I tried everything. But this should work tells everybody.
But what I see is that it goes always to initial role which is the login role.
I also see no Mac-auth triggered.
Session timeout triggers after 350seconds.
but the termination action 0 (default) or 1 doesn't trigger anything.
-------------------------------------------
Original Message:
Sent: Mar 09, 2026 08:45 AM
From: GorazdKikelj
Subject: After user-auth not doing re-auth from mac
Hi.
Yes, you can send CoA in enforcement profile.
You can use [AOS-CX - Disconnect] or [AOS-CX Bounce Switch Port] enforcement profiles to disconnect the user.
You will find required attributes in RADIUS Dynamic Authorization Templates.
Best, Gorazd
Best, Gorazd
------------------------------
Gorazd Kikelj
MVP Guru 2025
------------------------------
Original Message:
Sent: Mar 09, 2026 08:37 AM
From: EnzoJ
Subject: After user-auth not doing re-auth from mac
The sequence is correct.
First Mac-auth then user-auth.
The flow works correct if I manually disconnect the client from the controller.
Then the client comes back and does a Mac-auth.
Issue is to automate a disconnect after a user-auth after 600seconds.
Session timeout via enforcement doesn't trigger Mac-auth.
Role re-auth in gateway/MC (conductor) doesn't trigger also no Mac-auth.
If I could send a CoA in enforcement of user-auth to disconnect user after 600seconds would be great.
Like I do manaully and re-auth it against the clearpass.
Original Message:
Sent: Mar 09, 2026 07:05 AM
From: GorazdKikelj
Subject: After user-auth not doing re-auth from mac
What is services sequence?
You should have MAC Auth with MAC Caching before Captive portal login.
Best, Gorazd
------------------------------
Gorazd Kikelj
MVP Guru 2025
Original Message:
Sent: Mar 09, 2026 07:00 AM
From: EnzoJ
Subject: After user-auth not doing re-auth from mac
Hi,
Tried it with enforcement profile session timeout.
Then after x seconds he comes back to captive portal.
No Mac-auth but goes to initial role without asking to clearpass.
Best thing is CoA sending disconnect after 600secs.
But don't know how I can trigger this in clearpass enforcement.
Original Message:
Sent: Mar 09, 2026 05:10 AM
From: ahollifield
Subject: After user-auth not doing re-auth from mac
Yeah but why not use CoA? this is exactly what it's designed for.
Original Message:
Sent: 3/9/2026 3:59:00 AM
From: EnzoJ
Subject: RE: After user-auth not doing re-auth from mac
AOS8 since customer doesn't have budget to migrate to AOS10.
CoA works but I don't send it.
Session timeout send by clearpass triggers to go back logon role.
Where everything fails again.
I want to do Mac-auth after x seconds/minutes and should work as a charm then.
Someone else had same issue?
Original Message:
Sent: Mar 03, 2026 12:56 PM
From: ahollifield
Subject: After user-auth not doing re-auth from mac
Are you sending a CoA? How are you accomplishing this? Is there a session lifetime configured on the controller instead?
Also why AOS8 and not AOS10?