<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aruba wireless integrated with ISE disconnect's endpoint randomly in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066237#M588678</link>
    <description>&lt;P&gt;How do you have CoA configured?&amp;nbsp; What is the auth method?&amp;nbsp; What exactly is the Aruba NAD?&amp;nbsp; IAP?&amp;nbsp; Central?&amp;nbsp; Mobility Controller?&amp;nbsp; Are you performing redirection-based posture?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Apr 2024 11:27:15 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-04-11T11:27:15Z</dc:date>
    <item>
      <title>Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066191#M588674</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have implemented a wireless network integrated with remote RADIUS authentication using Cisco ISE. To gain network access, a user's device posture needs to be compliant &lt;/SPAN&gt;&lt;STRONG&gt;and&lt;/STRONG&gt;&lt;SPAN&gt; the user must exist in the Active Directory identity store. However, after successful authentication and posturing, the network connection is disconnecting unexpectedly. We'd appreciate it if anyone has experience with this issue.&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="48m7sltl.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215526iC5E4818DA31962C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="48m7sltl.png" alt="48m7sltl.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 11:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066191#M588674</guid>
      <dc:creator>ShalomETH</dc:creator>
      <dc:date>2024-04-11T11:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066237#M588678</link>
      <description>&lt;P&gt;How do you have CoA configured?&amp;nbsp; What is the auth method?&amp;nbsp; What exactly is the Aruba NAD?&amp;nbsp; IAP?&amp;nbsp; Central?&amp;nbsp; Mobility Controller?&amp;nbsp; Are you performing redirection-based posture?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 11:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066237#M588678</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-11T11:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066297#M588679</link>
      <description>&lt;P&gt;Thank you for quick response&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;we have configured "Reauth" CoA type and used the default ArubaWireless network device profile&lt;/LI&gt;&lt;LI&gt;used PEAP auth method&lt;/LI&gt;&lt;LI&gt;yes we are using redirection based posture.&lt;/LI&gt;&lt;LI&gt;Aruba instance 515 AP&lt;/LI&gt;&lt;LI&gt;Aruba Instatnt Access Point&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imgpsh_fullsize_anim (1).jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/215532i7FEC34FB324449CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="imgpsh_fullsize_anim (1).jpg" alt="imgpsh_fullsize_anim (1).jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066297#M588679</guid>
      <dc:creator>ShalomETH</dc:creator>
      <dc:date>2024-04-11T12:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066310#M588680</link>
      <description>&lt;P&gt;What port is CoA set to?&amp;nbsp; I would highly suggest not using the built-in Aruba Wireless NAD profile and use this one:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Why is PEAP being used?&amp;nbsp; Why not EAP-TLS or TEAP?&amp;nbsp; With certificates?&lt;/P&gt;
&lt;P&gt;How are you handling the redirect page on Aruba?&amp;nbsp; Static?&amp;nbsp; Again reference the link I posted above for a dynamic way to handle this instead.&lt;/P&gt;
&lt;P&gt;Since you are using Instant AP mode is the cluster healthy?&amp;nbsp; Do you have RADIUS proxy enabled?&amp;nbsp; Or is each AP defined as a NAD within ISE?&amp;nbsp; Any reason not to use Aruba Central management instead?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2024 12:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066310#M588680</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-11T12:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066989#M588705</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Now the authentication method is changed to TEAP with username and password. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The redirection was manually configured on Aruba AP because the default Arubawireless profile doesn't support dynamic redirection. We've now switched to dynamic redirection using the new profile you provided. but the Instant APs are not receiving the redirection link.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;The cluster is healthy, Radius Proxy is disabled, and we have defined each AP as a NAD in ISE.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 07:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5066989#M588705</guid>
      <dc:creator>ShalomETH</dc:creator>
      <dc:date>2024-04-12T07:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5067227#M588706</link>
      <description>&lt;P&gt;"not receiving the redirection link"?&amp;nbsp; What do you mean?&amp;nbsp; How have you confirmed this?&amp;nbsp; What do the ISE live logs look like?&amp;nbsp; Did you follow the other steps as needed in the link I posted?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 12:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5067227#M588706</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-12T12:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5069020#M588723</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;When an endpoint connects for the first time, it is redirected to the client provisioning portal to download the Cisco AnyConnect agent during default aubawireless profile usage. But, when we use the network device profile you provided, the endpoint isn't being redirected to the client provisioning portal.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Yes, we have followed the steps you provided.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The live log shows that posturing is on pending state.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Apr 2024 07:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5069020#M588723</guid>
      <dc:creator>ShalomETH</dc:creator>
      <dc:date>2024-04-15T07:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba wireless integrated with ISE disconnect's endpoint randomly</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5069478#M588730</link>
      <description>&lt;P&gt;Did you update the authorization rule accordingly to use the autogenerated PSN URL instead of whatever Static URL you had it set to?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 12:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-wireless-integrated-with-ise-disconnect-s-endpoint/m-p/5069478#M588730</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-15T12:17:55Z</dc:date>
    </item>
  </channel>
</rss>

