CLEANACCESS Archives

October 2007

CLEANACCESS@LISTSERV.MIAMIOH.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
"Speight, Howard" <[log in to unmask]>
Reply To:
Cisco Clean Access Users and Administrators <[log in to unmask]>
Date:
Fri, 19 Oct 2007 15:57:09 -0400
Content-Type:
multipart/mixed
Parts/Attachments:
text/plain (1443 bytes) , IPv6-Mac.jpg (163 kB) , CCA_SSL_error.jpg (32 kB) , CCA-Version.jpg (98 kB)
Anyone know if IPv6 mac can be blocked in CCA?

CCA 4.1.1, Agent 4.1.2.2 (required upgrade)

Here's the scenario:

Vista machine broadcasting IPv6 DNS service causing lookups to fail. I
tried blocking the Mac as it was listed on my computer, but received
invalid mac address/range format. By the way I blocked the IPv4 Mac in
CCA that was broadcasting the IPv6 DNS and the IPv6 is still
broadcasting. Makes me wonder what CCA is (or not) doing with IPv6
traffic, it certainly wasn't authenticated.

Our students were out on Monday and (patch) Tuesday, when they came back
on Wednesday the phones started ringing and the lines started forming.
The SSL error is killing us, through trial and error doing the following
allows the machine to login.

Go into Network and Sharing Center, Manage Network Connections, Right
click Local Area Connection

Uncheck Internet protocol Version 6 (TCP/IPv6), OK all windows, Reboot 

While the client machine is rebooting physically remove the login entry
from CCA manager interface to allow a "clean" login

This works without changing any other settings in IE or clearing SSL
cache or Web browser cache. It is important that the machine be rebooted
to put the machine in the right "frame of mind."

I tried doing an IPCONFIG /FLUSHDNS from a command prompt without
rebooting and received the SSL error, you need to reboot.

I have a TAC case open (SR 606961737), but will probably open a new one
just for dealing with IPv6 on Monday...

Howard


ATOM RSS1 RSS2