<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 - Apative Network Control problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3204000#M551703</link>
    <description>&lt;P&gt;I've been triggering the CoA by going to the Adaptive Network Control settings on the Primary Admin node and then (trying to!) quarantine the Client that way by entering the Client's MAC Address.&amp;nbsp; In the real world it will come from FirePower via pxGrid, but that way doesn't work either at the moment (same error messages coming back from the switch).&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2017 06:10:53 GMT</pubDate>
    <dc:creator>RichardAtkin</dc:creator>
    <dc:date>2017-10-24T06:10:53Z</dc:date>
    <item>
      <title>ISE 2.3 - Apative Network Control problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3203714#M551695</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RADIUS Attributes in Config VS Packet Trace" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/2370i836E934955EF59E4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Trace1.png" alt="RADIUS Attributes in Config VS Packet Trace" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;RADIUS Attributes in Config VS Packet Trace&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Switch is added to TEST Device Profile" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/2369iE986833540FC4C70/image-size/large?v=v2&amp;amp;px=999" role="button" title="Config1.png" alt="Switch is added to TEST Device Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Switch is added to TEST Device Profile&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Error logs from ISE" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/2368i28E722FA3A4058DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log1.png" alt="Error logs from ISE" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Error logs from ISE&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Evening..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with ISE.&amp;nbsp; I'm using ISE 2.3 (not patch 1 yet) and we're running Adaptive Network Control against some HP switches.&amp;nbsp; I've been around the mill with the attributes it needs and I'm sure I've got that cracked now, but it still doesn't work.&amp;nbsp; I ended up doing a packet trace and it looks like ISE isn't sending the attributes that are configured for it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Above screenshots show what I've configured VS what ISE is actually transmitting...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume its either a bug or I've done something daft somewhere... any tips please!?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3203714#M551695</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2020-02-21T18:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Apative Network Control problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3203889#M551700</link>
      <description>&lt;P&gt;When dealing with custom device profiles (like your 'test' derivative of an HP Profile) I have come across some funnies too.&amp;nbsp; But not CoA related.&amp;nbsp; In my case I had forgotten to attribute the custom profile to my Authorization Profile (default=Cisco).&amp;nbsp; Once I did that, the thing worked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your case it looks a bit suspect (like a bug) - but how do you trigger the CoA?&amp;nbsp; Via the PAN Context GUI?&amp;nbsp; I can see Cisco AVPairs in that CoA and that should not be the case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 22:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3203889#M551700</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-23T22:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Apative Network Control problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3204000#M551703</link>
      <description>&lt;P&gt;I've been triggering the CoA by going to the Adaptive Network Control settings on the Primary Admin node and then (trying to!) quarantine the Client that way by entering the Client's MAC Address.&amp;nbsp; In the real world it will come from FirePower via pxGrid, but that way doesn't work either at the moment (same error messages coming back from the switch).&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 06:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3204000#M551703</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2017-10-24T06:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Apative Network Control problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3204062#M551705</link>
      <description>&lt;P&gt;I've been looking closer at the Cisco AV Pairs that ISE is sending and they match with the default 'Cisco' device profile.&amp;nbsp; So, I think ANC instructions sent from ISE are just using their default Cisco Device Profile settings instead of using the custom device profile attributes that I've associated with the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've rebooted ISE - no change.&amp;nbsp; Deleted and re-created the switch as a NAD - no change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next step is to try 2.3 patch 1, but the release notes don't say anything about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that? TAC...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 08:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3204062#M551705</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2017-10-24T08:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Apative Network Control problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3205358#M551707</link>
      <description>&lt;P&gt;I think you've done more than your homework already!&amp;nbsp; Yes, TAC case is next step.&amp;nbsp; Maybe you have found a new bug.&lt;/P&gt;
&lt;P&gt;I have created over 20 TAC cases since July of this year and half of them resulted in new bug ID's.&amp;nbsp; The product is riddled with bugs.&amp;nbsp; It's not really fit for "off the shelf" usage without a lot of hand holding from the TAC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 00:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-apative-network-control-problem/m-p/3205358#M551707</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-26T00:03:26Z</dc:date>
    </item>
  </channel>
</rss>

