<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE sending CoA-requests for reauthentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4925724#M584128</link>
    <description>&lt;P&gt;Yes ISE is defined as Dynamic Authorization server on IAP. We have seen that the problem only exists when clients using an BYOD MAC-group in ISE (still using guest wifi), but when clients using Guest Portal on ISE it works fine. Check my Authorization profiles below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_0-1695125453605.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197681iD695F54ADBF2E1BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="pontusd_0-1695125453605.png" alt="pontusd_0-1695125453605.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_1-1695125529106.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197682i774AE7BC16FA5269/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_1-1695125529106.png" alt="pontusd_1-1695125529106.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_2-1695125561955.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197683iAFEF0C8C4625403B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_2-1695125561955.png" alt="pontusd_2-1695125561955.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_3-1695125609583.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197684iAEE8603B20BC198F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_3-1695125609583.png" alt="pontusd_3-1695125609583.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_5-1695125755310.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197686iC1BA334B883109DB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_5-1695125755310.png" alt="pontusd_5-1695125755310.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Aruba client logs:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;deauth&amp;nbsp; &amp;nbsp; Sapcp Ageout (internal ageout)&amp;nbsp; (seq num 0)&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;deauth&amp;nbsp; &amp;nbsp; Denied; Ageout (seq num 0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 12:21:01 GMT</pubDate>
    <dc:creator>pontusd</dc:creator>
    <dc:date>2023-09-19T12:21:01Z</dc:date>
    <item>
      <title>ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923236#M584037</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I have a problem with Cisco ISE 2.7 guest access. I can see in live logs that clients have been authenticated correctly but after every successful authentication ISE sending a CoA-request for reauthentication. This is happening every 5 seconds and keeps going forever. In this case we have Cisco ISE acting radius for an Aruba Wireless network.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 06:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923236#M584037</guid>
      <dc:creator>pontusd</dc:creator>
      <dc:date>2023-09-14T06:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923418#M584044</link>
      <description>&lt;P&gt;This is expected behavior to make sure the client has access to the network after a successful portal login.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 12:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923418#M584044</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-09-14T12:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923456#M584050</link>
      <description>&lt;P&gt;Ok I see,&lt;BR /&gt;But we still have problem with clients that constantly being connect and disconnected from the guest wifi every 5-10 second (same time as the CoA-requests). Do you think this is an ISE problem or Aruba problem?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 13:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923456#M584050</guid>
      <dc:creator>pontusd</dc:creator>
      <dc:date>2023-09-14T13:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923493#M584053</link>
      <description>&lt;P&gt;Right after they join?&amp;nbsp; Or constantly?&amp;nbsp; I'm possible to say.&amp;nbsp; Are you using the Aruba network device provfile in the article I linked?&amp;nbsp; That NDP is much more modern than the one provided natively in ISE. Is this IAP?&amp;nbsp; Mobility Controller on AOS8.x?&amp;nbsp; Gateway on AOS10?&amp;nbsp; Aruba Central?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 14:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923493#M584053</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-09-14T14:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923693#M584057</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1519954"&gt;@pontusd&lt;/a&gt;&amp;nbsp;- if you perform a tcpdump on the PSN that the Aruba WLC is using, you might get some extra clues. Does the Aruba send any RADIUS Accounting to ISE?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 21:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923693#M584057</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-09-14T21:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923896#M584061</link>
      <description>&lt;P&gt;yes I am using the custom Aruba network profile in ISE, we are using IAP without controller or Aruba Central, just virtual controller on the APs with AOS8.&amp;nbsp;&lt;BR /&gt;The clients flapping between connected/disconnected constantly after the first successful portal authentication.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 07:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923896#M584061</guid>
      <dc:creator>pontusd</dc:creator>
      <dc:date>2023-09-15T07:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923899#M584062</link>
      <description>&lt;P&gt;Doesn't see any interesting in the TCP dumps. Yes I had accounting ON at the Aruba SSID configuration. I turned it off now and I it seems to be better. But the problem with connect/disconnect still exists of course.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 07:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4923899#M584062</guid>
      <dc:creator>pontusd</dc:creator>
      <dc:date>2023-09-15T07:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4924039#M584067</link>
      <description>&lt;P&gt;Accounting should be enabled for proper ISE session/license management.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 10:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4924039#M584067</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-09-15T10:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4924040#M584068</link>
      <description>&lt;P&gt;So is this driven by CoA packets from ISE or not?&amp;nbsp; ISE should only be sending one CoA.&amp;nbsp; Do you have ISE defined as a Dynamic Authorization server on the IAP?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 10:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4924040#M584068</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-09-15T10:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE sending CoA-requests for reauthentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4925724#M584128</link>
      <description>&lt;P&gt;Yes ISE is defined as Dynamic Authorization server on IAP. We have seen that the problem only exists when clients using an BYOD MAC-group in ISE (still using guest wifi), but when clients using Guest Portal on ISE it works fine. Check my Authorization profiles below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_0-1695125453605.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197681iD695F54ADBF2E1BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="pontusd_0-1695125453605.png" alt="pontusd_0-1695125453605.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_1-1695125529106.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197682i774AE7BC16FA5269/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_1-1695125529106.png" alt="pontusd_1-1695125529106.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_2-1695125561955.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197683iAFEF0C8C4625403B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_2-1695125561955.png" alt="pontusd_2-1695125561955.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_3-1695125609583.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197684iAEE8603B20BC198F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_3-1695125609583.png" alt="pontusd_3-1695125609583.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pontusd_5-1695125755310.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/197686iC1BA334B883109DB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pontusd_5-1695125755310.png" alt="pontusd_5-1695125755310.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Aruba client logs:&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;deauth&amp;nbsp; &amp;nbsp; Sapcp Ageout (internal ageout)&amp;nbsp; (seq num 0)&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;deauth&amp;nbsp; &amp;nbsp; Denied; Ageout (seq num 0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sending-coa-requests-for-reauthentication/m-p/4925724#M584128</guid>
      <dc:creator>pontusd</dc:creator>
      <dc:date>2023-09-19T12:21:01Z</dc:date>
    </item>
  </channel>
</rss>

