<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE &amp;amp; EXOS Switch CoA failed - Missing Attribute in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638539#M575714</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;I don't know if I'm misunderstanding something.&lt;BR /&gt;Since we need to send the CoA to an Extreme switch and it expects the Filter-ID attribute, I think ACL is not an option.&lt;BR /&gt;On the switch the policies are configured and the switch applies them. The name is stored in the string.&lt;BR /&gt;Example:&lt;BR /&gt;Enterasys:version=1:policy=FatClients&lt;/P&gt;&lt;P&gt;But I have activated the option in the Network Device Profile&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" style="width: 818px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154621iA2FA77E459020205/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" alt="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Authrization Profile I had the possibility to activate the option as well. Unfortunately it is not possible to store the above mentioned string there.&amp;nbsp;It is always truncated to FatClients. I added the whole string. After saving, closing open it again This ist what the GUI does.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" style="width: 672px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154626i7006C4182EBE8EC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" alt="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;But also with this, the filter ID attributeis not included in the CoA request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 14:55:53 GMT</pubDate>
    <dc:creator>StefanSeubert44470</dc:creator>
    <dc:date>2022-06-24T14:55:53Z</dc:date>
    <item>
      <title>ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638446#M575707</link>
      <description>&lt;P&gt;Hello Community,&lt;BR /&gt;We are in the process of switching from Extreme Networks NAC solution to Cisco ISE.&lt;BR /&gt;Most of the switches are also replaced with Cisco 9300 switch.&lt;BR /&gt;Nevertheless, about 100 Summit X440-G2 switches still need to run for a few years and authenticate endpoints against the ISE in the future.&lt;BR /&gt;We already have a network device profile for EXOS which works. Only the CoA does not work properly.&lt;BR /&gt;Meanwhile Exos also supports CoA by radius, but needs special radius attributes in the CoA request.&lt;BR /&gt;These are also configured in the Network Device Profile.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild1.png" style="width: 603px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154604iDB4C67DFD6713904/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bild1.png" alt="Bild1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If a CoA is now executed, the radius attribute Filter-ID is missing and the switch sends back a CoANAK.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild2.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154606i7EA00187E1A815FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bild2.png" alt="Bild2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild3.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154607i660C2F5CE4CD1534/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bild3.png" alt="Bild3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Authorization Profile the Radius Attribute is configured.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bild4.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154608i9C9575D34415FE76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bild4.png" alt="Bild4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I set the identical string in the Network Device Profile, the Radius Attribute will be packed into the CoA Request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bild5.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154609iE58086821E5C0AEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bild5.png" alt="Bild5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bild6.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154611i328EDD4670E3EBE9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bild6.png" alt="Bild6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case CoA is working on the Exos Switch like expected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this configuration doesn't make sense, because the same Exos policy would be applied to every Reauth from every Endpoint if it is configured fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my understanding the ISE has to add the filter ID from the new Authorization Profile into the CoA Request?&lt;BR /&gt;Or do I have to write something else here as value?&lt;/P&gt;&lt;P&gt;If I connect an end device to the Exos switch, the correct filter ID from the authorization profile is transferred, depending on which authorization rule applies. Only with the Reauth it does not happen.&lt;/P&gt;&lt;P&gt;I have also tried to simply write a 0, but here I have the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully someone has an idea about this behavior.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 13:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638446#M575707</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-06-24T13:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638459#M575708</link>
      <description>&lt;P&gt;you can push the ACL from ISE or push filter-ID &amp;nbsp;from ISE&lt;BR /&gt;push the ACL from ISE meaning the ACL is config in ISE and push to SW&amp;nbsp;&lt;BR /&gt;push filter-ID from ISE meaning the ACL is config in SW and ISE push only the name&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;try push the ACL from ISE&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 13:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638459#M575708</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-24T13:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638539#M575714</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I don't know if I'm misunderstanding something.&lt;BR /&gt;Since we need to send the CoA to an Extreme switch and it expects the Filter-ID attribute, I think ACL is not an option.&lt;BR /&gt;On the switch the policies are configured and the switch applies them. The name is stored in the string.&lt;BR /&gt;Example:&lt;BR /&gt;Enterasys:version=1:policy=FatClients&lt;/P&gt;&lt;P&gt;But I have activated the option in the Network Device Profile&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" style="width: 818px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154621iA2FA77E459020205/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" alt="2022-06-24 16_46_45-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Authrization Profile I had the possibility to activate the option as well. Unfortunately it is not possible to store the above mentioned string there.