11-04-2020 03:12 AM
Hi,
I am actually trying to implemement profiling with the Cisco ISE (2.7 patch2) and Aruba 2530 (SW 16.10.011).
After profiling the devices, the ISE sends a CoA POrt Bounce to the switch.
But I am still getting a "Missing attribute" back from the switch.
On the switch, I have configured the following for CoA:
radius-server host <IP-address> key <Some Pass>
radius-server host <IP-address> dyn-authorization
radius-server host <IP-address> time-window 0
The CoA-NAKs increase with every attempt.
On the ISE, I have configured the following for the device profile:
from a packet dump, I can see that only a few attributes are sent to the switch via CoA:
Any idea what´s missing here?
Regards
Joerg
Solved! Go to Solution.
11-04-2020 10:58 PM
Here's what I recently used for Aruba CoA, it tested out fine. We changed to UDP 1700 on the Aruba config to match the Cisco equipment in the environment and existing load balancer config. To be fair, this is being used on wireless/wired with 303 model RAPs. I don't have a proper hp/aruba switch.
11-04-2020 03:56 AM
11-04-2020 05:05 AM
Hi Mohammed,
I will try and let you know about the results.
Thanks
Regards
Joerg
11-09-2020 06:13 AM
Hi Mohammed,
I have added the NAS-Port-ID, but still the same.
The NAS-Port-ID is included in the initial Radius access request, but missing in the CoA of the ISE.
Regards
Joerg
11-09-2020 08:13 AM
11-04-2020 10:58 PM
Here's what I recently used for Aruba CoA, it tested out fine. We changed to UDP 1700 on the Aruba config to match the Cisco equipment in the environment and existing load balancer config. To be fair, this is being used on wireless/wired with 303 model RAPs. I don't have a proper hp/aruba switch.
11-09-2020 11:04 PM
Hi Damien,
unfortunately, this did not work for me with the HPE switches.
I will do some further investigations.
Thanks.
Regards
Joerg
10-05-2022 08:33 AM
Hi @Damien Miller ,
I am in similar situation. Where my Aruba controllers in DMZ space and with Wired Guest Traffic. It has 3799 port for CoA. I want to do CoA Port bounce. I have also made the "CoA Termination" in the Guest HotSpot Portal.
Will your network device profile setting still work in my case ?
10-05-2022 09:58 AM
I would use the Network Device Profile linked in this article here: How To: Cisco ISE Captive Portals with Aruba Wireless - Cisco Community
10-05-2022 03:13 PM
HI @ahollifield , the article is wonderful made and brilliant. we are suing the similar way with Aruba-captive-portal-url vsa. All working good with the Aruba Wireless Controllers. Problem we have with Aruba Wired Controllers. So we are looking to do CoA PortBounce in the new custom device profile. Since Cisco didnt have provided the Aruba Wired Controller network device profile. It has for HP an Alcatel Wired.
Regards,
Sudarshan
10-06-2022 04:26 AM
Ahh got it. Wired controller like you are doing UBT to a mobility controller? Is there a wired switch involved here?
11-16-2020 05:28 AM
Hi everybody,
finally I got the following configuration from TAC, which worked for my case.
09-16-2024 01:56 PM
This worked for Dell S3148P's but I just needed the following:
Radius-NAS-Port = 0
Dell-Force10:Force10-av-pair = cmd=bounce-host-port
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide