cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2233
Views
5
Helpful
3
Replies

CTS CoA from PAN

REJR77
Level 1
Level 1

Hi,

In a 4 nodes ISE (2PAN/Mnt + 2PSN), I would like to understand what is CTS CoA and why it is the PAN that advertise the NADs with these CoA?

https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/InstallGuide27/b_ise_InstallationGuide27/b_ise_InstallationGuide27_chapter_0110.html

 

Thanks

 

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

You have the option to have ISE send a CoA to the network device informing it to immediately request an updated set of trustsec policies. This gets trustsec policy to the network devices in more of a "push" fashion vs waiting for the reoccurring pull interval for policy updates.

View solution in original post

3 Replies 3

Damien Miller
VIP Alumni
VIP Alumni

You have the option to have ISE send a CoA to the network device informing it to immediately request an updated set of trustsec policies. This gets trustsec policy to the network devices in more of a "push" fashion vs waiting for the reoccurring pull interval for policy updates.

Damien,

Does this CTS CoA have the same behaviour than the "Push" option displayed on the ISE WebUI when an SGT is created?

 

Image 4.png

Or does it mean than when we click "Push" it sends the CoA from the PAN?

 

Damien Miller
VIP Alumni
VIP Alumni

Yes, that is the same behavior/functionality.