Skip to main content
HS08
Explorer
August 5, 2026
Question

Fnac Daisy Chain CoA

  • August 5, 2026
  • 4 replies
  • 34 views

How we can successfully send CoA to gthe endpoint behind ip phone? Now the CoA is success only if the endpoint connect to the port switch.

Open case to Cisco TAC and them say FNAC should send SessionId inside the radius attribute but still not work. Has anyone here succeeded?

4 replies

adambomb1219
SuperUser
SuperUser
August 5, 2026

Can you provide more details? What switch? How is the port configured? 

AEK
SuperUser
SuperUser
August 5, 2026

.Did you use tcpdump in FNAC to see if it is sending CoA? it should be port 3799.
You can also use params -vvv and -X to print the content.

AEK
HS08
HS08Author
Explorer
August 5, 2026

hi ​@AEK ​@adambomb1219 

Here my detail.

Switch : Cisco 2960

IP Phone : CP-7821

Here my simulation, currently the endpoint sit under vlan 30 and if i change the host role to other vlan when the ip phone starting up (not yet authenticated and get voice vlan) then the CoA is working with below log. But when the ip phone get ip from voice vlan then when i change the host role the tcpdump not generate any message.

 

nac01  # execute tcpdump port 1700 -v -X
tcpdump: data link type LINUX_SLL2
dropped privs to admin
tcpdump: listening on any, link-type LINUX_SLL2 (Linux cooked v2), snapshot length 262144 bytes
06:39:51.718958 port1 Out IP (tos 0x0, ttl 64, id 61062, offset 0, flags [DF], proto UDP (17), length 125)
    nac01.37660 > 10.100.200.200.1700: RADIUS, length: 97
        CoA-Request (43), id: 0xfa, Authenticator: 051d6711a6bd0efe83e9c6b2610f9fbb
          Calling-Station-Id Attribute (31), length: 19, Value: F4-A8-0D-3D-5A-EB
          Tunnel-Medium-Type Attribute (65), length: 6, Value: Tag[Unused] 802
          Vendor-Specific Attribute (26), length: 41, Value: Vendor: Cisco (9)
            Vendor Attribute: 1, Length: 33, Value: subscriber:command=reauthenticate
          Tunnel-Private-Group-ID Attribute (81), length: 5, Value: Tag[Unused] 36
          Tunnel-Type Attribute (64), length: 6, Value: Tag[Unused] VLAN
        0x0000:  4500 007d ee86 4000 4011 a64c 0a67 c809  E..}..@.@..L.g..
        0x0010:  0a64 c8c8 931c 06a4 0069 a617 2bfa 0061  .d.......i..+..a
        0x0020:  051d 6711 a6bd 0efe 83e9 c6b2 610f 9fbb  ..g.........a...
        0x0030:  1f13 4634 2d41 382d 3044 2d33 442d 3541  ..F4-A8-0D-3D-5A
        0x0040:  2d45 4241 0600 0000 061a 2900 0000 0901  -EBA......).....
        0x0050:  2373 7562 7363 7269 6265 723a 636f 6d6d  #subscriber:comm
        0x0060:  616e 643d 7265 6175 7468 656e 7469 6361  and=reauthentica
        0x0070:  7465 5105 0033 3640 0600 0000 0d         teQ..36@.....
06:39:51.732942 port1 In  IP (tos 0x0, ttl 251, id 41121, offset 0, flags [none], proto UDP (17), length 79)
    10.100.200.200.1700 > nac01.37660: RADIUS, length: 51
        CoA-ACK (44), id: 0xfa, Authenticator: 60e226617afcd8fc80f64143117780e8
          Vendor-Specific Attribute (26), length: 9, Value: Vendor: Cisco (9)
            Vendor Attribute: 252, Length: 1, Value: 2
          Calling-Station-Id Attribute (31), length: 16, Value: f4a8.0d3d.5aeb
          Error-Cause Attribute (101), length: 6, Value: Error cause 200: Error-Cause 200 not known
        0x0000:  4500 004f a0a1 0000 fb11 795f 0a64 c8c8  E..O......y_.d..
        0x0010:  0a67 c809 06a4 931c 003b 7a23 2cfa 0033  .g.......;z#,..3
        0x0020:  60e2 2661 7afc d8fc 80f6 4143 1177 80e8  `.&az.....AC.w..
        0x0030:  1a09 0000 0009 fc03 321f 1066 3461 382e  ........2..f4a8.
        0x0040:  3064 3364 2e35 6165 6265 0600 0000 c8    0d3d.5aebe.....

HS08
HS08Author
Explorer
August 6, 2026

Found the issue, on the documentation for endpoint behind the ip phone then we need to enable the RFC5176 Daisy Chain

 

But this is not work for me, if i disable the RFC Multiple Connection and Daisy Chain then the CoA is working for endpoint behind ip phone and for endpoint connect directly to the port switch.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.