12-07-2016 11:39 AM
So they cisco ISE 2.1 is missing a great deal of the CoA Attributes for the HP switch, namely port shutdown, and port bounce. Does anyone have the strings that need to be in there for HP.. or a proper HP NAD Profile they can share.
Thanks
Solved! Go to Solution.
12-14-2016 04:54 PM
Not all Cisco-specific CoA directives have comparable options in 3rd-party devices and vice versa. Beyond RFC-based PoD and CoA Request (Push), other implementations would be vendor specific. Most vendors do not have a reauth option but opt instead to use CoA Push. Port Bounce is often implemented as a vendor-specific attribute.
For more specifics on CoA options supported by newer HP code, see Coa and HP 5130 or 5500 series switches - Airheads Community
In general, CoA reauth is not required as ISE has the ability to "stitch" together a terminated session with a successive attempt after terminate/disconnect.
Hope that helps.
Craig
12-07-2016 02:15 PM
Jeffrey, I have created two new NAD profiles you can try for port bounce and terminate. I am not aware of other CoA HPE switches support. See:
12-07-2016 02:44 PM
Thanks I tried to import in to ISE and it gave an error.
12-07-2016 02:58 PM
I've added additional instructions in the above doc. Please retry.
12-07-2016 03:06 PM
Followed instructions, same error as before.
12-07-2016 03:08 PM
I had misspelled the dictionary attribute name in the instructions. Was missing an 'n' in the word 'Bounce'. Try correcting the name:
- Attribute Name: HP-Port-Bounce-Host
12-07-2016 03:17 PM
Yes, i saw the change, made the change and it imported great. So there really isnt a port shutdown command that can be set via CoA to HP switches?
what about Re-authenticate commands? basic, rerun and last... and move vlan, basically move them to vlan 300 which is my remediation vlan.
12-08-2016 11:32 AM
Yes, i saw the change, made the change and it imported great. So there really isnt a port shutdown command that can be set via CoA to HP switches?
what about Re-authenticate commands? basic, rerun and last... and move vlan, basically move them to vlan 300 which is my remediation vlan.
can we get it on in one HPE-COAFH profile
12-08-2016 11:37 AM
I have not found any document stating what is supported on their platforms. If you know of such document I can reference it to add more CoA. Or if you know the attributes, that will work as well. Thanks.
12-14-2016 04:54 PM
Not all Cisco-specific CoA directives have comparable options in 3rd-party devices and vice versa. Beyond RFC-based PoD and CoA Request (Push), other implementations would be vendor specific. Most vendors do not have a reauth option but opt instead to use CoA Push. Port Bounce is often implemented as a vendor-specific attribute.
For more specifics on CoA options supported by newer HP code, see Coa and HP 5130 or 5500 series switches - Airheads Community
In general, CoA reauth is not required as ISE has the ability to "stitch" together a terminated session with a successive attempt after terminate/disconnect.
Hope that helps.
Craig
12-07-2016 03:31 PM
Can we get them in to one profile that would help some.
12-08-2016 11:33 AM
The 'Terminate' didn't match exactly to two of the options for disconnect that ISE provides so I made it into two separate profiles. If you want you can combine the two by gleaning the profile information and adding it to one of the CoA actions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide