300-715 · Question #274
An administrator is configuring endpoint profiling and needs to enable CoA for devices that change profiles. Which two actions must be taken to accomplish this goal? (Choose two.)
The correct answer is A. Ensure that the firewall is not blocking port 1700 B. Define "reauth" in the default CoA action to be used. To enable Change of Authorization (CoA) for devices that change profiles, ensure UDP port 1700 is open on firewalls between the Policy Service Node and Network Access Devices, and define the 'reauth' action as the default CoA action within ISE.
Question
An administrator is configuring endpoint profiling and needs to enable CoA for devices that change profiles. Which two actions must be taken to accomplish this goal? (Choose two.)
Options
- AEnsure that the firewall is not blocking port 1700
- BDefine "reauth" in the default CoA action to be used
- CUse an API to detect when profile changes occur and send instructions to ISE to provide a CoA
- DModify the RADIUS endpoint attribute filters to send CoA actions as the profiles change
- EEnable the CoA policy and create rules for each type
How the community answered
(25 responses)- A80% (20)
- C4% (1)
- D4% (1)
- E12% (3)
Why each option
To enable Change of Authorization (CoA) for devices that change profiles, ensure UDP port 1700 is open on firewalls between the Policy Service Node and Network Access Devices, and define the 'reauth' action as the default CoA action within ISE.
CoA messages use UDP port 1700 (RADIUS CoA port) to communicate between the Cisco ISE Policy Service Node and the Network Access Devices (NADs). Firewalls must allow this port for CoA to function correctly.
When an endpoint's profile changes, Cisco ISE needs to know what action to take. Defining 'reauth' as the default CoA action ensures that when a profile change is detected, ISE sends a RADIUS CoA-Reauthenticate message to the NAD, forcing the endpoint to reauthenticate and re-authorize with the new profile.
While APIs can be used for various integrations, detecting profile changes and manually sending CoA instructions via API is not the standard or primary method to enable automated CoA for profile changes within ISE itself.
RADIUS endpoint attribute filters are used to control which attributes ISE sends to the NAD, not for defining or sending CoA actions based on profile changes.
While a CoA policy is necessary to define specific CoA actions based on conditions, the question asks about enabling CoA for devices that change profiles, which is handled by the default CoA action or specific conditions that trigger reauthentication, along with ensuring proper network communication.
Concept tested: Cisco ISE Change of Authorization (CoA) for profiling
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_3_0_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.