<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: COA messages troubleshooting in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520139#M307777</link>
    <description>&lt;P&gt;yeah, I am a getting all that a bit emotionally because this is not the first "anomaly" that i see, and because of the time limits that i have to finish the integration i cannot play with support cases and wait for fixes and make another try, i need the solution asap, and every time i change the direction and trying to go around the problem i am hitting another wall.&lt;/P&gt;&lt;P&gt;--EDIT--&lt;/P&gt;&lt;P&gt;I am also sure for 99.999% that any my request to support will end up with response that this is how it is designed to be, already tried with several cases, so just a wasting of time, if it doesn't work as expected, then ok, it doesn't work... &lt;SPAN class="lia-unicode-emoji" title=":confused_face:"&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 19:37:06 GMT</pubDate>
    <dc:creator>Alexs20</dc:creator>
    <dc:date>2023-10-24T19:37:06Z</dc:date>
    <item>
      <title>COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520130#M307768</link>
      <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;I have a question about CoA messages.&lt;/P&gt;&lt;P&gt;I am following this document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/en/US/docs/ios-xml/ios/san/configuration/15-e/san-coa-supp.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/en/US/docs/ios-xml/ios/san/configuration/15-e/san-coa-supp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And my question is about how can I troubleshoot the reason for not answering to CoA messages?&lt;/P&gt;&lt;P&gt;For example, when I am targeting session that does not exist already, instead of return NAK the access point just keep silence, and on my side i have zero knowledge about what went wrong, it because of time drift? or maybe network problem? or i am sending bad message.&lt;/P&gt;&lt;P&gt;The Log/Events section in Meraki Cloud is also keep full silence about what is going on and why AP is not answering.&lt;/P&gt;&lt;P&gt;How can I troubleshoot such cases and force the AP to respond? Is it possible to just send a test Coa to AP just to make sure that at least no problems in the network? Any PONG-PONG coa message? Anything?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 17:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520130#M307768</guid>
      <dc:creator>Alexs20</dc:creator>
      <dc:date>2023-10-24T17:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520131#M307769</link>
      <description>&lt;P&gt;Are you sure that the CoA is reaching your APs ? Can you see it with a LAN packet capture ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 17:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520131#M307769</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2023-10-24T17:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520132#M307770</link>
      <description>&lt;P&gt;What exactly do you want to solve, can you give more details about your scenario? Authentication type for example.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520132#M307770</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-24T18:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520133#M307771</link>
      <description>&lt;P&gt;Yes. When I am targeting a real session then I am getting the AK message back.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520133#M307771</guid>
      <dc:creator>Alexs20</dc:creator>
      <dc:date>2023-10-24T18:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520134#M307772</link>
      <description>&lt;P&gt;I am trying to find a way to test that my messages are reaching the AP without using any session for that.&lt;/P&gt;&lt;P&gt;Imagine I have a site with 100 APs installed. And I want to send "TEST" COA to all of them and see if I get response from all of them - just to make sure that there is no issues with passing UDP traffic from my service to all APs.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520134#M307772</guid>
      <dc:creator>Alexs20</dc:creator>
      <dc:date>2023-10-24T18:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520135#M307773</link>
      <description>&lt;P&gt;Maybe it can help a little.&lt;/P&gt;&lt;P&gt;&lt;A href="https://wirelesslywired.com/2018/01/18/deconstructing-the-radius-coa-process/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://wirelesslywired.com/2018/01/18/deconstructing-the-radius-coa-process/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520135#M307773</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-24T18:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520136#M307774</link>
      <description>&lt;P&gt;Yeah, I know how CoA and Disconnects work. And from my experience there is a way to implement what I am trying to do. The proper way to do that is to send CoA with either &lt;STRONG&gt;Calling-Station-Id&lt;/STRONG&gt; or &lt;STRONG&gt;Acct-Session-Id&lt;/STRONG&gt; set mac address that does not exist, like 00:00:00:00:00:00 or FF:FF:FF:FF:FF:FF, and in that case, if the remote device implemented the CoA protocol correctly, the device will respond with NAK and message saying that Session context not found...&lt;/P&gt;&lt;P&gt;But looks like Meraki is again trying to invent their own rules and instead of just sending the NAK ignoring the request&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520136#M307774</guid>
      <dc:creator>Alexs20</dc:creator>
      <dc:date>2023-10-24T19:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520137#M307775</link>
      <description>&lt;P&gt;Is it referenced in the RFC ? If so , open a case. Else , that might be "expected"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520137#M307775</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2023-10-24T19:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520138#M307776</link>
      <description>&lt;P&gt;It seems like you always have an answer ready, well in your case I suggest opening a support case.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520138#M307776</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-24T19:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520139#M307777</link>
      <description>&lt;P&gt;yeah, I am a getting all that a bit emotionally because this is not the first "anomaly" that i see, and because of the time limits that i have to finish the integration i cannot play with support cases and wait for fixes and make another try, i need the solution asap, and every time i change the direction and trying to go around the problem i am hitting another wall.&lt;/P&gt;&lt;P&gt;--EDIT--&lt;/P&gt;&lt;P&gt;I am also sure for 99.999% that any my request to support will end up with response that this is how it is designed to be, already tried with several cases, so just a wasting of time, if it doesn't work as expected, then ok, it doesn't work... &lt;SPAN class="lia-unicode-emoji" title=":confused_face:"&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520139#M307777</guid>
      <dc:creator>Alexs20</dc:creator>
      <dc:date>2023-10-24T19:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: COA messages troubleshooting</title>
      <link>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520140#M307778</link>
      <description>&lt;P&gt;If you enable RADIUS testing on the SSID, the APs will regularly be sending an Access-Request with "meraki_802.1x_test" identity. A test is considered succesful if the AP gets any response (Challenge, Accept/Reject). If no response is provided for the Access-Request, a failure is considered, and the Dashboard will raise an Alert. This is all described per documentation; &lt;A href="https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Alert_-_Recent_802.1X_Failure" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Alert_-_Recent_802.1X_Failure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But, as I understand, rather than relying on Meraki RADIUS testing form AP to RADIUS server, you'd rather like to send a CoA to the AP instead, inorder to test connectivity? I'm not familiar with the RFC, so I'll take your word that if a CoA is sent, the AP ought to respond with a NAK whether or not the CoA is valid or not, and use this to monitor connectivity to the APs?&lt;/P&gt;&lt;P&gt;What type of encryption is your SSID using?&lt;/P&gt;&lt;P&gt;Also, according to the CoA documentation (&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points)" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Change_of_Authorization_with_RADIUS_(CoA)_on_MR_Access_Points)&lt;/A&gt; it's recommended to enable Cisco ISE, regardless if you're using ISE or not, for CoA.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 09:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/coa-messages-troubleshooting/m-p/5520140#M307778</guid>
      <dc:creator>Rasmus Hoffmann Birkelund</dc:creator>
      <dc:date>2023-10-25T09:05:12Z</dc:date>
    </item>
  </channel>
</rss>

