<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3081293#M23695</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've managed to Solve this issue, i've changed the authentication profile on ISE .&lt;/P&gt;
&lt;P&gt;we were using eap-fast, and for some reason eap chaining was not enabled. once i've enabled it, it started working fine.&lt;/P&gt;</description>
    <pubDate>Sun, 30 Apr 2017 09:30:16 GMT</pubDate>
    <dc:creator>snir_orlanczyk</dc:creator>
    <dc:date>2017-04-30T09:30:16Z</dc:date>
    <item>
      <title>ISE 2.2 COA fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3081292#M23694</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have installed Cisco ISE 2.2 as our NAC system.&lt;/P&gt;
&lt;P&gt;After Posturing the ISE send a COA packet to the 2960-X switch.&lt;/P&gt;
&lt;P&gt;But we see COA failed with the following result:&lt;/P&gt;
&lt;H3 class="title"&gt;Result&lt;/H3&gt;
&lt;TABLE class="content_table" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;RadiusPacketType&lt;/TD&gt;
&lt;TD id="eapKey" width="69%"&gt;CoANAK&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Reply-Message&lt;/TD&gt;
&lt;TD id="eapKey" width="69%"&gt;No valid Session&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Error-Cause&lt;/TD&gt;
&lt;TD id="eapKey" width="69%"&gt;Session Context Not Found&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Our Switch configuration:&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server radius radius_ISE-PSN&lt;BR /&gt; server name ISE-PSN-01&lt;BR /&gt; server name ISE-PSN-02&lt;BR /&gt;aaa authentication dot1x default group radius_ISE-PSN&lt;BR /&gt;aaa authorization network default group radius_ISE-PSN &lt;BR /&gt;aaa accounting delay-start all&lt;BR /&gt;aaa accounting update periodic 120&lt;BR /&gt;aaa accounting auth-proxy default start-stop group radius_ISE-PSN&lt;BR /&gt;aaa accounting dot1x default start-stop group radius_ISE-PSN&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt; client 1.1.1.1&lt;BR /&gt; client &lt;SPAN&gt;1.&lt;/SPAN&gt;&lt;SPAN&gt;1.1.2&lt;/SPAN&gt;&lt;BR /&gt;server-key&amp;nbsp;&amp;lt;KEY&amp;gt;&lt;BR /&gt; auth-type all&lt;BR /&gt;aaa session-id common&lt;/P&gt;
&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf upper-case&lt;BR /&gt;radius-server attribute 31 send nas-port-detail mac-only&lt;/P&gt;
&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server retransmit 5&lt;BR /&gt;radius-server deadtime 10&lt;BR /&gt;radius-server accounting system host-config&lt;BR /&gt;radius server ISE-PSN-01&lt;BR /&gt; address ipv4 1.1.1.1&amp;nbsp;auth-port 1645 acct-port 1646&lt;BR /&gt; key&amp;nbsp;&amp;lt;KEY&amp;gt;&lt;BR /&gt;radius server ISE-PSN-02&lt;BR /&gt; address ipv4 1&lt;SPAN&gt;1.1.1.2&lt;/SPAN&gt;&amp;nbsp;auth-port 1645 acct-port 1646&lt;BR /&gt; key &lt;SPAN&gt;&amp;lt;KEY&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/0/21&lt;BR /&gt; switchport access vlan&amp;nbsp;1&lt;BR /&gt; switchport mode access&lt;BR /&gt; authentication host-mode multi-host&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;show version &lt;BR /&gt;Cisco IOS Software, C2960X Software (C2960X-UNIVERSALK9-M), Version 15.0(2)EX4&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any ideas why the COA fails?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3081292#M23694</guid>
      <dc:creator>snir_orlanczyk</dc:creator>
      <dc:date>2019-03-11T07:30:48Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3081293#M23695</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've managed to Solve this issue, i've changed the authentication profile on ISE .&lt;/P&gt;
&lt;P&gt;we were using eap-fast, and for some reason eap chaining was not enabled. once i've enabled it, it started working fine.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 09:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3081293#M23695</guid>
      <dc:creator>snir_orlanczyk</dc:creator>
      <dc:date>2017-04-30T09:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 COA fails</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3350476#M23696</link>
      <description>&lt;P&gt;In my environment we are not using ERP-FAST configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Mar 2018 14:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-coa-fails/m-p/3350476#M23696</guid>
      <dc:creator>rajesh.mohapatra1</dc:creator>
      <dc:date>2018-03-18T14:17:41Z</dc:date>
    </item>
  </channel>
</rss>

