<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CTS-enabled C9500 ignores ISE' CoAs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4430613#M568391</link>
    <description>&lt;P&gt;Hi Andy&lt;/P&gt;&lt;P&gt;i appreciate your input. In fact in cube of interest (SW 2.1) there is no option to select node. What i've passed throu was noticing that one of my PSNs (one both configured rad-server group &amp;amp; as dynamic authZ client also configured as AAA server in TrastSec components) have been sending CoA ignored by switch. Then i've removed it from all the mentioned sections &amp;amp; found PAN has started to send CoA (obviously it was not in either rad-server group or dynamic authZ list). But when i added it to just dynamic authZ list issue disappeared. So far case with PSN looks quite wierd.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 15:42:23 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2021-07-09T15:42:23Z</dc:date>
    <item>
      <title>CTS-enabled C9500 ignores ISE' CoAs</title>
      <link>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4429022#M568349</link>
      <description>&lt;P&gt;Gents&lt;/P&gt;&lt;P&gt;C9500 runs 16.12.4. switch CTS&amp;amp;CoA enabled:&lt;/P&gt;&lt;P&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;SGT tag = 2-00:SGT_CTS_DEVICE&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0006, 3 server(s):&lt;BR /&gt;*Server: 10.100.5.62, port 1812, A-ID ID1&lt;BR /&gt;Status = ALIVE&lt;BR /&gt;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;*Server: 10.101.5.60, port 1812, A-ID ID2&lt;BR /&gt;Status = ALIVE&lt;BR /&gt;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;*Server: 10.101.5.62, port 1812, A-ID ID3&lt;BR /&gt;Status = ALIVE&lt;BR /&gt;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;0-00:Unknown&lt;BR /&gt;2-00:SGT_CTS_DEVICE&lt;BR /&gt;Environment Data Lifetime = 86400 secs&lt;BR /&gt;Last update time = 06:53:16 UTC Wed Jul 7 2021&lt;BR /&gt;Env-data expires in 0:23:59:19 (dd:hr:mm:sec)&lt;BR /&gt;Env-data refreshes in 0:23:59:19 (dd:hr:mm:sec)&lt;BR /&gt;Cache data applied = NONE&lt;BR /&gt;State Machine is running&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;BR /&gt;client 10.100.5.62 server-key &amp;lt;PSK&amp;gt;&lt;BR /&gt;client 10.101.5.62 server-key &amp;lt;PSK&amp;gt;&lt;BR /&gt;client 10.101.5.60 server-key &amp;lt;PSK&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Advanced TrustSec Settings have "Send configuration changes to device" checked with CoA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;everytime CTS on the switch gets refreshed one of the ISEs sends CoA to switch. &amp;amp; switch fully ignores it (No NACK/No ACK). CoAs r confirmed as delivered to switch with packet capture.&lt;BR /&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 07:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4429022#M568349</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-07-07T07:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: CTS-enabled C9500 ignores ISE' CoAs</title>
      <link>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4430602#M568389</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mentioned that your "Advanced TrustSec Settings have "Send configuration changes to device" checked with CoA". Underneath this setting you specify which ISE node to send the CoA from (on ISE 2.4 anyway). Is this set to one of the ISE nodes you have configured as dynamic author on the switch? I had a similar issue as you - I found that I had configured the PSNs as dynamic-author but was sending CoA from a PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4430602#M568389</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2021-07-09T15:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: CTS-enabled C9500 ignores ISE' CoAs</title>
      <link>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4430613#M568391</link>
      <description>&lt;P&gt;Hi Andy&lt;/P&gt;&lt;P&gt;i appreciate your input. In fact in cube of interest (SW 2.1) there is no option to select node. What i've passed throu was noticing that one of my PSNs (one both configured rad-server group &amp;amp; as dynamic authZ client also configured as AAA server in TrastSec components) have been sending CoA ignored by switch. Then i've removed it from all the mentioned sections &amp;amp; found PAN has started to send CoA (obviously it was not in either rad-server group or dynamic authZ list). But when i added it to just dynamic authZ list issue disappeared. So far case with PSN looks quite wierd.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cts-enabled-c9500-ignores-ise-coas/m-p/4430613#M568391</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-07-09T15:42:23Z</dc:date>
    </item>
  </channel>
</rss>

