<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HP switch with ISE - port bounce does not happen in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675219#M495954</link>
    <description>&lt;P&gt;Yes, we had tried this with SNMP CoA as well, but there was no success. Now we are trying to use the port bounce profile and a weird thing happened.&lt;/P&gt;
&lt;P&gt;When I unchecked the port-bounce from the network device profile, the endpoint became compliant and got full access.&lt;/P&gt;
&lt;P&gt;So just to check again, I rebooted the computer, and since then, its stuck in a loop, wherein NAM keeps asking for credentials and endpoint goes back to MAB and gets a deny access...&lt;/P&gt;
&lt;P&gt;Has anyone faced such an issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For further troubleshooting of this issue, I will try andanget a HP engineer involved and see what I can do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2018 10:28:58 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2018-07-26T10:28:58Z</dc:date>
    <item>
      <title>HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3674453#M495952</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am facing issue where in I see that a computer connected to a HP switch, goes through authentication and then posture checks.&lt;BR /&gt;Comes up as compliant, but the final access is not applied to the port.&lt;/P&gt;
&lt;P&gt;I feel that the port-bounce is not going through...&lt;/P&gt;
&lt;P&gt;I am using the community provided NAD profile for named as HPWired_CoA_Bounce&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Following the complete configuration:&lt;/P&gt;
&lt;P&gt;ISE&amp;nbsp;&lt;SPAN&gt;2.3.0.298 with patch 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NAM module for EAP Chaining (AnyConnect version 4.5.04029)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HP&amp;nbsp;HPE Comware Software, Version 7.1.070, Release 3208P03&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HP Device profile that I am using with port bounce:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HP Config.jpg" style="width: 406px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/15294i71751B35C6914D09/image-size/large?v=v2&amp;amp;px=999" role="button" title="HP Config.jpg" alt="HP Config.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Port configuration deployed:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet1/0/5&lt;BR /&gt; port link-type hybrid&lt;BR /&gt; undo port hybrid vlan 1&lt;BR /&gt; port hybrid vlan 230 untagged&lt;BR /&gt; port hybrid pvid vlan 230&lt;BR /&gt; undo voice-vlan mode auto&lt;BR /&gt; voice-vlan 260 enable&lt;BR /&gt; mac-vlan enable&lt;BR /&gt; undo stp enable&lt;BR /&gt; stp edged-port&lt;BR /&gt; undo lldp enable&lt;BR /&gt; port bridge enable&lt;BR /&gt; poe enable&lt;BR /&gt; undo dot1x handshake&lt;BR /&gt; dot1x handshake reply enable&lt;BR /&gt; dot1x mandatory-domain ciscoise&lt;BR /&gt; undo dot1x multicast-trigger&lt;BR /&gt; dot1x unicast-trigger&lt;BR /&gt; dot1x re-authenticate server-unreachable keep-online&lt;BR /&gt; mac-authentication domain ciscoise&lt;BR /&gt; mac-authentication re-authenticate server-unreachable keep-online&lt;BR /&gt; mac-authentication host-mode multi-vlan&lt;BR /&gt; mac-authentication parallel-with-dot1x&lt;BR /&gt; port-security port-mode userlogin-secure-or-mac-ext&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Following snap showing endpoint compliant, but no port-bounce:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="not so compliant.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/15297iA590E47607D5BB08/image-size/large?v=v2&amp;amp;px=999" role="button" title="not so compliant.jpg" alt="not so compliant.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any pointers or assistance much appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 15:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3674453#M495952</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-25T15:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675018#M495953</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;We see the coa sent by ise.&lt;BR /&gt;I've done very few deployment of ise with HP network devices.&lt;BR /&gt;You can try with the nad profile  HP_Wired_SNMP_CoA which will use snmp oid to bounce the port.&lt;BR /&gt;&lt;BR /&gt;If still not working, you have no choice to call HP to ask what command or snmp oid or dictionary needs to be configured to get a port bounce.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 26 Jul 2018 04:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675018#M495953</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-07-26T04:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675219#M495954</link>
      <description>&lt;P&gt;Yes, we had tried this with SNMP CoA as well, but there was no success. Now we are trying to use the port bounce profile and a weird thing happened.&lt;/P&gt;
&lt;P&gt;When I unchecked the port-bounce from the network device profile, the endpoint became compliant and got full access.&lt;/P&gt;
&lt;P&gt;So just to check again, I rebooted the computer, and since then, its stuck in a loop, wherein NAM keeps asking for credentials and endpoint goes back to MAB and gets a deny access...&lt;/P&gt;
&lt;P&gt;Has anyone faced such an issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For further troubleshooting of this issue, I will try andanget a HP engineer involved and see what I can do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 10:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675219#M495954</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-26T10:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675663#M495955</link>
      <description>Have you tried removing the posture xml file from anyconnect folder and test it using a fresh config?</description>
      <pubDate>Thu, 26 Jul 2018 18:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3675663#M495955</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-07-26T18:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3676033#M495956</link>
      <description>&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;I haven't thought of removing posture.xml and testing it. Will try this out and post results.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;Just as a note, what does the posture.xml store?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;Does it store the details about the last PSN contacted for performing posture and updates?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="georgia, palatino" size="3"&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 07:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3676033#M495956</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-27T07:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3676661#M495957</link>
      <description>Yes the xml has information of PSN where the laptop connects to to get their check/update.&lt;BR /&gt;&lt;BR /&gt;Have you also installed DART on the client to get logs on what's happening on the device.</description>
      <pubDate>Sat, 28 Jul 2018 02:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3676661#M495957</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2018-07-28T02:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3677171#M495958</link>
      <description>&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;I need to check that, since the machine is on the other end of the planet.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;Will have that checked and post it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="georgia,palatino" size="3"&gt;Thank you,&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 06:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3677171#M495958</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-07-30T06:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: HP switch with ISE - port bounce does not happen</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3685573#M495959</link>
      <description>&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;It turned out that, the issue was the policy was itself.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Since NAM is being used to perform EAP chaining, the user and machine authentication was happening, but the policy was disabled during some troubleshooting session.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Causing all the endpoints to go the MAB and failed as they were not IP phones (as configured on the authorization policy).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Rectified the issue and since then were able to run authentication and posture just fine on the HP switch.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Thanks for all the pointers, I think they can be very well used while troubleshooting posture issues.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;This case is deemed closed now!&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-switch-with-ise-port-bounce-does-not-happen/m-p/3685573#M495959</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-08-10T07:08:23Z</dc:date>
    </item>
  </channel>
</rss>

