Hi, Is SNAT + COA issue solved while using Load Balancer ?I believe, there should be changes for using NAS-IP instead of NAD IP for sending COA. https://community.cisco.com/t5/security-documents/ise-load-balancing/ta-p/3648759#toc-hId-58288313
Client IP address is learned by IP Device Tracking Feature (IPDT). This is an important feature for switch to track the IP address of the machine and then apply the dACL’s and Redirection ACL’s on that port using device IP address. Please refer below...