Security

Reply
Contributor I
Posts: 34
Registered: ‎03-19-2015

ClearPass sends to Cisco ASA dACL RADIUS CoA

Is there a way to send from ClearPass RADIUS_CoA dACL to Cisco ASA VPN ?
For example the OnGuard Agent finished the NAC health checks when the user connected to the VPN,
and I want to send the ClearPass a RADIUS_CoA dACL to Cisco ASA, if the health check result is quarantine or allow all.

 

Thanks,

Balazs

Thanks,
Balazs
Guru Elite
Posts: 8,185
Registered: ‎09-08-2010

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

What version of code are you running on the ASA?

Sent from Nine

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 34
Registered: ‎03-19-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

Hi Tim,

 

Cisco Adaptive Security Appliance Software Version 9.3(3)2
Device Manager Version 7.4(3)

 

Thanks,

Balazs

 

Thanks,
Balazs
Contributor I
Posts: 34
Registered: ‎03-19-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

[ Edited ]

So, if I send a generic Cisco Coa Reauthenticate session or generic Cisco Coa Terminate session nothing happens. I sent a RADIUS:Cisco Cisco-IP-Downloadable-ACL deny ip any any nothing happens.

So, my question is what attributes should to be send by the clearpass to the Cisco ASA in coa message if we want to change a user ACL list after a NAC check.

 

Thanks,
Balazs
New Contributor
Posts: 1
Registered: ‎11-16-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

[ Edited ]
 
Contributor I
Posts: 34
Registered: ‎03-19-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

what do you mean to trigger the reauthentication?

Thanks,
Balazs
Guru Elite
Posts: 8,185
Registered: ‎09-08-2010

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

You need to trigger a reauthentication for the user to get the new dACL.

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 34
Registered: ‎03-19-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

Bounce or reauth ?

Thanks,
Balazs
Guru Elite
Posts: 8,185
Registered: ‎09-08-2010

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

CoA. Can you post your enforcement policy?

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Contributor I
Posts: 34
Registered: ‎03-19-2015

Re: ClearPass sends to Cisco ASA dACL RADIUS CoA

I send only dACL in CoA:

 

coa_enf.png

 

Thanks,

Balazs

 

Thanks,
Balazs
Search Airheads
Showing results for 
Search instead for 
Did you mean: