<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Per-Profile CoA not worked in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857741#M582326</link>
    <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1396378"&gt;@LenarFA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Review the authorization policy in Cisco ISE that matches the IP Phone device profile. Ensure that the policy includes the necessary CoA attributes and defines the appropriate CoA actions. For per-profile CoA, the authorization policy should have the correct authorization profile assigned with the desired CoA actions , also&amp;nbsp;Verify the CoA configuration in Cisco ISE. Ensure that CoA is enabled and properly configured in the ISE administration settings. Check that the CoA port, key, and timeout values are correctly set. Also, verify that the correct CoA settings are configured on the network devices, such as the switch, to accept and process CoA requests from ISE.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2023 17:33:00 GMT</pubDate>
    <dc:creator>Mohamed Alhenawy</dc:creator>
    <dc:date>2023-06-19T17:33:00Z</dc:date>
    <item>
      <title>Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857657#M582323</link>
      <description>&lt;P&gt;Hi, looking for help with configuration per-profile COA in ISE:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LenarFA_0-1687183273944.png" style="width: 435px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187929iC4BAA5C3689A29D1/image-dimensions/435x300?v=v2" width="435" height="300" role="button" title="LenarFA_0-1687183273944.png" alt="LenarFA_0-1687183273944.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;New connected "ip-phone" is profiled as IP-Phone, but CoA not worked?&lt;/P&gt;&lt;P&gt;On the switch side, most likely everything is configured correctly, since if I send CoA from ISE &amp;gt; Live Sessions it worked.&lt;/P&gt;&lt;P&gt;Probably I missed something or did not understand from the side of ISE Configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 14:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857657#M582323</guid>
      <dc:creator>LenarFA</dc:creator>
      <dc:date>2023-06-19T14:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857741#M582326</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1396378"&gt;@LenarFA&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Review the authorization policy in Cisco ISE that matches the IP Phone device profile. Ensure that the policy includes the necessary CoA attributes and defines the appropriate CoA actions. For per-profile CoA, the authorization policy should have the correct authorization profile assigned with the desired CoA actions , also&amp;nbsp;Verify the CoA configuration in Cisco ISE. Ensure that CoA is enabled and properly configured in the ISE administration settings. Check that the CoA port, key, and timeout values are correctly set. Also, verify that the correct CoA settings are configured on the network devices, such as the switch, to accept and process CoA requests from ISE.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 17:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857741#M582326</guid>
      <dc:creator>Mohamed Alhenawy</dc:creator>
      <dc:date>2023-06-19T17:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857921#M582330</link>
      <description>&lt;P&gt;Thank you for reply, checked everything seems to all right?&lt;/P&gt;&lt;P&gt;If I enable globally CoA Reauth (Work Centers &amp;gt; Profiler &amp;gt; Settings) everything works as expected, ISE send CoA and port is reauthenticate. If I disable CoA globally - No CoA, per-profile CoA nor worked. May be some debug info from ISE would be helpful?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 23:27:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4857921#M582330</guid>
      <dc:creator>LenarFA</dc:creator>
      <dc:date>2023-06-19T23:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859398#M582382</link>
      <description>&lt;P&gt;If the phones get profield correctly then I would say the profiler policy CoA would have worked. First time the phone connects to the network it would be classified as unknown device from ISE perspective, this state will remain as is until that phone is matching the right profiler policy. The fact that you see it as an IP-Phone it would suggest that that phone moved from being an unknown device to an IP-Phone. This state change happens when the phone has been reauthenticated after it was showing as an unknown device and this reauthentication process would have been triggered via the profiler policy CoA.&amp;nbsp;If the profiler policy CoA wouldn't have worked, you wouldn't see that phone profiled as an IP-Phone, in that case you would still see it as an unknown device.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 11:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859398#M582382</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T11:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859463#M582384</link>
      <description>&lt;P&gt;Hi, let me explain this issue step by step:&lt;/P&gt;&lt;P&gt;"&lt;FONT size="2"&gt;&lt;EM&gt;First time the phone connects to the network it would be classified as unknown device from ISE perspective, this state will remain as is until that phone is matching the right profiler policy. The fact that you see it as an IP-Phone it would suggest that that phone moved from being an unknown device to an IP-Phone&lt;/EM&gt;&lt;/FONT&gt;"&lt;/P&gt;&lt;P&gt;It only mean that profiling is working - nothing else, yes phone profiled as IP-Phone by device sensor, but CoA not sending by ISE and phone stay on it initial session (for unknown device rule) until shut/no shut or session timer expired. It is behavior via per-profile CoA - profiling working, CoA - not.&lt;/P&gt;&lt;P&gt;If I turn global CoA, phone profiled as IP-Phone by device sensor, CoA is sending by ISE and phone reauthenticated to new session (rule for IP_Phone).&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 12:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859463#M582384</guid>
      <dc:creator>LenarFA</dc:creator>
      <dc:date>2023-06-21T12:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859685#M582390</link>
      <description>&lt;P&gt;I slightly disagree on a couple things. Device sensor would feed ISE with the LLDP details into RADIUS packets that will match the IP-Phone profiler policy. As a result, the phone will move from being an unknown device to a known device. This last bit would happen via the CoA, when ISE triggers the reauthentication via CoA you will then see that phone profiled as an IP-Phone. Did you actually run some packet capture on the switch or ISE to see if ISE actually sends any CoA traffic that would have been triggered through the profiler policy?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 16:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859685#M582390</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T16:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859713#M582395</link>
      <description>&lt;P&gt;Maybe I didn't explain exactly, English is not my native language...&lt;/P&gt;&lt;P&gt;Ok, ok, when I disable global CoA (it is by default) and disable CoA in profile (it is by default) how profiling work?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 17:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859713#M582395</guid>
      <dc:creator>LenarFA</dc:creator>
      <dc:date>2023-06-21T17:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859715#M582396</link>
      <description>&lt;P&gt;Apologies for not being clear in my last post. As per my knowledge, if the global CoA and the profiler policy CoA are both disabled, I wouldn't expect the phone to move from unknown to IP-Phone because when ISE sees that phone for the first time it would see it as an unkown device and then after a CoA is triggered the phone will complete its profiling process in which will move to its profiled category. The profiling feeds will just help ISE to know more about that device and try to match those attribues received by the feeders to a profiler policy. If no match the device will remain classified as unknown.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 17:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4859715#M582396</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T17:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4861681#M582450</link>
      <description>&lt;P&gt;&amp;gt; ... If I disable CoA globally - No CoA, per-profile CoA nor worked. ...&lt;/P&gt;
&lt;P&gt;This is expected. The global option acts as a kill switch when set to No CoA. Thus, to allow per-profiler-policy CoA, please set it to re-auth or port-bounce.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 03:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4861681#M582450</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-06-24T03:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4862370#M582481</link>
      <description>&lt;P&gt;Hi, hslai,&lt;/P&gt;&lt;P&gt;if I understand you correctly, then we have several cases:&lt;BR /&gt;1) if Global CoA are turned on to "Reauth", and per-profile CoA for profile IP-Phone are turned on to "Reauth"&lt;BR /&gt;- all endpoints that have changed own profile from "unknown" to "known" will recive a CoA via Global Exception "FirstTimeProfile", including endpoints that have changed own profile from "unknown" to "IP-Phone"&lt;BR /&gt;- all endpoints that have changed own profile from "known" to "IP-Phone" will recive a CoA via per-profile CoA for profile IP-Phone&lt;BR /&gt;2) if Global CoA are turned on "no CoA", and per-profile CoA for profile IP-Phone are turned on to Reauth&lt;BR /&gt;- nothing will happen&lt;/P&gt;&lt;P&gt;That is, there is no option if I want to enable CoA for only this way "unknown/known" to "IP-Phone"? I don't want all devices, that have changed own profile from "unknown" to "known" will recive a CoA.&lt;/P&gt;&lt;P&gt;And, I did not quite understand the purpose of this Global Exception "AuthorizationChange", could you explain, please?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 12:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4862370#M582481</guid>
      <dc:creator>LenarFA</dc:creator>
      <dc:date>2023-06-26T12:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4862628#M582495</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1396378"&gt;@LenarFA&lt;/a&gt; :&lt;/P&gt;
&lt;P&gt;If an endpoint changed from Profiler-policy-A to Profiler-policy-B, and if this results in matching a different authorization policy rule, then it will trigger CoA. If matching the same authorization policy rule, then no CoA.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 15:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4862628#M582495</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-06-26T15:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4864801#M582629</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;apart from the authorization rules match, wouldn't the CoA still work anyway? if we think about ISE profiling process, shouldn't changing the endpoint from being unkown to something trigger the CoA? I thought that would trigger it even if you don't have any authorization rule configured yet.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 17:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4864801#M582629</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-29T17:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Per-Profile CoA not worked</title>
      <link>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4865812#M582650</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt; I focused on Global Exception "AuthorizationChange".&lt;/P&gt;
&lt;P&gt;REF: &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1296406981" rel="nofollow noopener noreferrer" target="_blank"&gt;Change of Authorization (CoA)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jul 2023 07:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/per-profile-coa-not-worked/m-p/4865812#M582650</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-07-02T07:02:56Z</dc:date>
    </item>
  </channel>
</rss>

