<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4425768#M568217</link>
    <description>&lt;P&gt;Hi, Did you check if traffic from ISE server to NAD is allowed on port UDP 1700 if NAD is a Cisco Device ?&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 01:32:22 GMT</pubDate>
    <dc:creator>Sri Harsha Dasari</dc:creator>
    <dc:date>2021-06-30T01:32:22Z</dc:date>
    <item>
      <title>Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005015#M23433</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am having two types of below errors with some similarities from Cisco ISE summary reports for added sites. can any one let me know the fix and what can be the impact or risk of this error? is low or medium or high??? Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE width="678" style="width: 508.65pt; background: #FAFAFA; border: solid white 1.0pt;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Event&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: red;"&gt;5417 Dynamic Authorization failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Failure Reason&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: red;"&gt;11213 No response received from Network Access Device after sending a Dynamic Authorization request&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Resolution&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Check the connectivity between ISE and Network Access Device. Ensure that ISE is defined as Dynamic Authorization Client on Network Access Device and that CoA is supported on device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Root cause&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;No response received from Network Access Device after sending a Dynamic Authorization request&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Second type is as below.&lt;/P&gt;
&lt;TABLE width="678" style="width: 508.65pt; background: #FAFAFA; border: solid white 1.0pt;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Event&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: red;"&gt;5417 Dynamic Authorization failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Failure Reason&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: red;"&gt;11215 No response has been received from Dynamic Authorization Client in ISE&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Resolution&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; background: whitesmoke; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Check the connectivity between the following: ISE running Log Collector and Dynamic Authorization Client in ISE ; Dynamic Authorization Client in ISE and Network Access Device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%" style="width: 31.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;Root cause&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="69%" style="width: 69.0%; border: none; padding: 3.75pt 3.75pt 3.75pt 3.75pt;"&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #666666;"&gt;No response has been received from Dynamic Authorization Client in ISE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005015#M23433</guid>
      <dc:creator>technicalit10001</dc:creator>
      <dc:date>2019-03-11T07:33:49Z</dc:date>
    </item>
    <item>
      <title>Have you configured the CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005016#M23434</link>
      <description>&lt;P&gt;Have you configured the CoA on your switches ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="synph" style="color: #000000;"&gt;&lt;SPAN class="kwd"&gt;aaa server radius dynamic-author&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005016#M23434</guid>
      <dc:creator>Thibault BRISSE</dc:creator>
      <dc:date>2017-05-12T16:00:37Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005017#M23435</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;same issue. Radius dynamic-author configured but i received the follow error :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;11204 Received reauthenticate request&lt;/P&gt;
&lt;P&gt;11220 Prepared the reauthenticate request&amp;nbsp;&lt;/P&gt;
&lt;P&gt;11100 RADIUS-Client about to send request - ( port = 1700 , type = Cisco CoA )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;11104 RADIUS-Client request timeout expired (&lt;IMG src="https://mige422.unicatt.it/admin/css/images/alarm_n_16.png" title="step latency=10003  ms" /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Step latency=10003 ms)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;11213 No response received from Network Access Device after sending a Dynamic Authorization request&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any idea?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 09:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3005017#M23435</guid>
      <dc:creator>Marco Aresu</dc:creator>
      <dc:date>2017-07-21T09:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3730801#M23436</link>
      <description>&lt;P&gt;Hi, I have the same issue when configuring easyconnect:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;FONT size="2"&gt;11204 Received reauthenticate request&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;11220 Prepared the reauthenticate request&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;11211 Proxying request to Dynamic Authorization Client ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;11100 RADIUS-Client about to send request - ( port = 1700 , type = Cisco CoA )&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;11104 RADIUS-Client request timeout expired (step latency=10001 ms Step latency=10001 ms)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;11215 No response has been received from Dynamic Authorization Client in ISE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured CoA in my switch:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;aaa server radius dynamic-author&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client remains with LimitedAccess ACL applied no matter it log-in successfully into domain. Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 14:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3730801#M23436</guid>
      <dc:creator>obadillaa</dc:creator>
      <dc:date>2018-10-23T14:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3730816#M23437</link>
      <description>Do you have servers (client) defined within the aaa server radius dynamic-author section?&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Oct 2018 15:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3730816#M23437</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-10-23T15:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3734481#M23438</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-16-6/sec-usr-aaa-xe-16-6-book/sec-rad-coa.html" target="_blank"&gt;RADIUS Change of Authorization&lt;/A&gt;. In particular, it has a section&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-16-6/sec-usr-aaa-xe-16-6-book/sec-rad-coa.html#GUID-AE457161-5092-4602-8D50-53BA1F74FAB5" target="_blank"&gt;Monitoring and Troubleshooting RADIUS Change of Authorization&lt;/A&gt;, which might help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 18:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3734481#M23438</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-28T18:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3735070#M23440</link>
      <description>&lt;P&gt;Thks gbekmezi and hslai for your replies,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Let me start answering that yes, I have two servers configured in that section.&lt;/P&gt;
