<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA CoA problem with ISE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/3744587#M9005</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Apologies if this is&amp;nbsp;in the wrong area, but it covers a few.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm setting up RA VPN using Anyconnect client 4.6, ASA headends are 5545's running 9.9. I am also integrating ISE 2.4.&lt;BR /&gt;The clients currently authenticate via certificate on the ASA, then with AD credentials via ISE, this all seems to work nicely. The problem comes when I try to set up posturing/compliance, I can get the posturing module to find the policy server, and redirect url for provisioning works, and also DACL is enforced whilst client is in an 'unknown compliance' authorisation profile. However when the client finishes successful compliancy scan and sends result to ISE, the ISE then sends a CoA request to the ASA for that particular session, as expected, but the ASA logs 'CoA (Action type 43) from 'ISE server ip' failed for user 'username', with session ID 'session id'. Action not supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Wireshark shows it sending AVP subscriber:command=reauthentcicate, and coa-push+true amongst others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The Cisco docs say the log means the packet is correctly formed but the action is unsupported, I'm using the default Cisco device profile on ISE with CoA settings. If I send a CoA terminate session request from ISE, it is successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I'm struggling to find any similar problem online and I don't have much experience with CoA, so I'm thinking I've maybe set something up wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Anyone got any ideas? Would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:27:39 GMT</pubDate>
    <dc:creator>DAVIES604</dc:creator>
    <dc:date>2020-02-21T16:27:39Z</dc:date>
    <item>
      <title>ASA CoA problem with ISE</title>
      <link>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/3744587#M9005</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Apologies if this is&amp;nbsp;in the wrong area, but it covers a few.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm setting up RA VPN using Anyconnect client 4.6, ASA headends are 5545's running 9.9. I am also integrating ISE 2.4.&lt;BR /&gt;The clients currently authenticate via certificate on the ASA, then with AD credentials via ISE, this all seems to work nicely. The problem comes when I try to set up posturing/compliance, I can get the posturing module to find the policy server, and redirect url for provisioning works, and also DACL is enforced whilst client is in an 'unknown compliance' authorisation profile. However when the client finishes successful compliancy scan and sends result to ISE, the ISE then sends a CoA request to the ASA for that particular session, as expected, but the ASA logs 'CoA (Action type 43) from 'ISE server ip' failed for user 'username', with session ID 'session id'. Action not supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Wireshark shows it sending AVP subscriber:command=reauthentcicate, and coa-push+true amongst others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The Cisco docs say the log means the packet is correctly formed but the action is unsupported, I'm using the default Cisco device profile on ISE with CoA settings. If I send a CoA terminate session request from ISE, it is successful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I'm struggling to find any similar problem online and I don't have much experience with CoA, so I'm thinking I've maybe set something up wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Anyone got any ideas? Would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/3744587#M9005</guid>
      <dc:creator>DAVIES604</dc:creator>
      <dc:date>2020-02-21T16:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CoA problem with ISE</title>
      <link>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/5172420#M1115619</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;109104 error : CoA failed, Action not supported&lt;/PRE&gt;&lt;P&gt;usually occurs because that RADIUS server is in FAILED state in (another) AAA group on the ASA.&lt;/P&gt;&lt;P&gt;check &lt;STRONG&gt;show aaa-servers &lt;/STRONG&gt;output&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/5172420#M1115619</guid>
      <dc:creator>networksi08690</dc:creator>
      <dc:date>2024-09-06T12:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CoA problem with ISE</title>
      <link>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/5172511#M1115621</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1112937"&gt;@networksi08690&lt;/a&gt; the original post is 6 years old. I would hope they figured it out by now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 15:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-coa-problem-with-ise/m-p/5172511#M1115621</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2024-09-06T15:57:58Z</dc:date>
    </item>
  </channel>
</rss>

