<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CoA Terminate in Hotspot portal is not initiating DHCP refresh in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471680#M530659</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured my hotspot portal to send CoA terminate so that I could push guest on Wired to different VLAN but I dont see a session terminated of wired endpoint and the endpoint do not refresh their IPs in the new VLAN.&lt;/P&gt;&lt;P&gt;Is CoA Terminate same as CoA PortBounce ?&lt;/P&gt;&lt;P&gt;It does not look like from the packet capture as it does not have port-bounce cisco AVP attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I issue a CoA Port Bounce from ISE the endpoints come in the correct IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that in the past Jason has mentioned that Vlan change is not recommended in guest portals due to inconsistency but I thought CoA Terminate should still be able to bounce the port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Mar 2017 22:17:58 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2017-03-16T22:17:58Z</dc:date>
    <item>
      <title>CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471680#M530659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured my hotspot portal to send CoA terminate so that I could push guest on Wired to different VLAN but I dont see a session terminated of wired endpoint and the endpoint do not refresh their IPs in the new VLAN.&lt;/P&gt;&lt;P&gt;Is CoA Terminate same as CoA PortBounce ?&lt;/P&gt;&lt;P&gt;It does not look like from the packet capture as it does not have port-bounce cisco AVP attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I issue a CoA Port Bounce from ISE the endpoints come in the correct IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that in the past Jason has mentioned that Vlan change is not recommended in guest portals due to inconsistency but I thought CoA Terminate should still be able to bounce the port.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Mar 2017 22:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471680#M530659</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-16T22:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471681#M530660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Investigating&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471681#M530660</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-03-17T15:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471682#M530661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attached are also the packet captures for CoA PortBounce and CoA Terminate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:37:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471682#M530661</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-17T15:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471683#M530662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; Terminate will not trigger IP refresh as host without agent/supplicant will not detect without link state change.&amp;nbsp; If willing to send port bounce in all cases where session terminate is normally sent, then it would be possible to manipulate the NAD profile used for these wired switches so that terminate always results in port bounce.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 16:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471683#M530662</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-17T16:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471684#M530663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;The key use case was wireless &lt;/SPAN&gt;&lt;SPAN style="font-size: 14.666666984558105px;"&gt;hotspot issues present before ISE 2.1 patch 1&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt;. The problem was that we &lt;/SPAN&gt;&lt;SPAN style="font-size: 14.666666984558105px;"&gt;would&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt;"&gt; send a terminate after accepting an AUP.&amp;nbsp; This caused the device to go through and scan SSID list and DHCP over and took upwards of 30 seconds. If there was a more preferred network higher in the scan list then it would try to connect to that instead. We added the ability in hotspot portal to send a re-auth which alleviated this problem.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 11pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 16:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471684#M530663</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-03-17T16:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471685#M530664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig. Which of the below options should I change for Terminate to send Port Bounce ? &lt;/P&gt;&lt;P&gt;Also do you think there are any disadvantages of making this change which could affect some other areas ?&lt;/P&gt;&lt;P&gt;It is for a big ISE/TrustSec customer so want to make sure that we dont break any working scenario. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105427_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 18:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471685#M530664</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-17T18:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471686#M530665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason I am testing this in wired and hence I do not see any difference in the behaviour between CoA Reauth and CoA Terminate. Even the packet captures of CoA Disconnect seem similar.&lt;/P&gt;&lt;P&gt;How are you telling the WLC to behave differently between these two options ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 18:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471686#M530665</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-17T18:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471687#M530666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not telling the WLC to behave differently, its up to the hotspot portal to send a re-auth or disconnect, sorry it doesn’t work the same for wired side. It would be a nice enhancement to set this per portal.  I know craig has some enhancement ideas around that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 18:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471687#M530666</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-03-17T18:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471688#M530667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would need to duplicate the Cisco profile and assign it to the NAD in question.&amp;nbsp; The tricky part is that you need to make sure you set this NAD Profile in the AuthZ Profile.&amp;nbsp; AuthZ Policy Rule must then reference this profile.&amp;nbsp; By disabling RFC5176 option under Disconnect you will cause all request for terminate to be sent using port bounce.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to test your various use cases that entail CoA session terminate to assess impact.&amp;nbsp; For wireless, session terminate should be sufficient to terminate connection and force DHCP.&amp;nbsp; For wired you need bounce without supplicant to detect VLAN change. However, if port bounce all terminate, then need to expect client to start from square one on each terminate.&amp;nbsp; That may be desired behavior, but need to test your wired use cases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 18:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471688#M530667</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-17T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471689#M530668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I disabled the Disconnect option but the CoA request was sent using disable-host-port and the port was disabled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105431_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 19:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471689#M530668</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-17T19:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471690#M530669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are three Disconnect options in sequence of priority:&lt;/P&gt;&lt;P&gt;1) RFC5176&lt;/P&gt;&lt;P&gt;2) Port Bounce&lt;/P&gt;&lt;P&gt;3) Port Shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If #2 is properly configured and #1 unchecked, then Port Bounce should be sent on Session Terminate.&amp;nbsp; If you properly see #1 when enabled but #3 occurs when #1 disabled, then sounds like a defect.&amp;nbsp; You could just change the definition for #1 to include port-bounce.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 19:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471690#M530669</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-17T19:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471691#M530670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the logic Craig.&lt;/P&gt;&lt;P&gt;After playing around with it a couple of times I am able to send port bounce attributes (verified by packet captures) by disabling RFC5176 and also by having it identical to Port Bounce.&lt;/P&gt;&lt;P&gt;However the session is behaving as a normal disconnect/reauth and there is no port bounce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 20:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471691#M530670</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-17T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471692#M530671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then sounds like an issue with switch not properly processing port-bounce request.&amp;nbsp; If able to see port bounce with REST API or sending from Admin UI with exact same directive, then expect there may be some issue with your syntax under CoA config of NAD profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Mar 2017 21:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471692#M530671</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-17T21:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471693#M530672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am testing the similar scenario.&lt;/P&gt;&lt;P&gt;The switch I use is 3750V2-24PS.&lt;/P&gt;&lt;P&gt;What I see in ISE live log is:&lt;/P&gt;&lt;H3 class="title"&gt;&lt;SPAN style="padding-left: 22px;"&gt;Steps&lt;/SPAN&gt;&lt;/H3&gt;&lt;TABLE border="0" cellpadding="3" class="content_table_steps"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; 11202 &lt;/TD&gt;&lt;TD&gt; Received disconnect and port shutdown dynamic authorization request &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; 11217 &lt;/TD&gt;&lt;TD&gt; Prepared the disconnect dynamic authorization request &lt;/TD&gt;&lt;/TR&gt;&lt;TR class="content_table_steps_highlight"&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; 11100 &lt;/TD&gt;&lt;TD&gt; RADIUS-Client about to send request - ( port = 1700 , type = Cisco CoA ) &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; 11101 &lt;/TD&gt;&lt;TD&gt; RADIUS-Client received response &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This makes me thin that the issue is in the ISE itself and not in the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you comment?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 11:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471693#M530672</guid>
      <dc:creator>Vladislav Atanasov</dc:creator>
      <dc:date>2017-03-29T11:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471694#M530673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try and run debug CoA on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I use the customization recommended by Craig I get the below output on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled picture.png" class="image-1 jive-image" src="/legacyfs/online/fusion/105804_Untitled picture.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to issue CoA Portbounce from Live sessions I get the below output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled picture.png" class="jive-image image-2" src="/legacyfs/online/fusion/105805_Untitled picture.png" style="height: 171px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the switch is not able to parse the customized CoA port-bounce. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's strange is both the packet captures show the same AVP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled picture.png" class="jive-image image-3" src="/legacyfs/online/fusion/105806_Untitled picture.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 13:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471694#M530673</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-29T13:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471695#M530674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be time to open TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 14:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471695#M530674</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-29T14:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471696#M530675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I take back that both packets are same when I manually edit the &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;RFC5176&lt;/SPAN&gt; to include 'disable-host-port' AVP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I missed is the difference in CoA Code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CoA port bounce form Live Sessions look like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled picture.png" class="jive-image image-2" src="/legacyfs/online/fusion/105822_Untitled picture.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;The CoA port bounce with customized AVP looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="Untitled picture.png" class="image-1 jive-image" src="/legacyfs/online/fusion/105821_Untitled picture.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think once the switch receives a CoA with code 40 it thinks it is a RFC disconnect-request and does not look into the Cisco AVP pairs to find the 'port-bounce' AV pairs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened a TAC case who will recreate this in lab and probably file a bug. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll still try to make this work by disabling &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;RFC5176&lt;/SPAN&gt; option. &lt;/P&gt;&lt;P&gt;However I am seeing inconsistency in this approach as the ISE is sending 'disable-port-host' sometimes instead of 'host-port-bounce' which could be very dangerous to implement in production. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 15:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471696#M530675</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-29T15:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471697#M530676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi utkarsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just exploring the situation you posted but I could not find the ISE configuration part with the "disconnect" options. Could you please provide the path to this option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471697#M530676</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2017-10-23T19:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471698#M530678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In case you are asking about the AVP, that would be in the NAD profile as Craig responded on &lt;SPAN class="j-post-author"&gt;Mar 17, 2017 11:50 AM&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the CoA option in ISE hotspot portals, you would need ISE 2.1 Patch 1 or above. Below shows a screenshot from ISE 2.2. CoA Terminate is the disconnect option.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="112444" alt="Screen Shot 2017-10-23 at 12.48.25 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/112444_Screen Shot 2017-10-23 at 12.48.25 PM.png" style="height: 625px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Oct 2017 19:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471698#M530678</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-10-23T19:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: CoA Terminate in Hotspot portal is not initiating DHCP refresh</title>
      <link>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471699#M530679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Change of vlan is not generally  recommended because port is not bounced and no new dhcp is issued.&lt;/P&gt;&lt;P&gt;We are using macros to achieve port bounce instead of CoA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Utkarsh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Oct 2017 21:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/coa-terminate-in-hotspot-portal-is-not-initiating-dhcp-refresh/m-p/3471699#M530679</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-10-23T21:30:43Z</dc:date>
    </item>
  </channel>
</rss>

