<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE and Switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203843#M592205</link>
    <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;Understand that, i dont expect it to be in realtime but the fact is it should update in certain intervals like what you said reauthentication (switch setting or Authz profile), but isnt it the CoA also will be doing this as well to initial the changes to NAD (push) if there is authorization profile changes?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Oct 2024 14:39:22 GMT</pubDate>
    <dc:creator>wayne loh</dc:creator>
    <dc:date>2024-10-05T14:39:22Z</dc:date>
    <item>
      <title>Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203792#M592201</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have weird issue recently on Cisco ISE and need to seek for some advise. I have deployed the Cisco ISE and switches to adapt the dot1x and mab authentication. however I notice each authorization policy changes will not immediately take effect, even after some period of time and i need to shut the port/interface and no shut again in order for it to work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone facing such issue or did I miss any configuration?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 10:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203792#M592201</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2024-10-05T10:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203818#M592202</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/328964"&gt;@wayne loh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This is configuration related. Look for COA port bounce. I am sharing this link for reference but pretty for there will be plenty.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/ios-xml/ios/san/configuration/15-e/san-coa-supp.html#GUID-02AC45FF-2D37-4315-BD85-A88035DDC288" target="_blank"&gt;https://www.cisco.com/en/US/docs/ios-xml/ios/san/configuration/15-e/san-coa-supp.html#GUID-02AC45FF-2D37-4315-BD85-A88035DDC288&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 12:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203818#M592202</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-05T12:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203823#M592203</link>
      <description>&lt;P&gt;Show authentication session interface x/x&lt;/P&gt;
&lt;P&gt;Show authentication session interface x/x detail&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share this please&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show aaa server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share these please&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 13:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203823#M592203</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-05T13:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203825#M592204</link>
      <description>&lt;P&gt;ISE is a RADIUS protocol server. RADIUS is a request/response protocol upon session initiation or timeout. Policy is not updated in realtime across network devices everytime you make a little change. That would cause a massive spike in your RADIUS traffic everytime you made a change.&lt;/P&gt;
&lt;P&gt;Reauthentication should occur when each existing session times out. Are you setting a reauthentication timer or session-timeout in your authorization profile?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 13:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203825#M592204</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-10-05T13:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203843#M592205</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;Understand that, i dont expect it to be in realtime but the fact is it should update in certain intervals like what you said reauthentication (switch setting or Authz profile), but isnt it the CoA also will be doing this as well to initial the changes to NAD (push) if there is authorization profile changes?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 14:39:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203843#M592205</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2024-10-05T14:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE and Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203930#M592207</link>
      <description>&lt;P&gt;As Flavio hinted, the issue is most likely the CoA is not configured correctly. Check that the dynamic-authorization on the switch is configured with the IP address of the ISE PSN, and using the same shared secret. Plus, also specify the source interface and a VRF (if used) for RADIUS traffic. Test the CoA via ISE Context Visibility.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 20:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-and-switch/m-p/5203930#M592207</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-10-05T20:27:29Z</dc:date>
    </item>
  </channel>
</rss>

