300-715 · Question #327
A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA…
The correct answer is D. reauth. When a switch port exhibits multiple sessions, the RADIUS Change of Authorization (CoA) 'reauth' command should be used. This forces devices on the port to re-authenticate with Cisco ISE, allowing for updated policy enforcement.
Question
A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA configuration must be used?
Options
- Aport bounce
- Bno CoA
- Cexception
- Dreauth
How the community answered
(29 responses)- A10% (3)
- B7% (2)
- C3% (1)
- D79% (23)
Why each option
When a switch port exhibits multiple sessions, the RADIUS Change of Authorization (CoA) 'reauth' command should be used. This forces devices on the port to re-authenticate with Cisco ISE, allowing for updated policy enforcement.
Port bounce would physically reset the port, causing unnecessary disruption to all connected devices, which is more aggressive than typically needed for policy violations.
No CoA would mean no action is taken, which fails to address the identified issue of multiple sessions on the port.
Exception is not a standard RADIUS CoA action type; it refers to a policy state, not a specific CoA command to resolve multiple sessions.
When a switch port has multiple sessions, indicating potential policy violations, a RADIUS Change of Authorization (CoA) reauthentication (reauth) is the appropriate action. This forces the device(s) on the port to re-authenticate with Cisco ISE, allowing ISE to apply updated authorization policies, which can restrict or deny access based on the identified issue without full port disruption.
Concept tested: RADIUS Change of Authorization (CoA) actions
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ISE_admin_3_1/b_ISE_admin_3_1_chapter_0101.html#Cisco_Reference.dita_313e61c7-c598-482d-bf41-3a216f2c3d9a
Topics
Community Discussion
No community discussion yet for this question.