<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic At this point all of the end in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224131#M348945</link>
    <description>&lt;P&gt;At this point all of the end-of sales models will not be getting any significant functionality upgrade. That would include the RADIUS CoA that works with ISE.&lt;/P&gt;&lt;P&gt;Once a product goes end of sales (as they did back last September), generally any new software releases that come out are for bug fixes.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2014 22:48:04 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-07-14T22:48:04Z</dc:date>
    <item>
      <title>ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224122#M348936</link>
      <description>&lt;P&gt;Does anyone know if ASA 9.x code supports &lt;SPAN style="font-size: 10pt;"&gt;Change of Authorization (CoA). I have looked through the release notes and can't find anything. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224122#M348936</guid>
      <dc:creator>jrobey284</dc:creator>
      <dc:date>2019-03-12T01:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224123#M348937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does not yet support it. Last I heard it would be later this year - possibly in 9.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now you need to put an ISE IPEP inline to get CoA for VPN users using an ASA headend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 20:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224123#M348937</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-05-30T20:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224124#M348938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any update on CoA support on ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any plans to make CoA feature as open standard ? so that customers having non-Cisco products can benefit from advanced ISE features such as Posture assessment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akhtar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 07:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224124#M348938</guid>
      <dc:creator>Akhtar Samo</dc:creator>
      <dc:date>2013-11-25T07:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224125#M348939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last I heard, it's still projected for 9.2. Haven't heard the exact date yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt it would be made an open standard as it is a competitive differentiator.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 14:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224125#M348939</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-11-25T14:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224126#M348940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem in implementing CoA and MAB is when it comes to customers buying ISE and having a multivendor environment (Juniper/Nortel switches) are left with only ISE's authentication functionality on end points. I know they have an option for IPEP but that doesn't make sense for a client having high number of non-cisco switches connected to end points.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhtar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 10:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224126#M348940</guid>
      <dc:creator>Akhtar Samo</dc:creator>
      <dc:date>2013-11-27T10:31:56Z</dc:date>
    </item>
    <item>
      <title>ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224127#M348941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so as of 2 days ago, the latest I have heard about the ASA update is 1st Quarter of this year. Now, I will of course take this with a grain of salt, as we have been told this CoA update would be coming for 2 years. Last I had heard before this was by the end of this year.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way, I just read there is a vulnerability in RADIUS CoA on the ASA? How can there be a vulnerability in something that isn't supported? &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0655"&gt;http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0655&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I am not thinking of the same thing? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But whatever it is, I am still very anxious to get this update working, because having to have the IPN between the ASA traffic and the network has caused a few kinks in my moving our ASA into a firewall role on top of the current VPN role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dirk&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Jan 2014 16:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224127#M348941</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2014-01-26T16:29:06Z</dc:date>
    </item>
    <item>
      <title>ASA 9.0 support for CoA</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224128#M348942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the same vulnerability when searching for CoA support. Not sure what to make of that. Hoping we get CoA support soon. Is there any reference as to how to this interoperates with ISE and AuthZ rules etc..? What is the use case scenario?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 21:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224128#M348942</guid>
      <dc:creator>Jacob Gibb</dc:creator>
      <dc:date>2014-02-18T21:53:11Z</dc:date>
    </item>
    <item>
      <title>Of course it has now been</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224129#M348943</link>
      <description>&lt;P&gt;Of course it has now been revised to 1st half of this year, sure to slip again to 2nd half.&lt;/P&gt;&lt;P&gt;Use scenario is, as we are using it today, we have to have a physical ISE (IPN) Inline Posture Node to handle the CoA because that function is not native in the ASA.&lt;/P&gt;&lt;P&gt;So a user connects with Anyconnect, (and they have Cisco NAC installed), the NAC agent then contacts the ISE policy server to see what rules it needs to check and comply with, then ISE policy server says if you meet these rules then we check what 'group' you belong to, in order to determine what ACL is assigned.&lt;/P&gt;&lt;P&gt;The planned change will eliminate the need for the IPN and ISE server to be separate devices. Right now the IPN HAS to be physical, and our ISE Policy server is a VM. So when all this is updated we can remove the VM and only have the physical device, but it no longer has to be INLINE for the ASA VPN Posture functions.&lt;/P&gt;&lt;P&gt;Also, was told that ISE v1.3 will be required in addition to the ASA update.&lt;/P&gt;&lt;P&gt;So for this to work BOTH need to be released.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 14:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224129#M348943</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2014-03-12T14:42:30Z</dc:date>
    </item>
    <item>
      <title>It appears that the CoA is in</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224130#M348944</link>
      <description>&lt;P&gt;It appears that the CoA is in version 9.2.1. As far as I can tell, the 5500 non-x models stop at 9.1. Is there not going to be a maintenance 9.1 release to include CoA for non-x ASAs?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 22:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224130#M348944</guid>
      <dc:creator>MARK BAKER</dc:creator>
      <dc:date>2014-07-14T22:33:34Z</dc:date>
    </item>
    <item>
      <title>At this point all of the end</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224131#M348945</link>
      <description>&lt;P&gt;At this point all of the end-of sales models will not be getting any significant functionality upgrade. That would include the RADIUS CoA that works with ISE.&lt;/P&gt;&lt;P&gt;Once a product goes end of sales (as they did back last September), generally any new software releases that come out are for bug fixes.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 22:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-0-support-for-coa/m-p/2224131#M348945</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-07-14T22:48:04Z</dc:date>
    </item>
  </channel>
</rss>

