Specifications

2-7
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 2 Device Management: Adding Clean Access Servers, Adding Filters
Working with Clean Access Servers
Step 4 If you want to first test whether or not the CAM is able to authorize and connect to the CAS(s) in your
network, click Test CCA Server Authorization to test connection with the CASs you include in the
Authorized CCA Servers list. The CAM generates SSL Connection log messages that you can view in
the CAM Monitoring > Event Logs web console page after you click Update in step 5.
Step 5 Click Update to ensure the CAS(s) you have added become part of the group of servers authorized to
communicate back-and-forth with the CAM.
When you click Update, the CAM restarts services between the CAM and all CASs in the Authorized
CCA Server list, which may cause brief network interruptions to users logged into the Cisco NAC
Appliance system.
If you enabled the Test CCA Server Authorization option and there are one or more Clean Access
Servers in the Authorized CCA Server list to which the CAM is unable to connect, warning (yellow
flag) messages appear in the event log.
If you did not enable the Test CCA Server Authorization option and there are one or more Clean
Access Servers in the Authorized CCA Server list to which the CAM is unable to connect, error (red
flag) messages appear in the event log.
See View Logs, page 13-4 for more information.
Check Clean Access Server Status
The operational status of each Clean Access Server appears in the Status column:
Connected—The CAM can reach the CAS successfully.
Not connected—The CAS is rebooting, or the network connection between the CAM and CAS is
broken.
If the Clean Access Server has a status of Not connected unexpectedly (that is, it is not down for
standard maintenance, for example), try clicking the Manage icon to force a connection attempt. If
successful, the status changes to Connected. Otherwise, check for a connection problem between the
CAM and CAS and make sure the CAS is running. If necessary, try rebooting the CAS.
Note The Clean Access Manager monitors the connection status of all configured Clean Access Servers. The
CAM will try to connect a disconnected CAS every 3 minutes.
Disconnect a Clean Access Server
When a Clean Access Server is disconnected, it displays Not Connected status but remains in the Clean
Access Manager domain. You can always click Manage to connect the CAS and configure it.
Additionally, if at any point the Clean Access Server is out of sync with the Clean Access Manager, you
can disconnect the Clean Access Server then reconnect it. The Clean Access Manager will again publish
the data configured for the Clean Access Server and keep the CAS in sync.
In contrast, if you delete the Clean Access Server, all secondary configuration settings are lost.