11-09-2023 04:50 AM
i was trying to implement RTC, but it didn't work correctly with me. I'm running ISE3.2 and FMC7.0.4,
I should post screenshots for the configuration , but i won't be able to access the client network. so, these are the configured steps:
From FMC side:
From ISE side:
From Switch side:
1- i configured the required configuration for dot1x and COA
2- i did not configure ip device tracking.
But from test respective:
So, I need to understand the following :
11-09-2023 10:10 AM
"2- i did not configure ip device tracking." DACLs will not work without this enabled on the switch.
11-09-2023 11:00 AM - edited 11-09-2023 11:02 AM
Thank you ahollifield for your reply.
The DACL worked fine , but as i noticed at RTC Cisco videos , ISE should retreive the mac address of the endpoint automatically.
but this what i noticed from my test:
so,
11-10-2023 07:27 PM
@AFAWZY Please check ISE active sessions view and ensure ISE is getting both the IP address and the MAC address of the client endpoint. Also, you should see ISE initiate an CoA action to the switch after ISE assigns the endpoint's IP address with an ANC policy with shutdown action, this CoA should have the option to shutdown the switch interface, and the switch should respond with success for the CoA action. If any of these not happening, please engage Cisco TAC to troubleshoot.
11-24-2023 03:36 PM
@hslai I checked the active sessions previously and ISE got IP address and the MAC address of the client endpoint.
regarding to this point that you refrenced : "you should see ISE initiate an CoA action to the switch after ISE assigns the endpoint's IP address with an ANC policy with shutdown action", ISE couldn't assigns the endpoint's IP address with an ANC policy with shutdown action. (this is my primary issue)
and how can i set the COA action to be shutdown from the ISE side , i only see ( reauth - portbounce - no COA ) at profiling settings.?????
how can i see ISE initiate an CoA action ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide