<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with CoA? ISE 2.7/9800-80 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444886#M231930</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Grendizer,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can confirm that is working now as you have stated, my config is below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;webauth-http-enable&lt;BR /&gt;parameter-map type webauth Captive-Bypass-Portal !!this seems to be enabled anyway, not sure if its impacting&lt;BR /&gt;&lt;BR /&gt;no ip http server&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 14:35:10 GMT</pubDate>
    <dc:creator>Brian McPhillips</dc:creator>
    <dc:date>2021-08-05T14:35:10Z</dc:date>
    <item>
      <title>Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437560#M231580</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently we've been working on deploying new 9800-80's and currently have them set up in our test environment, they are running 17.3.3. We are presently using ISE 2.7.0.356 as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've set up a CWA Guest Portal and our redirects are presently working. The user joins the Guest SSID we have created and are presented with the captive portal page. Upon pressing "accept" to gain wireless access, the client is properly moved to the run state and a successful log is placed in the ISE Live Logs saying all is well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem, however, is that the client does not recognize that it has been moved into the run state and does not gain internet access unless the client disassociates from the SSID and re-associates. The client runs into no further issues upon re-association. We've tested this on multiple iPhones running iOS 14.7, a macbook air running OSX_Catalina and three motorola android devices. All exhibit the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking radioactive traces show the clients move through L2 and L3 auth as expected and move into the run state. The only errors generated pertain to 11w not being enabled as this is an open guest SSID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts on what to try would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 22:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437560#M231580</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-22T22:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437584#M231584</link>
      <description>&lt;P&gt;Please make sure overrides and NAC state is enabled under policy profile, also check support for COA is enabled under the Radius servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure if there is any firewalls UDP port 1700 is allowed as well. Also share the Web Auth redirect ACL,&amp;nbsp;remember for the&amp;nbsp;&lt;SPAN&gt;redirection ACL&amp;nbsp;&lt;/SPAN&gt;deny&amp;nbsp;action is deny redirection (not deny traffic), and&amp;nbsp;permit&lt;SPAN&gt;&amp;nbsp;action as permit redirection.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 00:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437584#M231584</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-07-23T00:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437594#M231585</link>
      <description>&lt;P&gt;Hi Arshadsaf,&lt;/P&gt;&lt;P&gt;Here is what my policy tag looks like, all of those options are enabled&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://i.imgur.com/cicWIUV.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;Additionally, we've checked our testing PA Firewall and can see that port 1700 is not being blocked. We see ISE successfully communicating over UDP port 1700. ISE also appears to be acknowledging that the WLC has replied.&lt;/P&gt;&lt;P&gt;Below is our generalized punt ACL for web auth redirection. We've tinkered with this a lot and admit that it's certainly very generalized and just enough to get the client to hit get the Hotspot Guest Portal (IP has been blurred.)&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://i.imgur.com/yUs5D3V.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;This ACL seems to "work" and users do get to the Hotspot Guest portal on all of the devices we've tested. They scroll down, press "accept" and get a confirmation screen that says, "You've connected to the network".&lt;/P&gt;&lt;P&gt;During this, I see the client move to the "RUN" state on the WLC and a successful authentication log is produced on ISE.&lt;/P&gt;&lt;P&gt;However, still,&amp;nbsp; the client does not see that it has an internet connection. We do have a deny ACL that is on that policy tag to block internal applications from being accessed by the guest user, but even taking that ACL out of play, the client still doesn't see it as having internet until you manually disconnect from the SSID and rejoin.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 01:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437594#M231585</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-23T01:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437604#M231586</link>
      <description>&lt;P&gt;Is the Guest SSID locally switched or centrally switched?&lt;/P&gt;&lt;P&gt;Also make sure to&amp;nbsp;&lt;SPAN&gt;match the ACL name that was entered into ISE on the authorization results. You may find the below community post helpful as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/can-ise-send-a-coa-in-an-authorization-profile/td-p/3454366" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/can-ise-send-a-coa-in-an-authorization-profile/td-p/3454366&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 02:32:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437604#M231586</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-07-23T02:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437706#M231593</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having a similiar Hotspot issue. Android/Apple get a redirect and accept but do not get the successful redirect page. A refresh or browsing to another page confirms internet access. Windows 10 devices do not redirect to the hotspot at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Android/Apple hit the initial redirect policy and then get the PermitAccess Policy, Windows 10 just permanently sit on the redirect policy on ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pretty sure i have everything in place with the 9800 CWA guidelines. I have a TAC logged. I will update if i get a resolution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9800-L 17.3.3&lt;/P&gt;&lt;P&gt;ISE 3.0 Patch 2&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 09:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4437706#M231593</guid>
      <dc:creator>Brian McPhillips</dc:creator>
      <dc:date>2021-07-23T09:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438213#M231621</link>
      <description>&lt;P&gt;The guest SSID is centrally switched. I have that option toggled in the policy as well.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The ACL names match directly (no extra spaces either) and still, no dice.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Also, we are using the same VLAN before and after CoA. There isn’t a separate guest VLAN. The client stays on our specified VLAN as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 14:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438213#M231621</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-24T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438216#M231622</link>
      <description>&lt;P&gt;Hopefully they find a solution that works! We’re still scratching our heads over this. You described perfectly what is occurring as well. If the user clicks, “continue without internet access” and tries to navigate to a page, the client is suddenly aware that it has internet.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will say, however, that our Windows 10 clients move to the proper policy and do not get stuck on the redirect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 14:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438216#M231622</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-24T14:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438272#M231625</link>
      <description>&lt;P&gt;I just confirmed on a 9800-80 where CWA is being used. I can see the Client is getting provided Internet access without any hassles as soon as Captive portal requirements are completed.&amp;nbsp;The only changes I see my ACL is more 5 lines instead of 3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip access-list extended WEB-AUTH-REDIRECT&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;deny ip any host X.X.X.X&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;deny ip host X.X.X.X any&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;deny udp any any eq domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;deny udp any eq domain any&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;permit ip any any &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this doesn't work open a case with TAC. As a matter of fact due to some bugs there were issues on 16.X.X codes where COA was not working, but I have multiple Cat WLC's doing CWA in 17.3.X codes or higher without any issues. PCAP's are the best way troubleshoot Radius related issues always, you can also do a radio active trace and upload it to&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer" target="_blank"&gt;https://cway.cisco.com/wireless-debug-analyzer&lt;/A&gt;&amp;nbsp;to get to know whats happening&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 19:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438272#M231625</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-07-24T19:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438302#M231627</link>
      <description>&lt;P&gt;I will try your ACL when I return to the office on Monday. Will update this post then.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I’ll also try the radioactive trace on the client. Didn’t know about the utility you provided.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jul 2021 01:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4438302#M231627</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-25T01:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4440450#M231722</link>
      <description>&lt;P&gt;A colleague has informed me that patch 3 is released. There seems to be two potential issues I am hitting. Getting some weird cert errors as well even though i have a publically signed cert.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84184" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu84184&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my portal i have a redirect url after successful authentication. That would match this issue below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv52637" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv52637&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have upgraded so will wait for some users to test.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 15:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4440450#M231722</guid>
      <dc:creator>Brian McPhillips</dc:creator>
      <dc:date>2021-07-28T15:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4440696#M231736</link>
      <description>&lt;P&gt;I'll be patching my ISE install tonight. Didn't even think about outstanding patches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will update hopefully tomorrow if this resolves my issue.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 23:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4440696#M231736</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-07-28T23:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444478#M231904</link>
      <description>&lt;P&gt;Unfortunately, even after patching ISE - the issue still persists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, we're out of ideas and will be looping TAC into this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the suggestions everyone.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 20:25:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444478#M231904</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-08-04T20:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444620#M231913</link>
      <description>&lt;P&gt;If you have “&lt;STRONG&gt;no ip http server&lt;/STRONG&gt;” in your config then you need to put it back by using “&lt;STRONG&gt;ip http server&lt;/STRONG&gt;” or you can do the below if you have 17.3 and after:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;parameter-map type webauth global&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;webauth-http-enable&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;the above is required if you have any Web Auth type: CWA, LWA, External LWA&lt;/P&gt;
&lt;P&gt;All details in the 17.3 config guide here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_sec_webauth_cg.html#d209960e4494a1635" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_sec_webauth_cg.html#d209960e4494a1635&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 04:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444620#M231913</guid>
      <dc:creator>Grendizer</dc:creator>
      <dc:date>2021-08-05T04:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444886#M231930</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Grendizer,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can confirm that is working now as you have stated, my config is below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;parameter-map type webauth global&lt;BR /&gt;webauth-http-enable&lt;BR /&gt;parameter-map type webauth Captive-Bypass-Portal !!this seems to be enabled anyway, not sure if its impacting&lt;BR /&gt;&lt;BR /&gt;no ip http server&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 14:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4444886#M231930</guid>
      <dc:creator>Brian McPhillips</dc:creator>
      <dc:date>2021-08-05T14:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445004#M231936</link>
      <description>&lt;P&gt;Hi Grendizer,&lt;/P&gt;&lt;P&gt;I had ran into this previously, but had already made these changes as well. The captive portal is working as expected. My failure occurs here:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://i.imgur.com/7CZp7HZ.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While the page shows "Connection Successful" users have to hit "Cancel" and then "Use without internet".&lt;/P&gt;&lt;P&gt;Immediately upon doing this, the client recognizes that it does have wireless connectivity and they can browse the internet as expected. This holds true for my Macbook as well as my android devices. Users never see that "done" button appear as we would expect. If they don't hit cancel, but toggle their wifi off and then on, the connection works as expected.&lt;/P&gt;&lt;P&gt;We're utilizing one VLAN for our guest network and not attempting to apply a new VLAN after authentication. As far as I am aware, this shouldn't be causing any issues with authentication and the client recognizing it has network.&lt;/P&gt;&lt;P&gt;Before the user hits "cancel" and "Use without internet" the WLC shows them in the "RUN" state and our ISE installation generates a successful Live Log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally, I've ran my configuration through the Wireless Config Analyzer Express (to see if there was anything obviously wrong) and got no results from that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts or guidance is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 16:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445004#M231936</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-08-05T16:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445657#M231972</link>
      <description>&lt;P&gt;Hi Erik,&lt;/P&gt;
&lt;P&gt;1) What is the WLC code: is it 17.3.3 (just for confirmation)?&lt;/P&gt;
&lt;P&gt;2) What are the AP models?&lt;/P&gt;
&lt;P&gt;3) What is the AP mode? Local or Flex? If the AP mode is Flex, does the problem happen with local mode APs too?&lt;/P&gt;
&lt;P&gt;4) Is this Foreign/Anchor scenario?&lt;/P&gt;
&lt;P&gt;5) Is the DHCP external or local, meaning the 9800 is acting as the DHCP or you have external DHCP server?&lt;/P&gt;
&lt;P&gt;6) If you have external DHCP server, where did you configure the ip helper address, from the 9800 or from the connected Switch?&lt;/P&gt;
&lt;P&gt;7) Is the clients VLAN configured on the WLC has a Layer 3 interface or just Layer 2 (I saw many problems with Layer 3 interfaces for client’s subnet and the best practices is to go with Layer 2 interface for all clients unless we need to implement mDNS or DHCP relay or Internal DHCP Server) Best Practices Doc is here: &lt;A href="https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;(((DHCP bridging is the recommended mode)))&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I’m not TAC but I really suspect a DHCP problem here (not from your DHCP server, instead handling the DHCP packets from/to AP-WLC-switch)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to go further to troubleshoot this without TAC, then collect RA trace “radioactive” as explained here &lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213949-wireless-debugging-and-log-collection-on.html#anc13" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213949-wireless-debugging-and-log-collection-on.html#anc13&lt;/A&gt; then verify if you’re seeing the below messages:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Failed to get ewlc dot11 packet handler. Dot11 action processing error. Dropping request&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Skipping DHCP TLVs for further processing. DHCP based classification isn't enabled&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;If that’s the case, then you will see just&lt;/P&gt;
&lt;P&gt;DHCP_DISCOVER&lt;/P&gt;
&lt;P&gt;DHCP_OFFER&lt;/P&gt;
&lt;P&gt;Without DHCP_REQUEST&lt;/P&gt;
&lt;P&gt;Then the client sends another discover because didn’t get an offer.&amp;nbsp;This will validate that you have problem with DHCP handling.&lt;/P&gt;
&lt;P&gt;Oh, I forgot to mention that I did test CWA with ISE 3.0 Patch 2 and Patch 3 and it’s working fine for me with iOS 14.7.1&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 19:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445657#M231972</guid>
      <dc:creator>Grendizer</dc:creator>
      <dc:date>2021-08-06T19:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445675#M231977</link>
      <description>&lt;P&gt;Hi Grendizer,&lt;/P&gt;&lt;P&gt;1. Version is 17.3.3&lt;/P&gt;&lt;P&gt;2. We were initially using an AIR-AP3802i-B-K9, but switched to using AIR-AP2802i-B-K9. I've also tried a 3702, problem persists across models.&lt;/P&gt;&lt;P&gt;3. AP's are in Local Mode, we don't utilize flex.&lt;/P&gt;&lt;P&gt;4. This is not a Foreign/Anchor scenario.&lt;/P&gt;&lt;P&gt;5. We are utilizing our external DHCP server on site.&lt;/P&gt;&lt;P&gt;6. We configured IP helper addresses on each of our Layer 2 VLANS. Additionally, our connected switches do have an ip helper address configured. These IP's match.&lt;/P&gt;&lt;P&gt;7. The client VLANs are configured as a layer 2 interface only. The configuration of one of them looks like such:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;interface Vlan1101&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;description DC WiFi Guest1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ip address 10.18.0.11 255.255.248.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ip helper-address 172.21.64.101&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8. Radioactive Trace is attached, and I unfortunately do not see those statements in there. I ran this through the debug analyzer and don't see anything that sticks out, but will admit that this is a little over my head.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 17:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445675#M231977</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-08-07T17:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445736#M231981</link>
      <description>&lt;P&gt;Ok! Try two (didn't sanitize my debug enough, I've double checked and removed every identifying element in the debug)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. WLC Code is 17.3.3, and we're using ISE 2.7 on Patch 4.&lt;/P&gt;&lt;P&gt;2. We've tried various AP models: a 3802i, 2802i, 3702i, and a 2702i. The issue persists on all of these models.&lt;/P&gt;&lt;P&gt;3. AP mode is Local, as we do not utilize flex.&lt;/P&gt;&lt;P&gt;4. This is not a Foreign/Anchor scenario. The controller is acting alone.&lt;/P&gt;&lt;P&gt;5. DHCP server is external. The 9800 is not acting as our DHCP server.&lt;/P&gt;&lt;P&gt;6. The IP helper address is configured per interface on the 9800. I also have the ip helper address on our downstream switches to aid wired clients, etc.&lt;/P&gt;&lt;P&gt;7. The client vlans are purely layer 2 interfaces. We wanted to avoid the layer 3 interfaces due to reported issues. Our DHCP mode is in bridging mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like DHCP is working as expected. However, I'm not too well versed in deciphering the log and the parser seems to suggest that things look ok? Not quite sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, I've ran a debug and radioactive trace. I've attached it after sanitizing any identifying information from it. (all information from the trace is sanitized. I've removed IP addresses/mac addresses/etc and substituted them with their corresponding purpose, I.E "[Wireless Controller] and [Client Mac]" etc.)&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 00:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445736#M231981</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-08-07T00:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445771#M231985</link>
      <description>&lt;P&gt;OK, two things need to be checked:&lt;BR /&gt;After the client accept the AUP page/portal, ISE is sending back to the WLC two things to apply them to the client session (yes, you will see successful log from ISE and the WLC moved the client to run state with below):&lt;BR /&gt;&lt;BR /&gt;1. ACL: DENY_GUEST_INTERNAL&lt;BR /&gt;2. security-group-tag=0006&lt;BR /&gt;ISE shouldn't send group tag in this case&lt;BR /&gt;For the ACL, best practice is to not use ACL to control guest traffic, instead use Anchor deployment in the DMZ or VRFs design so you can isolate the guest traffic from corp traffic. In this case it might causing the problem somehow, you can start removing the security tag first from ISE config then if that doesn't fix the problem then try to remove the ACL too from ISE reply and make it simple "Permit Access" as in below screenshot.&lt;BR /&gt;I'm positive one of the above is causing the issue you have.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CWA ISE AuthZ Policy Set.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/127371iEB44948D30B9271D/image-size/large?v=v2&amp;amp;px=999" role="button" title="CWA ISE AuthZ Policy Set.jpg" alt="CWA ISE AuthZ Policy Set.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;[cid:image001.jpg@01D78B1D.3D3E8960]&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;From the RA trace:&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;2021/08/06 15:23:46.036756 {wncd_x_R0-0}{1}: [radius] [24995]: (info): RADIUS: Cisco AVpair [1] 32 "cts:security-group-tag=0006-00"&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;2021/08/06 15:23:46.036773 {wncd_x_R0-0}{1}: [radius] [24995]: (info): RADIUS: Airespace-ACL-Name [6] 21 "DENY_GUEST_INTERNAL"&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;2021/08/06 15:23:46.040199 {wncd_x_R0-0}{1}: [aaa-attr-inf] [24995]: (info): [ Applied attribute : security-group-tag 0 "0006-00" ]&lt;BR /&gt;.&lt;BR /&gt;.&lt;BR /&gt;2021/08/06 15:23:46.040201 {wncd_x_R0-0}{1}: [aaa-attr-inf] [24995]: (info): [ Applied attribute : bsn-acl-name 0 "DENY_GUEST_INTERNAL" ]&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 05:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4445771#M231985</guid>
      <dc:creator>Grendizer</dc:creator>
      <dc:date>2021-08-07T05:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with CoA? ISE 2.7/9800-80</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4446433#M232039</link>
      <description>&lt;P&gt;Good morning Grendizer,&lt;/P&gt;&lt;P&gt;First, thank you for your continued help. I really appreciate you taking the time to help me try and solve this issue.&lt;/P&gt;&lt;P&gt;Secondly, it was the ACL. We're going to look into the best practices for deploying the VRF's design, but as soon as I removed the ACL... it worked.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 13:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-coa-ise-2-7-9800-80/m-p/4446433#M232039</guid>
      <dc:creator>Erik Allen</dc:creator>
      <dc:date>2021-08-09T13:28:53Z</dc:date>
    </item>
  </channel>
</rss>

