC power
Catalyst 3560 48 10/100 PoE ports + 4 GE/SFP ports fixed configuration L2/L3 Ethernet switch
Catalyst 3560 48 10/100 ports + 4 Ethernet Gigabit SFP ports fixed configuration L2/L3 Ethernet Non-stackable PoE switch
12.Cisco NAC Appliance 4.1(3) and later supports MAC-move notifications from switches. See MAC-Move Notification Support for details.
Table 14 Supported Cisco Catalyst 4000/450015 Switches
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2948G CatOS 6
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2948G 6
Cisco Catalyst WS-C2948G Layer 3 switch featuring IP, IPX, and IP multicast with 48 10/100BaseTX ports using DC power
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2948-GGE-TX CatOS 6
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2948G-L320
Cisco Catalyst WS-C2948G-L3 48 port 10/100 Layer 3 switch with 2 GBIC ports
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2980-G CatOS 6
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C2980-GA CatOS 6
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
WS-C4948 21
Cisco Catalyst 4000 with 48 10/100/1000BaseT ports and 4 1000BaseX SFP ports (WS-C4948)
Cisco Catalyst 4948E with 48 10/100/1000-Gbps RJ45 downlink ports and four 1/10 Gigabit Ethernet uplink ports
Cisco Catalyst 4000 with 48 10/100/1000BaseT ports and 2 10 Gbps ports (WS-C4948-10GE)
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst OS Release 7.1 or Cisco IOS Software Release 12.2(31)SGA02
Cisco Catalyst 6000 Series 22
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
760323
Cisco Optical Services Router 7600 Series Chassis with 3 slots
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
7606 2
Cisco Optical Services Router 7600 Series Chassis with 6 slots
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
7609 2
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
7613 2
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6000 Series with 9 slots with CatOS (WS-C6009 CatOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6000 Series Multilevel Switching Feature Card
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6000 Series Multilevel Switching Feature Card Version 2
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6000 Series Multilevel Switching Feature Card Version 2a
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
WS-SVC-SSL-1-K924
Cisco Catalyst 6500 series High-Speed SSL Termination Engine (WS-SVC-SSL-1-K9)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6000 or 6500 Series Multilayer Switch Module (WS-X6302-MSM)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 Series with 6 slots with CatOS (WS-C6506 CatOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 Series with 9 slots with CatOS (WS-C6509 CatOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 Series with 9 slots with CatOS (WS-C6509-NEB CatOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 series with 9 slots (WS-C6509-NEB-A CatOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 series with 9 slots (WS-C6509-NEB-A-IOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst 6500 series with 9 slots Constellation vertical slot chassis (WS-C6509SP-IOS)
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
Cisco Catalyst OS Release 7.5 or Cisco IOS Software Release12.2(33)SXH1
![]()
Note Wireless OOB only supports Layer 2 OOB Virtual Gateway deployments that require no IP address change. The Cisco NAC Network Module (NME-NAC) does not support a Layer 2 OOB Virtual Gateway topology, therefore the Cisco NAC Network Module is not supported for Wireless OOB deployments.
![]()
Note If CAM is using SNMP V3 for write, wireless clients might not move into Access VLAN even when the NAC agent on the client passed posture validation after WLC reboot. Refer to WLC caveat CSCtb78072.
Known Issues with Switches/WLCs
This section describes known issues when integrating Cisco NAC Appliance with the following switch models/wireless LAN controllers and deployment types:
- Cisco Catalyst 3550/3560/3750 and NAC Appliance In-Band Central Deployment
- Stacked Cisco Catalyst 3750 Switches and NAC Appliance Out-of-Band Deployment
- Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs) and DHCP
Cisco Catalyst 3550/3560/3750 and NAC Appliance In-Band Central Deployment
For Cisco NAC Appliance in In-Band Central Deployment mode, when a Cisco Catalyst 3560/3750 series switch is used as a Layer 3 switch and if both ports of the CAS are connected to the same 3560/3750 switch, the minimum switch IOS code required is Cisco IOS release 12.2(25)SEE.
Because caveat CSCdu27506 is not fixed on the Catalyst 3550 series switch, when the Catalyst 3550 is used as a Layer 3 switch, it cannot be used in NAC Appliance In-Band Central Deployment.
For further details, refer to switch IOS caveat CSCdu27506:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCdu27506
See also Switch Support for CAS Virtual Gateway/VLAN Mapping (IB and OOB).
