<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167465#M591515</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;. Although Cisco does not officially mention (based on your first link you have provided) supportability of RADIUS Cisco AVP's &lt;STRONG&gt;CTS Request&lt;/STRONG&gt; push from ISE to ASA, but, based on testing this situation in my lab, the following event occurs after ISE pushes CoA to ASA:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1724917330706.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227285iCFC359A43C5F6B40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rezaalikhani_0-1724917330706.png" alt="rezaalikhani_0-1724917330706.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From ASA perspective:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_1-1724917433019.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227286i7DA04CC0CC37725B/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_1-1724917433019.png" alt="rezaalikhani_1-1724917433019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see above, although ASA has received the &lt;STRONG&gt;CoA Request&lt;/STRONG&gt; from ISE (192.168.10.120), it does not respond back.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 07:50:59 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2024-08-29T07:50:59Z</dc:date>
    <item>
      <title>Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166246#M591416</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;Based on Cisco's published documents, everywhere Cisco explains about configuring TrustSec settings for ASA in ISE, the documents omit the CoA configuration. For example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227108iC4AA67416724A935/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Does Cisco ASA support pushing TrustSec configuration from ISE side?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 04:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166246#M591416</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-08-27T04:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166270#M591420</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt; you need to manually import a PAC file to the ASA, generated from ISE. With the PAC file installed the ASA a secure connection to ISE is established to download the TrustSec data. The IP/SGT bindings must be exchanged using SXP.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/firewall/asa-920-firewall-config/access-trustsec.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa920/configuration/firewall/asa-920-firewall-config/access-trustsec.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2019/01/26/cisco-trustsec-on-asa-firewall/" target="_blank" rel="noopener"&gt;https://integratingit.wordpress.com/2019/01/26/cisco-trustsec-on-asa-firewall/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 12:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166270#M591420</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-27T12:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166465#M591430</link>
      <description>&lt;P&gt;It's a much better experience to migrate to Firepower and use pxGrid to exchange SGT info instead.&amp;nbsp; Is there a requirement to still use an ASA?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 11:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5166465#M591430</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-08-27T11:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167465#M591515</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;. Although Cisco does not officially mention (based on your first link you have provided) supportability of RADIUS Cisco AVP's &lt;STRONG&gt;CTS Request&lt;/STRONG&gt; push from ISE to ASA, but, based on testing this situation in my lab, the following event occurs after ISE pushes CoA to ASA:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1724917330706.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227285iCFC359A43C5F6B40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rezaalikhani_0-1724917330706.png" alt="rezaalikhani_0-1724917330706.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From ASA perspective:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_1-1724917433019.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/227286i7DA04CC0CC37725B/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_1-1724917433019.png" alt="rezaalikhani_1-1724917433019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see above, although ASA has received the &lt;STRONG&gt;CoA Request&lt;/STRONG&gt; from ISE (192.168.10.120), it does not respond back.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167465#M591515</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-08-29T07:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167467#M591516</link>
      <description>&lt;P&gt;Just for learning purpose...&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167467#M591516</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-08-29T07:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167487#M591520</link>
      <description>&lt;P&gt;Hi&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt; I believe CoA is only supported on the ASA for posture and not TrustSec integration. The guide above was for the latest version 9.20, so if that does not state CoA is supported it probably is not. The release notes for all ASA versions seem to confirm that also.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/asa_new_features.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/roadmap/asa_new_features.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 08:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167487#M591520</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-08-29T08:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing TrustSec Configuration changes to ASA by CoA. Supported?</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167494#M591522</link>
      <description>&lt;P&gt;Yes, it is true. My testing proves this...&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 08:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-trustsec-configuration-changes-to-asa-by-coa-supported/m-p/5167494#M591522</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-08-29T08:19:22Z</dc:date>
    </item>
  </channel>
</rss>

