<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius CoA not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5292078#M596384</link>
    <description>&lt;P&gt;Anyone have any other thoughts on how I can proceed?&lt;/P&gt;</description>
    <pubDate>Mon, 19 May 2025 18:30:37 GMT</pubDate>
    <dc:creator>BlackDiamond71</dc:creator>
    <dc:date>2025-05-19T18:30:37Z</dc:date>
    <item>
      <title>Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290411#M596323</link>
      <description>&lt;P&gt;I have Cisco ISE setup using IBNS 2.0 but without Radius DTLS and CoA seemed to work fine. I converted it to Radius DTLS and when I did that, I can no longer do CoA commands via the endpoints page of Cisco ISE. I included the names of the trustpoints below and the dynamic author settings. Any thoughts on what I am doing wrong?&lt;/P&gt;&lt;P&gt;show crypto pki certificates pem&lt;/P&gt;&lt;P&gt;------Trustpoint: SWITCH-V2-SELF-SIGNED------ (I created on the switch)&lt;/P&gt;&lt;P&gt;------Trustpoint: ise1.domain.com------&lt;/P&gt;&lt;P&gt;------Trustpoint: ise2.domain.com------&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;client 192.168.1.5 dtls client-tp SWITCH-V2-SELF-SIGNED server-tp ise1.domain.com&lt;/P&gt;&lt;P&gt;client 192.168.1.6 dtls client-tp SWITCH-V2-SELF-SIGNED server-tp ise2.domain.com&lt;/P&gt;&lt;P&gt;radius server ISE01&lt;BR /&gt;address ipv4 192.168.1.5&lt;BR /&gt;automate-tester username [test-user] ignore-acct-port probe-on&lt;BR /&gt;dtls port 2083&lt;BR /&gt;dtls trustpoint client SWITCH-V2-SELF-SIGNED&lt;BR /&gt;dtls trustpoint server ise1.domain.com&lt;BR /&gt;dtls match-server-identity hostname ise1.domain.com&lt;BR /&gt;dtls match-server-identity ip-address 192.168.1.5&lt;BR /&gt;!&lt;BR /&gt;radius server ISE02&lt;BR /&gt;address ipv4 192.168.1.6&lt;BR /&gt;automate-tester username [test-user] ignore-acct-port probe-on&lt;BR /&gt;dtls port 2083&lt;BR /&gt;dtls trustpoint client SWITCH-V2-SELF-SIGNED&lt;BR /&gt;dtls trustpoint server ise2.domain.com&lt;BR /&gt;dtls match-server-identity hostname ise2.domain.com&lt;BR /&gt;dtls match-server-identity ip-address 192.168.1.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5417 Dynamic Authorization failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;11103 RADIUS-Client encountered error during processing flow&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Resolution&lt;/TD&gt;&lt;TD&gt;Do the following: 1) Verify shared secret matches on the ISE Server and corresponding AAA Client, External AAA Server or External RADIUS Token Server. 2) Check the AAA Client or External Server for hardware problems. 3) Check the network devices that connect the AAA peer to ISE for hardware problems. 4) Check whether the network device or AAA Client has any known RADIUS compatibility issues.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Root cause&lt;/TD&gt;&lt;TD&gt;RADIUS-Client encountered an error during processing flow&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;H3&gt;&lt;SPAN&gt;Steps&lt;/SPAN&gt;&lt;/H3&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Step ID&lt;/TD&gt;&lt;TD&gt;Description&lt;/TD&gt;&lt;TD&gt;Latency (ms)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11203&lt;/TD&gt;&lt;TD&gt;Received disconnect and port bounce dynamic authorization request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11219&lt;/TD&gt;&lt;TD&gt;Prepared the disconnect and port bounce dynamic authorization request&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11100&lt;/TD&gt;&lt;TD&gt;RADIUS-Client about to send request - ( port = 2083 , type = Cisco CoA )&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;91055&lt;/TD&gt;&lt;TD&gt;RADIUS packet is encrypted&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;11103&lt;/TD&gt;&lt;TD&gt;RADIUS-Client encountered error during processing flow&lt;/TD&gt;&lt;TD&gt;120001&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 13 May 2025 19:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290411#M596323</guid>
      <dc:creator>BlackDiamond71</dc:creator>
      <dc:date>2025-05-13T19:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290674#M596327</link>
