<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Forescout - CoA Reauth to VOSS 9.2 5320 Switch in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120216#M3055</link>
    <description>&lt;P&gt;# EAP CONFIGURATION&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;eapol auto-isid-offset 9900000&lt;BR /&gt;eapol auto-isid-offset enable&lt;BR /&gt;eapol enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet 1/3&lt;BR /&gt;default-vlan-id 32&lt;BR /&gt;name "dot1x"&lt;BR /&gt;no shutdown&lt;BR /&gt;slpp-guard enable&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;spanning-tree mstp edge-port true&lt;BR /&gt;no spanning-tree mstp force-port-state enable&lt;BR /&gt;eapol guest-vlan 32&lt;BR /&gt;eapol fail-open-vlan 32&lt;BR /&gt;eapol guest-isid 1000032&lt;BR /&gt;eapol fail-open-isid 1000032&lt;BR /&gt;eapol radius-dynamic-server enable&lt;BR /&gt;eapol status auto&lt;BR /&gt;eapol multihost radius-non-eap-enable&lt;BR /&gt;eapol re-authentication-period 28800&lt;BR /&gt;eapol re-authentication enable&lt;BR /&gt;eapol traffic-control in&lt;/P&gt;&lt;P&gt;# RADIUS CONFIGURATION&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;radius server host 192.168.22.21 key ****** priority 1 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.22.21 used-by cli acct-enable&lt;BR /&gt;radius server host 192.168.24.21 key ****** priority 2 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.24.21 used-by cli acct-enable&lt;BR /&gt;radius server host 192.168.22.20 key ****** used-by eapol priority 1 retry 2 timeout 3&lt;BR /&gt;radius server host 192.168.24.20 key ****** used-by eapol priority 2 retry 2 timeout 3&lt;BR /&gt;radius server host 192.168.22.21 key ****** used-by web priority 1 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.22.21 used-by web acct-enable&lt;BR /&gt;radius server host 192.168.24.21 key ****** used-by web priority 2 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.24.21 used-by web acct-enable&lt;/P&gt;&lt;P&gt;radius enable&lt;BR /&gt;radius accounting enable&lt;BR /&gt;radius maxserver 6&lt;BR /&gt;radius reachability keep-alive-timer 30 unreachable-timer 30&lt;BR /&gt;radius reachability mode status-server&lt;BR /&gt;radius dynamic-server client 192.168.22.20 secret ****** enable&lt;BR /&gt;radius dynamic-server client 192.168.24.20 secret ****** enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2025 12:08:03 GMT</pubDate>
    <dc:creator>NikAll</dc:creator>
    <dc:date>2025-09-05T12:08:03Z</dc:date>
    <item>
      <title>NAC Forescout - CoA Reauth to VOSS 9.2 5320 Switch</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120194#M3049</link>
      <description>&lt;P&gt;Hey team&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am running Forescout as a NAC and when a client via Dot1x gets access to the network and Forescoute sends a CoA message i se the switch accept it but its no kicking out the client until i remove the cable and put it back in.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Sometimes mulitble times until it enters the correct Client VLAN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am Useing freeradius.internal&lt;/P&gt;&lt;P&gt;attribute "Send-CoA-Type"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Session-Reauthenticate&lt;BR /&gt;and also tested Reauthenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone manage to solve this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 14:21:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120194#M3049</guid>
      <dc:creator>NikAll</dc:creator>
      <dc:date>2025-09-02T14:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Forescout - CoA Reauth to VOSS 9.2 5320 Switch</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120206#M3051</link>
      <description>&lt;P&gt;What does your configuration on the switch look like?&lt;BR /&gt;&lt;BR /&gt;Looking at my own NAC config it's using the standard COA delimited radius responses so I don't see much of an issue there, it should be comparable to what you are sending.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brent_Addis_0-1756940023754.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9175iF5FE6DE87913BFC5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Brent_Addis_0-1756940023754.png" alt="Brent_Addis_0-1756940023754.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 22:59:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120206#M3051</guid>
      <dc:creator>Brent_Addis</dc:creator>
      <dc:date>2025-09-03T22:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Forescout - CoA Reauth to VOSS 9.2 5320 Switch</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120216#M3055</link>
      <description>&lt;P&gt;# EAP CONFIGURATION&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;eapol auto-isid-offset 9900000&lt;BR /&gt;eapol auto-isid-offset enable&lt;BR /&gt;eapol enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet 1/3&lt;BR /&gt;default-vlan-id 32&lt;BR /&gt;name "dot1x"&lt;BR /&gt;no shutdown&lt;BR /&gt;slpp-guard enable&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;spanning-tree mstp edge-port true&lt;BR /&gt;no spanning-tree mstp force-port-state enable&lt;BR /&gt;eapol guest-vlan 32&lt;BR /&gt;eapol fail-open-vlan 32&lt;BR /&gt;eapol guest-isid 1000032&lt;BR /&gt;eapol fail-open-isid 1000032&lt;BR /&gt;eapol radius-dynamic-server enable&lt;BR /&gt;eapol status auto&lt;BR /&gt;eapol multihost radius-non-eap-enable&lt;BR /&gt;eapol re-authentication-period 28800&lt;BR /&gt;eapol re-authentication enable&lt;BR /&gt;eapol traffic-control in&lt;/P&gt;&lt;P&gt;# RADIUS CONFIGURATION&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;radius server host 192.168.22.21 key ****** priority 1 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.22.21 used-by cli acct-enable&lt;BR /&gt;radius server host 192.168.24.21 key ****** priority 2 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.24.21 used-by cli acct-enable&lt;BR /&gt;radius server host 192.168.22.20 key ****** used-by eapol priority 1 retry 2 timeout 3&lt;BR /&gt;radius server host 192.168.24.20 key ****** used-by eapol priority 2 retry 2 timeout 3&lt;BR /&gt;radius server host 192.168.22.21 key ****** used-by web priority 1 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.22.21 used-by web acct-enable&lt;BR /&gt;radius server host 192.168.24.21 key ****** used-by web priority 2 retry 2 timeout 3&lt;BR /&gt;no radius server host 192.168.24.21 used-by web acct-enable&lt;/P&gt;&lt;P&gt;radius enable&lt;BR /&gt;radius accounting enable&lt;BR /&gt;radius maxserver 6&lt;BR /&gt;radius reachability keep-alive-timer 30 unreachable-timer 30&lt;BR /&gt;radius reachability mode status-server&lt;BR /&gt;radius dynamic-server client 192.168.22.20 secret ****** enable&lt;BR /&gt;radius dynamic-server client 192.168.24.20 secret ****** enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 12:08:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/nac-forescout-coa-reauth-to-voss-9-2-5320-switch/m-p/120216#M3055</guid>
      <dc:creator>NikAll</dc:creator>
      <dc:date>2025-09-05T12:08:03Z</dc:date>
    </item>
  </channel>
</rss>