&lt;P&gt;Now&amp;nbsp;let me re-phrase my issue providing a little more info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I connect my test-laptop to the switch, it applies the limited&lt;BR /&gt;connection profile as expected:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;FONT size="2"&gt;switch#sho authe sess int gi1/0/2 det&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Interface: GigabitEthernet1/0/2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; IIF-ID: 0x101B180000000BB &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; MAC Address: 8cdc.d4cd.8a8f&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; IPv6 Address: Unknown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; IPv4 Address: 172.20.40.100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; User-Name: 8C-DC-D4-CD-8A-8F&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Status: Authorized&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Domain: DATA&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Oper host mode: multi-auth&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Oper control dir: both&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Session timeout: N/A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Common Session ID: AC1428F70000107F7EEE74B2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Acct Session ID: 0x000016C6&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Handle: 0x9F00002B&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Current Policy: POLICY_Gi1/0/2&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;FONT size="2"&gt;Server Policies:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Vlan Group: Vlan: {vlan-id}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; ACS ACL: xACSACLx-IP-EASYCONNECT_ACL-5b3409b5&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;FONT size="2"&gt;Method status list:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; Method State&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt; mab Authc Success&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But no matter I login successfully into domain, profile does not change to full-access.&lt;/P&gt;
&lt;P&gt;I have noticed that full-access authorization policy inside my EZConnect policy does not get any matches, the condition for this policy is&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;FONT size="2"&gt;"{myDomain} ExternalGroups EQUALS {myDomain}/Users/Domain Users". &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All matches go to default policy which has the limited-connection profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Domain Users" group was included in "Network Access&amp;gt;Ext Id Sources&amp;gt;Active Directory&amp;gt;Groups"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using default CoA port (1700), my ISE servers are behind a firewall as expected, but I could not see any packets going in that port (on both FW´s interfaces) just 1812-1813 packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW has policies to allow CoA traffic to reach ISE servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not pretty sure who triggers the CoA (the switch or the ISE server) and I have checked connection between ISE servers an AD and all test passed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3735070#M23440</guid>
      <dc:creator>obadillaa</dc:creator>
      <dc:date>2018-10-29T17:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3735164#M23441</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;I am using default CoA port (1700), my ISE servers are behind a firewall as expected, but I could not see any packets going in that port (on both FW´s interfaces) just 1812-1813 packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW has policies to allow CoA traffic to reach ISE servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not pretty sure who triggers the CoA (the switch or the ISE server) and I have checked connection between ISE servers an AD and all test passed.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;For CoA interactions, the switch (NAD) is the CoA server and the ISE is the CoA client so that NAD listening on the CoA port (UDP 1700 or other port) and ISE makes the CoA requests to NAD. The packets would be from ISE outbound to NAD on UDP 1700.&lt;/P&gt;
&lt;P&gt;Once CoA succeeds, NAD will trigger a re-authentication request for the endpoint to&amp;nbsp;ISE and ISE will merge the Passive ID identity into the RADIUS MAB session and authorize with the endpoint with the matched AD group.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 21:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/3735164#M23441</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-29T21:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4425768#M568217</link>
      <description>&lt;P&gt;Hi, Did you check if traffic from ISE server to NAD is allowed on port UDP 1700 if NAD is a Cisco Device ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 01:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4425768#M568217</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2021-06-30T01:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4425770#M568218</link>
      <description>&lt;P&gt;It only matters if you are pushing any dynamic attributes in authorization policy like dACL's or VLAN changes.&lt;/P&gt;&lt;P&gt;Check if traffic from ISE server to NAD is allowed on port UDP/1700 if NAD is a Cisco Device.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 01:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4425770#M568218</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2021-06-30T01:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4454555#M569255</link>
      <description>&lt;P&gt;Hello together&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check double check the shared secret for the RADIUS Server on the NAD. You may check this by debugging aaa events.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;(wlc) &amp;gt;debug aaa events enable&lt;/P&gt;&lt;P&gt;*radiusCoASupportTransportThread: Aug 01 16:07:30.310: [SA] Invalid message authenticator received in 'CoA-Request' from 8.8.8.8 port 41396&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is that an wlc e.g. silently drops a CoA if the shared secret is wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 07:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/4454555#M569255</guid>
      <dc:creator>rene_braun</dc:creator>
      <dc:date>2021-08-25T07:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/5104045#M589413</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Try enabling IP Tracking on the switch. Example (device tracking policy attacked to easy connect configured port):&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;device-tracking policy IP-TRACKING&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;limit address-count 4&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;security-level glean&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;no protocol ndp&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;no protocol dhcp6&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;no protocol udp&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;tracking enable reachable-lifetime 30&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;interface ge 1/0/X&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;device-tracking attach-policy IP-TRACKING&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2024 06:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/5104045#M589413</guid>
      <dc:creator>Faruzzi</dc:creator>
      <dc:date>2024-05-14T06:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE error Dynamic Authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/5143578#M590567</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;having same issue...I believe it may be due to the distributed deployment, where PAN nodes initiate CoA requests not the PSN nodes! at least in my case. ALSO&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAN sends CoA" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223225i47484056BF6708D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="pan_coa.png" alt="PAN sends CoA" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;PAN sends CoA&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 12:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-error-dynamic-authorization-failed/m-p/5143578#M590567</guid>
      <dc:creator>bohumil-danilak</dc:creator>
      <dc:date>2024-07-11T12:53:51Z</dc:date>
    </item>
  </channel>
</rss>

