cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2718
Views
0
Helpful
11
Replies

CoA Operation not supported for an EndPoint

yafli
Cisco Employee
Cisco Employee

Hi Folks,

          I got error when trying to send CoA request on authenticated endpoints. But there was error on the page which indicated the operation was not supported for the endpoint(but I did the CoA request before on the endpoint) . The endpoint is just a normal dot1x endpoint of switchport.  Do you know why I got the error and how to resolve it ?  Thanks a lot !!!

1 Accepted Solution

Accepted Solutions

Would recommend contacting the tac if it’s something that was working before and now not working

View solution in original post

11 Replies 11

ognyan.totev
Level 5
Level 5

What is this endpoint ?? As i see it is cisco device  ,cisco switch, router or what ??

the endpoint is the supplicant of the switchport.

CAT-Pri-003#sh run int gi 1/0/22

Building configuration...

Current configuration : 178 bytes

!

interface GigabitEthernet1/0/22

description connect to sword gi 0/2/0

switchport access vlan 100

switchport mode access

dot1x pae supplicant

dot1x credentials radius

end

Craig Hyps
Level 10
Level 10

The NAD specified may not support CoA, or specific CoA operation selected.  Try again from Live Sessions log.

livesession.png

Unfortunately, the live session also got the same error.

Actually, I could send the CoA before on the endpoit. Then after power outage during the weekend, when I restarted the ISE, the error appeared. I don't know what the system is checking for opteration not supported scenarios ?

Would recommend contacting the tac if it’s something that was working before and now not working

hi Jason,

     It's not commercial usage. Just internal query.

yafli
Cisco Employee
Cisco Employee

Hi Team,

          Could you share some of the detailed reason that mentioned which kinds of endpoint not supported ?

The endpoint shows up there as a Cisco Device, but what is that Cisco device connected to? What is the Cisco device? Is it using MAB to authenticate? The piece that needs to support CoA is the network device the “Cisco Device” is connected to. Consider your laptop being authenticated to a switchport, the switch and switchport need to support CoA, your laptop just responds to what the switch does (port reset, dot1x reauth…). Hope that helps.

George

Per earlier reply... "The NAD specified may not support CoA, or specific CoA operation selected."

Make sure NAD Profile for selected NAD indicates support for the CoA operation being attempted.

you mean the device profile support for CoA(administration - - - network resources - - - network device profiles) ?  Yes, I am using default network profile "cisco" and it's with full CoA support.

it's just a simulator client on a switch port .  The topology like   3750 port ( supplicant) - - -port1  isr4k port2 - -raius - - ise   .

It's using dot1x for authenticate. I am trying to setup an ip phone to see if it's working or not. Thanks!