&amp;nbsp;It is always truncated to FatClients. I added the whole string. After saving, closing open it again This ist what the GUI does.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" style="width: 672px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154626i7006C4182EBE8EC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" alt="2022-06-24 16_53_24-Identity Services Engine und 23 weitere Seiten - Profil 1 – Microsoft​ Edge.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;But also with this, the filter ID attributeis not included in the CoA request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4638539#M575714</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-06-24T14:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4640487#M575771</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654"&gt;@StefanSeubert44470&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like a bug in ISE with the Network Device Profiles not retaining the Filter-ID attribute for that session.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The fact that your Wireshark showed Filter-ID as missing when you asked ISE to send the contents of the Filter-ID for that session, would imply (in my mind) that the string was not found, and hence, ISE didn't include it in the CoA. But when you hard-coded a string there, it dutifully sent it.&lt;/P&gt;
&lt;P&gt;I don't know of a way to dump the RADIUS dictionary for that session at run-time - but that would be the answer (inspect the Dictionary to see if the Filter-ID attribute remains in memory)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps an Endpoint Debug from start to end (including the auth, accept and CoA) could reveal something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If nothing found in Endpoint Debug then you should open a TAC case - great investigative work, by the way &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 20:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4640487#M575771</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-28T20:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4640755#M575785</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you ;-), yes TAC Case is already open and the technician is trying to recreate the problem.&lt;BR /&gt;But I was hoping that I did something wrong.&amp;nbsp;No idea how long it takes then until it is patched.&lt;BR /&gt;I had a similar case before where the timestamp was not transferred. Here the trick was to set a 0 as Value. ISE then makes the current time out of it in the CoA.&lt;BR /&gt;But in the meantime I have no more idea and I will wait for the TAC and report here.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 10:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4640755#M575785</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-06-29T10:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4832156#M581623</link>
      <description>&lt;P&gt;Hi &lt;A id="link_46" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654" target="_self" aria-label="View Profile of StefanSeubert44470"&gt;&lt;SPAN class=""&gt;StefanSeubert44&lt;WBR /&gt;470&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Would you share if this issue was solved with TAC? and how it was solved?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Also, please share the Network Device Template you have working with Extreme Switches,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 20:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4832156#M581623</guid>
      <dc:creator>aleksie.sanchez</dc:creator>
      <dc:date>2023-05-09T20:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4869146#M582701</link>
      <description>&lt;P&gt;Hello Stefan,&lt;BR /&gt;&lt;BR /&gt;The solution to this issue would be to make one minor change to your current Network Device Profile. The only thing you need to do is to change the value for Filter-ID to 0. For some reason the Extreme Switches accept and process that value resulting in a successful CoA-Reauth. &lt;BR /&gt;&lt;BR /&gt;In addition, you will need to change the global Profiler setting to Port Bounce, since a session termination is required for the CoA to work as expected in this scenario for Extreme. This is done under Administration &amp;gt; System &amp;gt; Settings &amp;gt; Profiler &amp;gt; CoA Type.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 23:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4869146#M582701</guid>
      <dc:creator>asimitch</dc:creator>
      <dc:date>2023-07-06T23:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4872330#M582815</link>
      <description>&lt;P&gt;Hello Asimitch,&lt;/P&gt;&lt;P&gt;if I set port bounce globally in the profiler, this would then also be applied to the Cisco switches, right?&lt;BR /&gt;This would cause our IP phones on the Cisco switches to reboot.&lt;BR /&gt;Here it would be great if the CoA action could be bound to a network device profile.&lt;BR /&gt;We have now found a way to deliberately avoid a scenario that requires a dynamic CoA.&lt;BR /&gt;My bigger problem with the Extreme switches currently is that the endpoint status is not correct.&lt;BR /&gt;When I connect a device, I have a 50/50 chance that it will get the connected state in the ISE. Then after a few minutes/hours it switches to disconnected status even though the device is active.&lt;BR /&gt;Do you have a tip how to set the timers etc. on the Exos switches? Accounting actually works, otherwise I would see no status at all and always get disconnected end devices displayed. But as mentioned above I also have devices that are green after connect, at least for some time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 07:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4872330#M582815</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2023-07-12T07:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE &amp; EXOS Switch CoA failed - Missing Attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4873940#M582859</link>
      <description>&lt;P&gt;I believe that ISE won't send a port bounce to an interface, if it detects/learns that that interface has a voice endpoint attached. I have never tested this but it's in the documentation somewhere. That would prevent a port bounce when a workstation is attached to the phone itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 00:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-amp-exos-switch-coa-failed-missing-attribute/m-p/4873940#M582859</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-07-14T00:09:50Z</dc:date>
    </item>
  </channel>
</rss>

