Wednesday, December 6, 2017

Change of Authorization


  • Radius Change of Authorization (CoA) Access-Request was introduced in order for ISE to issue new authorization policy to the endpoint based CoA triggers
    • Endpoint authenticated
    • Initial Authorization Policy pushed to the switch (endpoint not yet profiled)
    • Profiling data received and endpoint profile selected
    • ISE triggers CoA for endpoint to reauthenticate (this is subject to configured CoA Type)
    • Final Authorization Policy pushed to the switch based the endpoint profile (during reauthentication process)
  • The following scenarios trigger CoA
    • Endpoint profiling for 1st time
    • Endpoint statically assigned to device identity group
    • Endpoint removed from ISE database
    • Endpoint dynamically change identity group membership
    • Manual CoA  from Context Visibility > Endpoints > Change Authorization

No comments:

Post a Comment

DNS Performance Troubleshooting

When you are troubleshooting internet performance, there are different parts of the connection should be verified:   ·         DNS Pe...