<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Printer COA vlan Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351173#M599147</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Version&amp;nbsp; 17.06.03, yes we have policies in places. see attachment.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hani&lt;/P&gt;</description>
    <pubDate>Mon, 01 Dec 2025 14:58:47 GMT</pubDate>
    <dc:creator>hanis2903</dc:creator>
    <dc:date>2025-12-01T14:58:47Z</dc:date>
    <item>
      <title>Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350763#M599123</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am having a weird issue with ISE 3.4 Patch 3. Printers is not getting vlan changed when it is pushed via COA. It clearly shows on the authentication session that it is pushing the correct vlan but the ip did not change and switch to unknow. I tried to reboot same issue. we tried different printers models like HP Zebra but same behavior. We tried to plug a pc instead and it worked right away. So looks like something related to printers. We are using Cisco sw 9300 models.&lt;/P&gt;&lt;P&gt;we are using IBNS2 and apply template on the port. Any suggestions?&lt;/P&gt;&lt;P&gt;Thank you ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hani,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 17:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350763#M599123</guid>
      <dc:creator>hanis2903</dc:creator>
      <dc:date>2025-11-28T17:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350768#M599124</link>
      <description>&lt;P&gt;What version of code is running on Cat 9300 models? Is this issue after upgrading to ISE 3.4pat3 or after a fresh installation?&lt;/P&gt;
&lt;P&gt;What session details are shown for that port? Is this for MAB? Also, what do the radius live logs show?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 18:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350768#M599124</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-28T18:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350789#M599127</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are running&amp;nbsp; 17.06.03 version. I can not tell if this is after upgrading because we just have a fresh deploy on this version of ISE.&lt;/P&gt;&lt;P&gt;NA-CAN-MTL-IDF7-ACC-SW1#sho authentication sessions int gi4/0/20 det&lt;BR /&gt;Interface: GigabitEthernet4/0/20&lt;BR /&gt;IIF-ID: 0x165D8B63&lt;BR /&gt;MAC Address: 80e8.2c7a.7ee9&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: 80-E8-2C-7A-7E-E9&lt;BR /&gt;Device-type: HP-Device&lt;BR /&gt;Device-name: MTL-PRN093&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Acct update timeout: 172800s (local), Remaining: 172798s&lt;BR /&gt;Common Session ID: 0C00F00A000025FFCBBEA876&lt;BR /&gt;Acct Session ID: 0x0000086c&lt;BR /&gt;Handle: 0xc100071f&lt;BR /&gt;Current Policy: DOT1X_MAB_POLICY&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: 150&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hani,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 18:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350789#M599127</guid>
      <dc:creator>hanis2903</dc:creator>
      <dc:date>2025-11-28T18:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350795#M599128</link>
      <description>&lt;P&gt;How does your configuration look globally and at the port level?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 23:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350795#M599128</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-28T23:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350825#M599129</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Is the printer getting an IP prior to authorization? If so, the printer will retain this DHCP lease even if its nic is bounced.&lt;/P&gt;&lt;P&gt;I've seen this behaviour across all printer vendors.&lt;/P&gt;&lt;P&gt;Try reducing the DHCP lease time of the landing VLAN to a matter of minutes so that the printer will request a new IP on its authorization vlan.&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 09:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350825#M599129</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2025-11-29T09:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350837#M599130</link>
      <description>&lt;P&gt;Hi, but how come it works perfectly with a PC? no need to touch the DHCP. Also if you manually config the new vlan let say 150 on the switchport it gets and ip immediately from that vlan (150) so the same behavior ISE is doing pushing the vlan 150 via COA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the global config:&lt;/P&gt;&lt;P&gt;template WIRED_DOT1X_OPEN&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;access-session host-mode multi-domain&lt;/P&gt;&lt;P&gt;access-session port-control auto&lt;/P&gt;&lt;P&gt;access-session control-direction in&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 7&lt;/P&gt;&lt;P&gt;dot1x max-reauth-req 2&lt;/P&gt;&lt;P&gt;dot1x timeout quiet-period 300&lt;/P&gt;&lt;P&gt;dot1x timeout held-period 300&lt;/P&gt;&lt;P&gt;authentication periodic&lt;/P&gt;&lt;P&gt;authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt;service-policy type control subscriber DOT1X_MAB_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/0/20&lt;BR /&gt;description Printer&lt;BR /&gt;switchport access vlan 100&lt;BR /&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;no logging event link-status&lt;BR /&gt;storm-control broadcast level 50.00&lt;BR /&gt;storm-control multicast level 30.00&lt;BR /&gt;storm-control action trap&lt;BR /&gt;source template WIRED_DOT1X_OPEN&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip dhcp snooping limit rate 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hani,&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 12:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350837#M599130</guid>
      <dc:creator>hanis2903</dc:creator>
      <dc:date>2025-11-29T12:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350846#M599131</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;the thread below discusses how windows 802.1x supplicant detects a vlan change&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/dynamic-vlan-behavor/td-p/4589001" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/dynamic-vlan-behavor/td-p/4589001&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The output you posted shows that you are using mab for the printer - does the printer support 802.1x? If so, maybe the printer's 802.1x supplicant would support detection of a vlan change?&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 12:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350846#M599131</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2025-11-29T12:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350888#M599132</link>
      <description>&lt;P&gt;suggest refer -&amp;nbsp;&lt;/P&gt;
&lt;H5 id="toc-hId-528884011"&gt;IBNS 2.0 Policy and Interface Configuration&lt;/H5&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 18:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5350888#M599132</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-11-29T18:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351100#M599140</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes you are right the printer only support MAB, but the policy it doing both, dot1x first then MAB. So is there something special to it should be be excluded from Trying MAB and apply a different policy on the port level to only do MAB?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hani,&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 12:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351100#M599140</guid>
      <dc:creator>hanis2903</dc:creator>
      <dc:date>2025-12-01T12:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351127#M599141</link>
      <description>&lt;P&gt;It's not necessary; you can have the order supplier authenticate, and if it doesn't work in time, move to MAB. Could you make sure you have policies or a trusted MAC address-based authentication in place? What is the version of IOS XE?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 13:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351127#M599141</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-12-01T13:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Printer COA vlan Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351173#M599147</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Version&amp;nbsp; 17.06.03, yes we have policies in places. see attachment.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hani&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 14:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/printer-coa-vlan-issue/m-p/5351173#M599147</guid>
      <dc:creator>hanis2903</dc:creator>
      <dc:date>2025-12-01T14:58:47Z</dc:date>
    </item>
  </channel>
</rss>

