<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot get CoA switch to bounce port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478446#M87737</link>
    <description>&lt;P&gt;Hi, I am trying to clear up a VLAN change/IP addressing conflict and have configured the profile's associated CoA type to 'port bounce'. I also created an exception action to force CoA with an associate rule in the policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the device hit the correct profile upon MAB, and the correct VLAN is applied to the port. However, I never see the port bounce occuring, so the deviec does not know to release/renew it's IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something I'm missing to get the CoA port bounce to happen? Here is my switchport config...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;&lt;P&gt; description ISE_TEST&lt;/P&gt;&lt;P&gt; switchport access vlan 32&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 64&lt;/P&gt;&lt;P&gt; ip access-group ACL-ALLOW in&lt;/P&gt;&lt;P&gt; logging event link-status&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2700&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer restart 600&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation restrict&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; service-policy input QoS-Input-Policy&lt;/P&gt;&lt;P&gt; service-policy output QoS-Host-Port-Output-Policy&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:27:22 GMT</pubDate>
    <dc:creator>Josh Morris</dc:creator>
    <dc:date>2019-03-11T04:27:22Z</dc:date>
    <item>
      <title>Cannot get CoA switch to bounce port</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478446#M87737</link>
      <description>&lt;P&gt;Hi, I am trying to clear up a VLAN change/IP addressing conflict and have configured the profile's associated CoA type to 'port bounce'. I also created an exception action to force CoA with an associate rule in the policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the device hit the correct profile upon MAB, and the correct VLAN is applied to the port. However, I never see the port bounce occuring, so the deviec does not know to release/renew it's IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something I'm missing to get the CoA port bounce to happen? Here is my switchport config...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;&lt;P&gt; description ISE_TEST&lt;/P&gt;&lt;P&gt; switchport access vlan 32&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 64&lt;/P&gt;&lt;P&gt; ip access-group ACL-ALLOW in&lt;/P&gt;&lt;P&gt; logging event link-status&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2700&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication order dot1x mab&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer restart 600&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation restrict&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; service-policy input QoS-Input-Policy&lt;/P&gt;&lt;P&gt; service-policy output QoS-Host-Port-Output-Policy&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478446#M87737</guid>
      <dc:creator>Josh Morris</dc:creator>
      <dc:date>2019-03-11T04:27:22Z</dc:date>
    </item>
    <item>
      <title>please see the Port Bounce</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478447#M87739</link>
      <description>&lt;P&gt;please see the Port Bounce Configuration guide:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_prof_pol.html#wp2021892&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 06:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478447#M87739</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2014-03-12T06:06:58Z</dc:date>
    </item>
    <item>
      <title>Did you fix this?</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478448#M87742</link>
      <description>Did you fix this?</description>
      <pubDate>Sat, 31 May 2014 22:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478448#M87742</guid>
      <dc:creator>bikespace</dc:creator>
      <dc:date>2014-05-31T22:28:24Z</dc:date>
    </item>
    <item>
      <title>I did, but my issue was not</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478449#M87747</link>
      <description>&lt;P&gt;I did, but my issue was not related to the port bounce itself. It was because arp inspection was identifying the arp based off the ports initial VLAN. Once ISE changed the VLAN, ip arp was denying the port because the address had changed. I disabled arp inspection and it cleared up the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 15:38:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-get-coa-switch-to-bounce-port/m-p/2478449#M87747</guid>
      <dc:creator>Josh Morris</dc:creator>
      <dc:date>2014-06-04T15:38:20Z</dc:date>
    </item>
  </channel>
</rss>

