<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unless something dramatic has in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092667#M25457</link>
    <description>&lt;P&gt;Unless something dramatic has changed in the code, the N1Kv does not support CoA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010111.html#task_ECEA0697E37149238F54C051B97F0306"&gt;CLI(SSH)&lt;/A&gt; instead.&amp;nbsp; That is a link to ISE 2.1 documentation, but the steps are identical in 2.3. &lt;/P&gt;
&lt;P&gt;If you simply need the N1Kv to be aware of changes you have made in ISE configuration (such as in the TrustSec Matrix or SGACL, which would normally be pushed to a device via CoA), you can use a simple CLI command in NX-OS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 107%; font-family: 'Anonymous Pro'; color: #7030a0;"&gt;N1kv# cts refresh role-based-policy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 13 Aug 2017 17:57:19 GMT</pubDate>
    <dc:creator>jonathan.cuthbert</dc:creator>
    <dc:date>2017-08-13T17:57:19Z</dc:date>
    <item>
      <title>ISE 2.3 Trustsec Configuration for Nexus 1000v</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092666#M25456</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am struggeling with the configuration of my Nexus 1000. In the&amp;nbsp;Cisco TrustSec Quick Start Configuration Guide, in the section Defining TrustSec Devices within ISE it is mentioned to configure the option "Send configuration changes to device" to use CoA.&lt;/P&gt;
&lt;P&gt;There is a following note "The step above configures communication between the 3650 and ISE. The step must be repeated to configure the communication between the Nexus1000v and ISE."&lt;/P&gt;
&lt;P&gt;But it seems the Nexus is not capable of receiving CoA messages. Because ISE is giving me this error "11213 No response received from Network Access Device after sending a Dynamic Authorization request "&lt;/P&gt;
&lt;P&gt;How can I&amp;nbsp;update changes of&amp;nbsp;my policies to the Nexus 1000v?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for your feedback&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092666#M25456</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2019-03-11T07:56:09Z</dc:date>
    </item>
    <item>
      <title>Unless something dramatic has</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092667#M25457</link>
      <description>&lt;P&gt;Unless something dramatic has changed in the code, the N1Kv does not support CoA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010111.html#task_ECEA0697E37149238F54C051B97F0306"&gt;CLI(SSH)&lt;/A&gt; instead.&amp;nbsp; That is a link to ISE 2.1 documentation, but the steps are identical in 2.3. &lt;/P&gt;
&lt;P&gt;If you simply need the N1Kv to be aware of changes you have made in ISE configuration (such as in the TrustSec Matrix or SGACL, which would normally be pushed to a device via CoA), you can use a simple CLI command in NX-OS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; line-height: 107%; font-family: 'Anonymous Pro'; color: #7030a0;"&gt;N1kv# cts refresh role-based-policy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 17:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092667#M25457</guid>
      <dc:creator>jonathan.cuthbert</dc:creator>
      <dc:date>2017-08-13T17:57:19Z</dc:date>
    </item>
    <item>
      <title>Hi Jonathan, </title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092668#M25458</link>
      <description>&lt;P&gt;Hi Jonathan,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your reply, just testing while I am writing this lines.&lt;/P&gt;
&lt;P&gt;I assume this is also valid for the Neus 5K switches.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 18:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-trustsec-configuration-for-nexus-1000v/m-p/3092668#M25458</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2017-08-13T18:10:02Z</dc:date>
    </item>
  </channel>
</rss>