Stacked Cisco Catalyst 3750 Switches and NAC Appliance Out-of-Band Deployment
For Cisco NAC Appliance customers with OOB deployments running stacked Cisco Catalyst 3750 switches with Cisco IOS 12.2(25) SEC2 or lower, SNMP mac-notifications can fail, and SNMP does not report MAC addresses to the OOB CAM and CAS.
Affected customers can resolve this issue by upgrading their stacked Cisco Catalyst 3750 switches to Cisco IOS release 12.2(25)SEE or above. For further details refer to switch IOS caveat CSCeh80716:
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_25_sed/release/notes/OL8113.html#wp821615![]()
Note Catalyst 3750 Stacks are affected by caveats CSCse86236 and CSCsg31176. These caveats are resolved in IOS release 12.2(35)SE.
See Cisco NAC Appliance Switch Support Matrixes for additional details on the switches supported for OOB deployments.
![]()
Note When configuring SNMP settings on switches, never use the “@” character in the community string.
Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs) and DHCP
Due to changes in DHCP server operation with Cisco NAC Appliance release 4.0(2) and later, networks with Cisco 2200/4400 Wireless LAN Controllers (also known as Airespace WLCs) which relay requests to the CAS (operating as a DHCP server) may have issues. Client machines may be unable to obtain DHCP addresses.
If you have DHCP issues with Airespace controllers after installing/upgrading to release 4.0(2), the following will need to be done to restore DHCP functionality:
Step 1
Enable DHCP options on the CAS:
a.
Go to Device Management > CCA Servers > Manage [CAS_IP] > Network > DHCP > Global Options
b.
Click the Enable button (User-Specified DHCP Options).
Step 2
Create a new custom Global DHCP option with option number “54” and option type “IP-Address”:
a.
Click the New Option link for the Root Global Option List.
c.
Select IP-Address from the Type dropdown menu.
d.
Click the Create Custom Option button.
Step 3
Set the value of this option to the CAS eth1 IP address (or eth1 Service IP if CAS is in HA mode):
a.
Type the CAS eth1 IP address in the text field.
Step 4
This should restore DHCP capability with Airespace controllers.
![]()
Note For further details on configuring DHCP options, see the “Configuring DHCP” chapter of the Cisco NAC Appliance - Clean Access Server Configuration Guide.
Troubleshooting
This section discusses the following:
- Preventing Loops on Central Switch for VGW/Central Deployments
- OOB Switch Trunk Ports and Upgrade
- Switch OID Support
- NAC Appliance Device Support
- MAC-Move Notification Support
Preventing Loops on Central Switch for VGW/Central Deployments
In Virtual Gateway Central deployment, both interfaces of the CAS are connected to the same switch. Administrators must use the following procedure for correct configuration of a Virtual Gateway Central Deployment. To prevent looping on any central/core switch as you plug both interfaces of the CAS into the switch, perform the following steps:
1.
Before you connect both interfaces of the CAS to the switch, SSH to the CLI of the CAS and disable the eth1 (untrusted interface) using the CLI command:
2.
Physically connect the eth0 and eth1 interfaces of the CAS to the network.
3.
After you have added the CAS to the CAM web console, make sure to set the VLAN to be mapped under Device Management > CCA Servers > Manage [CAS_IP] > Advanced > VLAN Mapping . Also make sure you check the “ Enable VLAN Mapping ” checkbox and click Update .
4.
For the 802.1q ports configuration on the switch, make sure to prune all other VLANs for switches trunking to eth0 and eth1 of the CAS except those used for the CAS Management VLAN and the User VLANs.
5.
Prune VLAN 1 on the switch ports connecting to the CAS eth0 and eth1 interfaces. For details, see:
http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/software/release/12.1_22ea/SCG/swvlan.html6.
Once the preceding steps are completed, SSH to the CLI of the CAS and enable eth1 on CAS using the CLI command:
See also Switch Support for CAS Virtual Gateway/VLAN Mapping (IB and OOB) for additional information.
