<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unfortunatly not... An in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428961#M87624</link>
    <description>&lt;P&gt;Unfortunatly not... An upgrade to 1.4 patch 3 and WLC 8.1 helped finally, for whatever reason...&lt;/P&gt;&lt;P&gt;Did you find any other solution?&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2015 16:15:20 GMT</pubDate>
    <dc:creator>mstraessle</dc:creator>
    <dc:date>2015-09-01T16:15:20Z</dc:date>
    <item>
      <title>Dynamic Authorization Failed: DiconnectNAK</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428957#M87619</link>
      <description>&lt;P&gt;I have WLC 7.6 and ISE 1.2 Patch 6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My use case is WLAN Guest Access with CWA. I have ISE Appliance 3395 (2 Admin/Mon, 2 PSN). Everything work fine so far. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But from time to time I get these strange message (it does not matter if I do a manual Session termination in the Operations Tab) Everything is configured in the right way, since normal CWA works (CoA is working fine, but not always...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here the corresponding Log-Entry:&lt;/P&gt;&lt;P&gt;0000001241 2 0 2014-02-28 11:11:37.241 +01:00 0000106595 5417 &lt;SPAN style="color: #ff0000;"&gt;NOTICE Dynamic-Authorization: Dynamic Authorization failed,&lt;/SPAN&gt; ConfigVersionId=53, Device IP Address=a.b.c.d, Device Port=42121, DestinationIPAddress=a.b.c.d, DestinationPort=1700, RadiusPacketType=DisconnectRequest, Protocol=Radius, RequestLatency=3, NetworkDeviceName=xx-WLC01, NAS-IP-Address=172.16.226.26, Calling-Station-ID=1C:AB:A7:96:7B:99, Acct-Session-Id=53105c2a/1c:ab:a7:96:7b:99/336136, Acct-Terminate-Cause=Admin Reset, Event-Timestamp=1393582297, cisco-av-pair=audit-session-id=ac10e21a00052f6953105f07, AcsSessionID=ise-04/182359788/9392, Step=11044, Step=11017, Step=11100, Step=11101, Step=11048, NetworkDeviceGroups=Location#All Locations#xx_VPN, NetworkDeviceGroups=Device Type#All Device Types#Wireless Devices#WLC Foreign, CPMSessionID=ac10e21a00052f6953105f07, EndPointMACAddress=1C-AB-A7-96-7B-99, Location=Location#All Locations#xx_VPN,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody ever had the same expirence, or is this a know issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for feedback!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/6/7/181762-CoA-Problem.png" alt="CoA-Problem.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428957#M87619</guid>
      <dc:creator>mstraessle</dc:creator>
      <dc:date>2019-03-11T04:28:34Z</dc:date>
    </item>
    <item>
      <title>Dynamic Authorization Failed: DiconnectNAK</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428958#M87620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please go through the link below for best practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.redelijkheid.com/blog/2013/4/2/cisco-ise-change-of-authorization-coa-not-working"&gt;http://www.redelijkheid.com/blog/2013/4/2/cisco-ise-change-of-authorization-coa-not-working&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Mar 2014 03:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428958#M87620</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2014-03-03T03:15:38Z</dc:date>
    </item>
    <item>
      <title>Hi mstraessle, I have also</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428959#M87621</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A about="/users/mstraessle" class="username" datatype="" href="https://supportforums.cisco.com/users/mstraessle" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;mstraessle&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also facing the same issue with wlc 7.6.130 and ISE 1.2.0.899 patch 7 .Do you found any solution for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2015 11:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428959#M87621</guid>
      <dc:creator>Pranav Gade</dc:creator>
      <dc:date>2015-02-23T11:34:37Z</dc:date>
    </item>
    <item>
      <title>Not sure if this will help</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428960#M87622</link>
      <description>&lt;P&gt;Not sure if this will help you in particular, but I was consistently having this issue with ISE 1.3 and WLC running 7.6.&lt;/P&gt;&lt;P&gt;After a device would go through provisioning and then posture assessment ISE would clear them for access. I would get this error and looking on the WLC client detail see that the device was still in Posture_REQ state and would still have the web redirect URL. I could manually 'fix' this by having the device disconnect and reconnect to the wireless, they would then be assigned the proper authz profile and access.&lt;/P&gt;&lt;P&gt;After much troubleshooting and trying to tear out non-existent hair I discovered I had forgotten to check the RFC 3576 box under the radius server entry for ISE on the WLC. As soon as I did CoA started working 100%.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 14:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428960#M87622</guid>
      <dc:creator>Stephen Means</dc:creator>
      <dc:date>2015-07-17T14:05:37Z</dc:date>
    </item>
    <item>
      <title>Unfortunatly not... An</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428961#M87624</link>
      <description>&lt;P&gt;Unfortunatly not... An upgrade to 1.4 patch 3 and WLC 8.1 helped finally, for whatever reason...&lt;/P&gt;&lt;P&gt;Did you find any other solution?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 16:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428961#M87624</guid>
      <dc:creator>mstraessle</dc:creator>
      <dc:date>2015-09-01T16:15:20Z</dc:date>
    </item>
    <item>
      <title>Ciao,</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428962#M87627</link>
      <description>&lt;P&gt;Ciao,&lt;/P&gt;
&lt;P&gt;with ISE 2.0 patch 2 (2x 3495) and WLC 5508 8.1.131 I've the same problem. On WLC with&amp;nbsp;RADIUS debug activates the CoA is working: but&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;Received a 'CoA-Request' from 172.17.2.243 port 65393&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;Handling a valid 'CoA-Request' regarding station 64:b8:53:fe:95:03&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;*radiusCoASupportTransportThread: Feb 10 15:31:33.448: 64:b8:53:fe:95:03 Reauthenticating station 64:b8:53:fe:95:03&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;*radiusCoASupportTransportThread: Feb 10 15:31:33.448: Sent a 'CoA-Ack' to 172.17.2.243 (port:65393)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;but on ISE I received:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;5417 Dynamic Authorization failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier, monospace;"&gt;11103 RADIUS-Client encountered error during processing flow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"&gt;On clients everything works fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: arial, helvetica, sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2016 15:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-authorization-failed-diconnectnak/m-p/2428962#M87627</guid>
      <dc:creator>ipagliani</dc:creator>
      <dc:date>2016-03-01T15:44:05Z</dc:date>
    </item>
  </channel>
</rss>

