The objective of this article is to provide an overview of the change of authorization message types in Catalyst 1300 switches.
Change of Authorization (CoA) is an extension to the RADIUS protocol, allowing dynamic changes to a AAA or dot1x user session. When a policy for a user of group in AAA changes, administrators can transmit RADIUS CoA packets from the AAA server, such as a Cisco Identity Services Engines (ISE), to reinitialize authentication and apply the new policy.
This feature requires communication between the Dynamic Authorization Client (RADIUS Server) and the Dynamic Authorization Server (Catalyst switch). As seen in network diagram below, the Dynamic Authorization Client sends a disconnect or CoA message to the Dynamic Authorization Server and the switch provides a response.
The device supports the following CoA actions:
CoA Sanet Session Query is not supported by the Catalyst 1300 switches.
CoA requests, as described in RFC 5176, are used to allow for session identification, host reauthentication, and session termination. The model contains a single request (CoA-Request) and two possible response codes:
The request is initiated from a CoA client (usually a RADIUS or policy server) and directed to the device that acts as a listener.
CoA ACK Response Code
If an authorization state is changed successfully, a positive acknowledgment (ACK) is sent. The attributes returned within a CoA ACK can vary based on the CoA request.
CoA NAK Response Code
A negative acknowledgment (NAK) indicates a failure to change the authorization state and can include attributes that indicate the reason for the failure.
CoA is an extension to the overall RADIUS protocol and has the ISE server sending packets to UDP Port 1700 on the switch.
The RADIUS packet type codes are defined in RFC3575.
Now that you understand CoA message types, check out the following articles to configure CoA in Catalyst 1300 switches.
Configure Change of Authorization in Catalyst 1300 Using Web User Interface
Configuration of Change of Authorization in Catalyst 1300 Switch using CLI
Revision | Publish Date | Comments |
---|---|---|
1.0 |
05-Mar-2025 |
Initial Release |