<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE stealthwatch integration - ANC not working with aruba in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4827784#M581516</link>
    <description>&lt;P&gt;Are you using a custom Aruba Network Device Profile?&amp;nbsp; Or are you using the Cisco one for this NAD?&amp;nbsp; Is this an AOS-S or AOS-CX switch?&lt;/P&gt;</description>
    <pubDate>Wed, 03 May 2023 15:46:54 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2023-05-03T15:46:54Z</dc:date>
    <item>
      <title>Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4822440#M581397</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;so i have the following problem i have an Stealthwatch and ISE integration at the moment and is working, i can see the 802.1x users on ise and stealthwatch with the ip and mac address, in that way everything is working as spected but when i do the change over on the stealthwatch to the &lt;SPAN&gt;ANC-Policy &lt;/SPAN&gt;that a specific users should use i got a problem on Cisco ISE and ARUBA switch.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_0-1682531543024.png" style="width: 1072px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183017i6A5F540C700A04F4/image-dimensions/1072x260?v=v2" width="1072" height="260" role="button" title="vivarock12_0-1682531543024.png" alt="vivarock12_0-1682531543024.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;as you can see in the picture above the error the i get is when i do the change on the stheatlwatch and then being send to the ARUBA switch but the aruba is not responding correctly to the request.(afeter that i do a manual COa and is working as spected)&lt;/P&gt;
&lt;P&gt;After double checking i see that the Radius VSA that is being send is CISCO AV PAIR, as you can see below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_1-1682531694796.png" style="width: 532px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183018i35B84351225F2850/image-dimensions/532x617?v=v2" width="532" height="617" role="button" title="vivarock12_1-1682531694796.png" alt="vivarock12_1-1682531694796.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;so the question: is ther a way to change that parameter from CISCO AV PAIR to just a normal COA port-bounce or shutdown instead?&lt;/P&gt;
&lt;P&gt;because that the only thing not working on the implementation, DACL and manualy changing the &lt;SPAN&gt;ANC-Policy &lt;/SPAN&gt;and then doing a manual port-bounce is working.&lt;/P&gt;
&lt;P&gt;does anyone has any idea on how to do this?&lt;/P&gt;
&lt;P&gt;thanks for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 18:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4822440#M581397</guid>
      <dc:creator>vivarock12</dc:creator>
      <dc:date>2023-04-26T18:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4822444#M581398</link>
      <description>&lt;P&gt;Check this community link for CoA port bounce : &lt;A href="https://community.cisco.com/t5/network-access-control/coa-port-bounce-vs-coa-session-termination-with-port-bounce/td-p/4044275" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/coa-port-bounce-vs-coa-session-termination-with-port-bounce/td-p/4044275&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 18:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4822444#M581398</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-26T18:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4827719#M581507</link>
      <description>&lt;P&gt;just for you to know today i will be trying with terminate to see because it looks like the COA TERMINATE does not use Cisco-AV-PAIR and is the standar parameter if it works ill show the complete guide on how to make this work.&lt;/P&gt;
&lt;P&gt;and thank for the help by the way.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 14:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4827719#M581507</guid>
      <dc:creator>vivarock12</dc:creator>
      <dc:date>2023-05-03T14:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4827784#M581516</link>
      <description>&lt;P&gt;Are you using a custom Aruba Network Device Profile?&amp;nbsp; Or are you using the Cisco one for this NAD?&amp;nbsp; Is this an AOS-S or AOS-CX switch?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 15:46:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4827784#M581516</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-03T15:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4829524#M581565</link>
      <description>&lt;P&gt;a custum one with specific parameter for COA directions&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 19:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4829524#M581565</guid>
      <dc:creator>vivarock12</dc:creator>
      <dc:date>2023-05-05T19:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4829526#M581566</link>
      <description>&lt;P&gt;The switch must not like what you are returning for the CoA attributes.&amp;nbsp; What exact parameters are you returning?&amp;nbsp; AOS-S or AOS-CX?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 19:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4829526#M581566</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-05-05T19:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4830068#M581582</link>
      <description>&lt;P&gt;You need to get real specific with the details in your responses if you would like us to make suggestions.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;We need configurations, error messages, and what your exact COA parameters are.&lt;/P&gt;
