Reset Search
 

 

Article

NAC Manager Loses Contact with NAC Appliance After Change of Internal Communication Certificate.

« Go Back

Information

 
TitleNAC Manager Loses Contact with NAC Appliance After Change of Internal Communication Certificate.
Symptoms
  • NAC Manager Loses Contact with NAC Appliance After Change of Internal Communication Certificate.
  • Errors in NetSight server.log containing the following phrase:
    server certificate change is restrictedduring renegotiation

 

 
Environment
NetSight v6.3.x.x
 
Cause
  • Correction to the NetSight SSL module to combat the Poodle vulnerability
  • Certificates no longer allowed to be re-hashed midstream in communication
Resolution
Resolution 1:
  1. Restart the NAC appliance first
  2. Restart the Netsight appliance



Resolution 2:

If you are experiencing intermittent contact lost in NAC Manger to your NAC appliances and the same error is seen in the server.log regarding certificate renegotiation check to make sure there are no incorrect reverse records for the NAC/NetSight appliances in the configured DNS server. This typically occurs when more than one NAC is present

  1. Gather all Internal Certificate information from the NAC appliances by right clicking the NAC appliances in NAC Manager -> Webview -> Diagnostics -> Certificate Diagnostics 
  2. Note the Server Certificate name for each appliance.
  3. SSH to the NetSight appliance 
  4. Run the following command to perform a reverse DNS lookup on the NAC's IP address
    nslookup <ip_of_NAC>
  5. From the results shown verify that the name you have gathered in step 1 matches the result of the nslookup. If there are any other records return, remove them from the reverse DNS zone of the DNS server.
  6. If the FQDN returned from the nslookup is not an exact match of the CN and Domain on the NAC's internal certificate it will cause issues with NetSight/NAC communication with the above error message. Remove the reverse lookup, or correct the reverse record to reply with the correct CN and domain.
Additional notes
NOTE: The incorrect spacing of the words in the Error text is intentional.  This is exactly as displayed. 

NOTE: Additional symptoms of this occurring after adding a new NAC appliance
    NAC Appliance green in NetSight Console
    NAC Appliance red in NAC Manager
    Enforce of new appliance fails with error message "NAC Appliance is Unreachable"

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255