OOB Switch Trunk Ports and Upgrade
Because Cisco NAC Appliance can control switch trunk ports for OOB, ensure that the uplink ports for controlled switches are configured as “uncontrolled” ports before or after upgrade. This can be done in one of two ways:
- Before upgrading, change the Default Port Profile for the entire switch to “uncontrolled” under Switch Management > Devices > Switches > List > Config[Switch_IP] > Default Port Profile | uncontrolled , or
- After upgrading, change the Profile to “uncontrolled” for the applicable uplink ports of the switch under Switch Management > Devices > Switches > List > Ports [Switch_IP] | Profile
This will prevent unnecessary issues when the Default Port Profile for the switch has been configured as a managed/controlled port profile
If for some reason the above steps are omitted and the switch becomes disconnected, use the following procedure:
1.
Delete the switch from the List of Switches in the CAM (under Switch Management > Devices > Switches > List ).
2.
Configure the switch using its CLI to reverse the changes made to the uplink port by the CAM (trunk native VLAN and mac-notification), for example:
3.
Add the switch back to the CAM (under Switch Management > Devices > Switches > New or Search ), applying “uncontrolled” as the Default Port Profile.
4.
Specifically assign the “uncontrolled” port Profile to the uplink port and other uncontrolled ports (under Switch Management > Devices > Switches [x.x.x.x] > Ports ).
5.
Reset the Default Port Profile for the switch (under Switch Management > Devices > Switches [x.x.x.x] > Config ).
6.
Initialize the switch ports (under Switch Management > Devices > Switches [x.x.x.x] > Ports ).
Switch OID Support
Administrators can update the object IDs (OIDs) of supported switches by performing a CAM update (under Device Management > Clean Access > Updates ). For example, if a new switch (such as C3750-XX-NEW) of a supported model (Catalyst 3750 series) is released, administrators only need to perform Cisco Updates on the CAM to obtain support for the switch OIDs, instead of performing a software upgrade of the CAM/CAS. The update switch OID feature only applies to existing models. If a new switch series is introduced, administrators will still need to upgrade to ensure OOB support for the new switches.
Starting from Release 4.5, administrators can also update the object IDs (OIDs) of Wireless LAN Controller platforms supported for the Wireless OOB feature by performing a CAM update.
Before opening a support case for Switch OID support
1.
On the CAM go to Device Management > Clean Access > Updates . Make sure to perform an Update and verify the current version of the “Supported Out-of-Band Switch OIDs.”
2.
If the switch still cannot be managed from the CAM, get the OID from the switch by running the following command from the CAM:
NAC Appliance Device Support
Cisco NAC Appliance Release 4.9 has Universal Switch Support that makes it possible for Cisco NAC Appliance to support any Cisco Switch as long as it supports the MIBs that are used by NAC. The Universal Device Support is limited only to Cisco Switches and non-Cisco Switches are not supported.
Starting from Cisco NAC Appliance Release 4.9, you can view the list of supported devices and check whether a device supports the MIBs that are used by NAC.
In the CAM Web Console, go to OOB Management > Profiles > Device > New . You can click the link available at the top of this tab to view the list of supported device models.
You can verify whether a device is supported by using the Verify tab. This utility verifies a device already added to CAM or a new device that is yet to be added to CAM. This option is available in the CAM Web Console in OOB Management > Devices > Devices > Verify tab.
Refer to Cisco NAC Appliance - Clean Access Server Configuration Guide, Release 4.9 for more details.
MAC-Move Notification Support
Starting from Release 4.1(3), Cisco NAC Appliance supports MAC-move notifications from switches in addition to the MAC-changed notification and linkup/linkdown SNMP traps.
Table 19 lists the switch models and OS versions that support the MAC-Move notification.
Refer to the Release Notes for Cisco NAC Appliance, Version 4.1(3) for additional details.
Switch Support for CAS Virtual Gateway/VLAN Mapping (IB and OOB)
Table 20 describes Cisco Catalyst switch model support for the Virtual Gateway VLAN Mapping feature of the CAS for either in-band (IB) or out-of-band deployments (OOB). This table is intended to clarify CAS network deployment options when connecting the CAS in Virtual Gateway (bridge) mode to the switches listed.
Table 20 Switch Support for CAS Virtual Gateway In-Band/OOB VLAN Mapping Feature
Yes with 12.2(25) SEE and higher 1
No 27
No 1
Yes with 12.2(25) SEE and higher 28
27.2900 XL does not support removing VLAN 1 from switch trunks.
28.Due to switch caveat CSCdu27506. See Cisco Catalyst 3550/3560/3750 and NAC Appliance In-Band Central Deployment for details.
For additional information on Virtual Gateway Central Deployment, see also Preventing Loops on Central Switch for VGW/Central Deployments.