&lt;P&gt;Please explain why your "custom one" was necessary and why the default one for Aruba was unacceptable or did not work.&lt;/P&gt;
&lt;P&gt;See &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 16:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4830068#M581582</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-05-07T16:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4831082#M581598</link>
      <description>&lt;P&gt;ok i follow the Aruba manual that defines the parameters for a COA Re-authenticate or COA port bounce:&lt;/P&gt;
&lt;P&gt;DACL’S AND VLAN ASSIGNMENT&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_0-1683554209793.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/184096i869336603A2CE495/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vivarock12_0-1683554209793.png" alt="vivarock12_0-1683554209793.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_1-1683554224899.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/184097i79F530D75167282A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vivarock12_1-1683554224899.png" alt="vivarock12_1-1683554224899.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;this configuration where suggested on aruba comunnity(link bellow):&lt;BR /&gt;&lt;A href="https://community.arubanetworks.com/discussion/coa-port-bounce-with-cisco-ise-and-aruba-2530#bm2e01654f-d7c4-4709-ac4d-d7099b805112" target="_blank"&gt;https://community.arubanetworks.com/discussion/coa-port-bounce-with-cisco-ise-and-aruba-2530#bm2e01654f-d7c4-4709-ac4d-d7099b805112&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;for RADIUS COA terminate:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.arubanetworks.com/discussion/coa-terminate-session#bm9f53ab89-d904-4e0e-9306-018695ecfd1e" target="_blank"&gt;https://community.arubanetworks.com/discussion/coa-terminate-session#bm9f53ab89-d904-4e0e-9306-018695ecfd1e&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and that the link before is for the parameter of Radius COA terminate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_4-1683554810623.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/184101iB84D371DC56C7FDC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vivarock12_4-1683554810623.png" alt="vivarock12_4-1683554810623.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;THE PROBLEM:&lt;/P&gt;
&lt;P&gt;but the problem lies on the following when i apply a change on the Stealthwatch, CISCO ISE allways send to the SWITCH the Cisco AV-PAIR VSA and aruba is now able to get the information from that VSA.&lt;/P&gt;
&lt;P&gt;as suggested from &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/358459"&gt;@Nancy Saini&lt;/a&gt;&amp;nbsp; i should be using a terminate because that a standar parameter thant being send:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_2-1683554404318.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/184099i7B87474833C20E10/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vivarock12_2-1683554404318.png" alt="vivarock12_2-1683554404318.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;this is a capture from the link that &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/358459"&gt;@Nancy Saini&lt;/a&gt; share before, but the problem is that ANC does not give that parameter at all to be chose as the action taken when the change is send from stealthwatch.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01100.html&lt;/A&gt; (ADAPTIVE NETWORK CONTROL MANUAL)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vivarock12_3-1683554547013.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/184100i6E61E97AE7C0AB6F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vivarock12_3-1683554547013.png" alt="vivarock12_3-1683554547013.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;as you canse in here those are the 3 options and those use a Cisco only VSA.&lt;/P&gt;
&lt;P&gt;so is there a way to define that when you do this change it should use the parameters define on the device profile specific configuration or not because everything else work, DACL and manual Port-bounce, termination from cisco ISE directly done, to the switch so the integratino is working but lets say with a extra step.&lt;/P&gt;
&lt;P&gt;here how it should work:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=BAN3CaYsunw&amp;amp;t=141s" target="_blank"&gt;https://www.youtube.com/watch?v=BAN3CaYsunw&amp;amp;t=141s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;but insted you need to got to ENDPOINTS DASHBOARD and do the COA manualy.&lt;/P&gt;
&lt;P&gt;i spect your comments thanks for the help.&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 14:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4831082#M581598</guid>
      <dc:creator>vivarock12</dc:creator>
      <dc:date>2023-05-08T14:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE stealthwatch integration - ANC not working with aruba</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4833919#M581705</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 19:31:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-stealthwatch-integration-anc-not-working-with-aruba/m-p/4833919#M581705</guid>
      <dc:creator>vivarock12</dc:creator>
      <dc:date>2023-06-26T19:31:49Z</dc:date>
    </item>
  </channel>
</rss>

