I typically enable all IPs for CoA in the controller, so the ClearPass VIP(s) and the node addresses. I thought that ClearPass always uses the VIP (if it has one active) to send out CoA, but it appears to use the IP that it was called on for the authentication. If authentication is done to the VIP, the VIP will be used as source IP to send out the CoA, if the node IP is used, that IP is used. This makes sense as for deployments with Instant, you set the CoA as an attribute on the RADIUS server, so it is hard to configure a RADIUS server just for CoA. On controllers, for historical reasons, the RADIUS server and CoA server configuration is separate, but you should configure CoA servers for each of the configured RADIUS authentication servers
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
------------------------------