      <description>&lt;P&gt;I did some digging and I think I had this backwards, so I changed it to show this (Below). I looked at the error and it shows 1700 even though I have "Radius DLTS" checked. Could this be a bug as it shows it is sending over the wrong port?&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;client 192.168.1.5 dtls client-tp ise1.domain.com server-tp SWITCH-V2-SELF-SIGNED&lt;/P&gt;&lt;P&gt;client 192.168.1.6 dtls client-tp ise2.domain.com server-tp SWITCH-V2-SELF-SIGNED&lt;/P&gt;&lt;H3&gt;&lt;SPAN&gt;Steps&lt;/SPAN&gt;&lt;/H3&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Step ID&lt;/TD&gt;&lt;TD&gt;Description&lt;/TD&gt;&lt;TD&gt;Latency (ms)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11203&lt;/TD&gt;&lt;TD&gt;Received disconnect and port bounce dynamic authorization request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11219&lt;/TD&gt;&lt;TD&gt;Prepared the disconnect and port bounce dynamic authorization request&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11100&lt;/TD&gt;&lt;TD&gt;RADIUS-Client about to send request - ( port = 1700 , type = Cisco CoA )&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;11104&lt;/TD&gt;&lt;TD&gt;RADIUS-Client request timeout expired&lt;/TD&gt;&lt;TD&gt;15011&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11213&lt;/TD&gt;&lt;TD&gt;No response received from Network Access Device after sending a Dynamic Authorization request&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 14 May 2025 13:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290674#M596327</guid>
      <dc:creator>BlackDiamond71</dc:creator>
      <dc:date>2025-05-14T13:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290698#M596329</link>
      <description>&lt;P&gt;Do either of these match what you are seeing? Both have been updated today but neither have a fixed ISE release.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwn76670" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCwn76670&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvv20753" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCvv20753&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 15:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290698#M596329</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2025-05-14T15:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290712#M596330</link>
      <description>&lt;P&gt;Seems likely that it is related. From the switch I also Ran these codes and I get "User successfully authenticated"&lt;BR /&gt;test aaa group ISE-RADIUS server name ISE01 username password new-code&lt;/P&gt;&lt;P&gt;test aaa group ISE-RADIUS server name ISE02 username password new-code&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Version:&lt;/DIV&gt;&lt;DIV class=""&gt;3.4.0.608&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Patch Information:&lt;/DIV&gt;&lt;DIV class=""&gt;1&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 May 2025 15:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5290712#M596330</guid>
      <dc:creator>BlackDiamond71</dc:creator>
      <dc:date>2025-05-14T15:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5292078#M596384</link>
      <description>&lt;P&gt;Anyone have any other thoughts on how I can proceed?&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2025 18:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5292078#M596384</guid>
      <dc:creator>BlackDiamond71</dc:creator>
      <dc:date>2025-05-19T18:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5292270#M596391</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1868971"&gt;@BlackDiamond71&lt;/a&gt;&amp;nbsp;wonder the intention of having 3 different trustpoints on the switch. Is it because ISE servers have certificates from different CA. In my understanding if signing CA of switch certificate and ISE certificate is same then you just need one trustpoint.&lt;/P&gt;&lt;P&gt;Can you share screen shot of device RADSEC configuration in ISE ? Also enable "debug radius authentication" and "debug radius radsec" and share the logs.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 12:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5292270#M596391</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2025-05-20T12:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Radius CoA not working</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5296225#M596630</link>
      <description>&lt;P&gt;I figured it out, This Document goes in good detail&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-3/configuration_guide/b_163_consolidated_3850_cg/b_163_consolidated_3850_cg_chapter_01100010.pdf" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-3/configuration_guide/b_163_consolidated_3850_cg/b_163_consolidated_3850_cg_chapter_01100010.pdf&lt;/A&gt;. Essentially, I needed&amp;nbsp;# dtls ip radius source-interface vlanX, where X is the vlan of your Cisco ISE Servers&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 15:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-coa-not-working/m-p/5296225#M596630</guid>
      <dc:creator>BlackDiamond71</dc:creator>
      <dc:date>2025-06-03T15:04:28Z</dc:date>
    </item>
  </channel>
</rss>

