05-21-2019 05:34 AM
Hi experts,
My customer gave me another challenge, to replace all cisco NAD to H3C.
Here is their request, do the posture check, if the PC is no compliant, put them to VLAN 60, then put them to VLAN 20 after their PC compliant. Everything is OK in cisco NAD but stuck the second authorization(COA) in H3C. Can anyone help me to solve this question? Thank you very much!
Attach my log and config!
Solved! Go to Solution.
05-21-2019 11:00 PM
Already solved. The key is CISCO provide the HP Wired Device Profile is not include port bounce attribute. But the second authorization needs the port bounce to change vlan. So I searched forum and RFC 5176 about COA. Founded the solution about this case.
This post was the expert gave the profile which I reference. https://community.cisco.com/t5/security-documents/hpe-wired-xml/ta-p/3643636
05-21-2019 11:00 PM
Already solved. The key is CISCO provide the HP Wired Device Profile is not include port bounce attribute. But the second authorization needs the port bounce to change vlan. So I searched forum and RFC 5176 about COA. Founded the solution about this case.
This post was the expert gave the profile which I reference. https://community.cisco.com/t5/security-documents/hpe-wired-xml/ta-p/3643636
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide