<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CoA not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574146#M503928</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot truly bounce the port and have the phone stay connected without a reconnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jun 2018 20:22:37 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-06-22T20:22:37Z</dc:date>
    <item>
      <title>CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574143#M503920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Configuring the MAB for IP phone was successful and I can get the IP phones to a right voice VLAN using the authz profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Now what happens is that, when I connect a computer behind the IP phone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Authentication is successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Goes for compliance check&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;Comes out of compliant&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;But,when I check ISE live logs, it still shows :&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" class="content_table" style="font-size: 12px; font-family: Arial; background-color: #fafafa; border: 1px solid #ffffff; color: #333333;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666; border-top: none;" width="33%"&gt;ConfigVersionId&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666; border-top: none;" width="67%"&gt;7199&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Device CoA type&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;RFC 5176&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Device CoA port&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;3799&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;NetworkDeviceProfileId&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;26b0501b-9e48-48c7-b8c4-99a0e791bcca&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;IsThirdPartyDeviceFlow&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;true&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;HP-Port-Bounce-Host&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;AcsSessionID&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;58d8f8f8-04f7-451b-bc21-3d36b63adfe2&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;CoASourceComponent&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;Posture&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;CoAReason&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;posture status changed&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;CoAType&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;Reauthentication&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Network Device Profile&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;HPWired_CoA_Bounce_H3C&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Software Version&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;Unknown&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Location&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;Location#All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="background: #f5f5f5;"&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Device Type&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;Device Type#All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border-left: none; font-weight: bold; color: #666666;" width="33%"&gt;Device IP Address&lt;/TD&gt;&lt;TD style="padding: 5px; color: #666666;" width="67%"&gt;10.226.232.23&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;But the computer shows that its limited connectivity.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;If I connect the computer directly to the switch port, computer goes to compliant state and access is granted as per the policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;I am using the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;SPAN style="font-style: inherit; font-family: georgia, palatino; font-weight: inherit;"&gt;ISE ver &lt;SPAN style="font-weight: bold; font-style: inherit; font-size: 14px; color: #39393b;"&gt;2.3.0.298 patch 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;SPAN style="font-style: inherit; font-family: georgia, palatino; font-weight: inherit;"&gt;Switch Hp H3C Comware 7&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-family: georgia, palatino;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: georgia, palatino; font-weight: inherit;"&gt;Port config:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/5&lt;/P&gt;&lt;P&gt; port link-type hybrid&lt;/P&gt;&lt;P&gt; undo port hybrid vlan 1&lt;/P&gt;&lt;P&gt; port hybrid vlan 230 untagged&lt;/P&gt;&lt;P&gt; port hybrid pvid vlan 230&lt;/P&gt;&lt;P&gt; voice-vlan 260 enable&lt;/P&gt;&lt;P&gt; mac-vlan enable&lt;/P&gt;&lt;P&gt; undo stp enable&lt;/P&gt;&lt;P&gt; stp edged-port&lt;/P&gt;&lt;P&gt; undo lldp enable&lt;/P&gt;&lt;P&gt; port bridge enable&lt;/P&gt;&lt;P&gt; poe enable&lt;/P&gt;&lt;P&gt; undo dot1x handshake&lt;/P&gt;&lt;P&gt; dot1x handshake reply enable&lt;/P&gt;&lt;P&gt; undo dot1x multicast-trigger&lt;/P&gt;&lt;P&gt; dot1x unicast-trigger&lt;/P&gt;&lt;P&gt; dot1x re-authenticate server-unreachable keep-online&lt;/P&gt;&lt;P&gt; mac-authentication re-authenticate server-unreachable keep-online&lt;/P&gt;&lt;P&gt; mac-authentication host-mode multi-vlan&lt;/P&gt;&lt;P&gt; mac-authentication parallel-with-dot1x&lt;/P&gt;&lt;P&gt; port-security port-mode userlogin-secure-or-mac-ext&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: georgia, palatino;"&gt;Is there something that I am missing here?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino; font-size: 10pt;"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: georgia, palatino; font-size: 10pt;"&gt;Thank you,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt; font-family: georgia, palatino;"&gt;Dinesh&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574143#M503920</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-21T14:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574144#M503923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If bouncing the port as part of 3rd-party CoA, you could be bouncing phone connection which will cause PC to lose link.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 16:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574144#M503923</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-21T16:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574145#M503925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case, the phone stays connected.&lt;/P&gt;&lt;P&gt;It the computer that stays in the limited connectivity, it is as if like switch recieved the bounce or re-auth for the, but since there are two domains, it does not whom to send the re-auth to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that something observed before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 06:25:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574145#M503925</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-22T06:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574146#M503928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot truly bounce the port and have the phone stay connected without a reconnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 20:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574146#M503928</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-22T20:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574147#M503930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there something missing from the configuration then?&lt;/P&gt;&lt;P&gt;Since I can see that, the computer gets compliant, but then stays in limited connectivity.&lt;/P&gt;&lt;P&gt;Also, I can see that ISE shows it as compliant, but nothing happens at the computer's end...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, if I connect the same machine directly to the switch port, all works fine, the computer gets compliant and gets full access as per the authz &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2018 07:27:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574147#M503930</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-06-25T07:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574148#M503932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it seems there is not session stitching post CoA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please attach the live logs page ( including the steps section)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 12:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3574148#M503932</guid>
      <dc:creator>smashash</dc:creator>
      <dc:date>2018-07-02T12:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3685578#M503933</link>
      <description>&lt;DIV id="messageBodyDisplay_13" class="lia-message-body lia-tooltip-trigger"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;It turned out that, the issue was the policy was itself.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Since NAM is being used to perform EAP chaining, the user and machine authentication was happening, but the policy was disabled during some troubleshooting session.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Causing all the endpoints to go the MAB and failed as they were not IP phones (as configured on the authorization policy).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;FONT face="terminal,monaco" size="3"&gt;Rectified the issue and since then were able to run authentication and posture just fine on the HP switch.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;Thanks for all the pointers, I think they can be very well used while troubleshooting posture issues.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;We have requested another switch of the same model, so that we are sure about the testing that we conducted earlier.&lt;/FONT&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-panel lia-panel-standard MessageTagsTaplet Chrome lia-component-message-view-widget-tags"&gt;&amp;nbsp;
&lt;P&gt;&lt;FONT face="terminal,monaco" size="3"&gt;This case is deemed closed now!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-not-working/m-p/3685578#M503933</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-08-10T07:13:14Z</dc:date>
    </item>
  </channel>
</rss>

