12-18-2017 01:41 AM
Hi Folks,
I got error when trying to send CoA request on authenticated endpoints. But there was error on the page which indicated the operation was not supported for the endpoint(but I did the CoA request before on the endpoint) . The endpoint is just a normal dot1x endpoint of switchport. Do you know why I got the error and how to resolve it ? Thanks a lot !!!
Solved! Go to Solution.
12-19-2017 04:50 AM
Would recommend contacting the tac if it’s something that was working before and now not working
12-18-2017 02:16 AM
What is this endpoint ?? As i see it is cisco device ,cisco switch, router or what ??
12-18-2017 05:44 PM
the endpoint is the supplicant of the switchport.
CAT-Pri-003#sh run int gi 1/0/22
Building configuration...
Current configuration : 178 bytes
!
interface GigabitEthernet1/0/22
description connect to sword gi 0/2/0
switchport access vlan 100
switchport mode access
dot1x pae supplicant
dot1x credentials radius
end
12-18-2017 07:45 AM
The NAD specified may not support CoA, or specific CoA operation selected. Try again from Live Sessions log.
12-18-2017 05:49 PM
Unfortunately, the live session also got the same error.
Actually, I could send the CoA before on the endpoit. Then after power outage during the weekend, when I restarted the ISE, the error appeared. I don't know what the system is checking for opteration not supported scenarios ?
12-19-2017 04:50 AM
Would recommend contacting the tac if it’s something that was working before and now not working
12-19-2017 06:54 PM
hi Jason,
It's not commercial usage. Just internal query.
12-19-2017 10:17 PM
Hi Team,
Could you share some of the detailed reason that mentioned which kinds of endpoint not supported ?
12-20-2017 07:58 AM
The endpoint shows up there as a Cisco Device, but what is that Cisco device connected to? What is the Cisco device? Is it using MAB to authenticate? The piece that needs to support CoA is the network device the “Cisco Device” is connected to. Consider your laptop being authenticated to a switchport, the switch and switchport need to support CoA, your laptop just responds to what the switch does (port reset, dot1x reauth…). Hope that helps.
George
12-20-2017 09:13 AM
Per earlier reply... "The NAD specified may not support CoA, or specific CoA operation selected."
Make sure NAD Profile for selected NAD indicates support for the CoA operation being attempted.
12-20-2017 09:42 PM
you mean the device profile support for CoA(administration - - - network resources - - - network device profiles) ? Yes, I am using default network profile "cisco" and it's with full CoA support.
12-20-2017 09:37 PM
it's just a simulator client on a switch port . The topology like 3750 port ( supplicant) - - -port1 isr4k port2 - -raius - - ise .
It's using dot1x for authenticate. I am trying to setup an ip phone to see if it's working or not. Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide