Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Switch CoA Session-Context-Not-Found

This thread has been viewed 14 times
  • 1.  Switch CoA Session-Context-Not-Found

    Posted Oct 08, 2013 12:10 PM

    I'm doing dot1x authentication and mac auth on a switch port and also trying to set users VLAN by using the RADIUS CoA. I'm getting the following message in the access tracker on clearpass and it's not setting the VLAN.

     

    Application NamePolicy Manager
    RADIUS CoA Action TypeCoA
    RADIUS CoA Action NameChange to VLAN 251
    Status Code0
    Status MessageSession-Context-Not-Found
    RADIUS CoA AttributesAruba-Vlan = 151
    Calling-Station-Id = E8E0B7AC886B

     

    Any tips?



  • 2.  RE: Switch CoA Session-Context-Not-Found

    Posted Oct 08, 2013 12:30 PM

    Check to make sure that the AAA profile for those ports has CPPM defined as the RFC 3576 server (with the same key as the Network Device definition).   Also, make sure Enable RADIUS CoA is enabled on the Network Device configuration for your switch.



  • 3.  RE: Switch CoA Session-Context-Not-Found
    Best Answer

    EMPLOYEE
    Posted Oct 08, 2013 12:44 PM

    Make sure you have CoA (rfc-3576-server) enabled in the AAA profile with the IP address(es) of your ClearPass server.

     

    rfc-3576-server.png

     

    You can run the command show aaa rfc-3576-server statistics which will show the different types of CoA requests received/processed by the switch.

     

    rfc-3576-stats.png

     



  • 4.  RE: Switch CoA Session-Context-Not-Found

    Posted Oct 08, 2013 03:03 PM
    Thanks guys. Will check this in the lab tomorrow.


  • 5.  RE: Switch CoA Session-Context-Not-Found

    EMPLOYEE
    Posted Oct 08, 2013 04:49 PM

    Another thing to note is the controller-IP or the NAS IP set in the AAA advanced tab under Authentication in the controller.  Make sure that whatever the NAS IP is...that is matches on both ends for the CoA to work.



  • 6.  RE: Switch CoA Session-Context-Not-Found

    Posted Oct 09, 2013 06:32 AM

    I've added the RFC 3576 server to the aaa profile I'm using on the port.


    Here's what the stats show :

     

     

    rfc3576stats.JPG

     

    It's working for 802.1x auth clients but not for the MAC auth clients.



  • 7.  RE: Switch CoA Session-Context-Not-Found

    Posted Oct 09, 2013 07:08 AM

    I just recreated my enforcement profile and it's working now. 

    Not 100% sure why though which is worrying. :smileyfrustrated: