cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2983
Views
5
Helpful
8
Replies

C9800-CL CoA Assign VLAN Issue

snailmus0
Level 1
Level 1

I have a C9800-CL in my testing env, and it integrated with ISE 2.4p8, I configure 802.1x auth and posture feature on ISE, and when ISE issue a CoA request to C9800-CL, it disconnects the wireless client and report errs in the log.

 

2021/01/11 10:54:03.666 {wncd_x_R0-0}{1}: [client-orch-sm] [22011]: (ERR): Vlan change after CO has reached IP Learn state is not allowed
2021/01/11 10:54:03.666 {wncd_x_R0-0}{1}: [sanet-shim-translate] [22011]: (ERR): 9cda.3e6c.8815 :Auth interface failed to process vlan change from 222 to 370

 

Does anyone know how to resolve this problem?

1 Accepted Solution

Accepted Solutions

d.friday
Level 4
Level 4

What IOS version are you running,  I know CoA with a VLAN change was not supported until IOS 17.x version.

 

 

View solution in original post

8 Replies 8

d.friday
Level 4
Level 4

What IOS version are you running,  I know CoA with a VLAN change was not supported until IOS 17.x version.

 

 

Oh no, i use 16.12.4a!

Let me upgrade my devices and test again!

Do you have any documents describe this striction?

Is there any release notes referencing this? TIA

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214855-ios-xe-wireless-feature-list-per-release.html
shows ...
Amsterdam - 17.1.1s
- Vlan override support after guest authentication (LWA and CWA)

Thank you!

hello guys,

i am experiencing the same issue. WLC 9800 version 17.3.5a. Did anyone resolved the issue if yes then please guide me.

thanks

Yes the solution is highlighted above.
You're using a software version which should support the feature so you must have a different problem.

Suggest you open a new thread with a detailed description of exactly what your problem is, what model of WLC you're using, exact software version and SMUs installed and what troubleshooting and debugging you have done.

Meanwhile take a look at the best practices guide and TAC recommended versions of code below and make sure you have configured everything required as per the config guide.  In particular the "aaa server radius dynamic-author" config required for CoA to work.

Review Cisco Networking for a $25 gift card