As it turns out, for some as-yet unknown reason, removing the custom profile I created and using the [Cisco - Reauthenticate-Session] profile instead allows it to work. I don't understand it, but I'll take the win and hope for clearer understanding in the future.
-------------------------------------------
Original Message:
Sent: Sep 18, 2025 09:52 AM
From: EMU_IS
Subject: Issue - COA enforcement profile never send to NAS
I'm experiencing the same issue on 6.12.5. In my case, even an enforcement profile copy is not working. I have the same symptoms: Access Tracker log shows the CoA-Disconnect message was generated, but a packet capture on the CPPM indicates that it was not sent. Do you have any other guidance on how to resolve this issue?
Original Message:
Sent: Apr 08, 2018 05:21 AM
From: mkk
Subject: Issue - COA enforcement profile never send to NAS
I focus a strange problem when i use a [ArubaOS Switching - Terminate Session] enforcement profile, the radius response is vissible in accesstracker but never sends by clearpass to de NAS device. The radius response packets are not vissible in Wireshark and never sends to the NAS.
I Solved the problem by making a clone of the [ArubaOS Wireless - Terminate Session] template and change the attributes to be equal to the [ArubaOS Switching - Terminate Session] template.
It seems like i bug to me in Clearpass 6.7.2.105008.
The switch a 2920 with fw16.04 isnt the problem here, the problem is clearpass never sends de radius response that access tracker showns.
One thing i notice is that when i do a manualy COA in a accepted radius request in accesstracker only the wireless COA enforcement profiles are visible here.
Are other people seen the same issue here? Or do i missed something?
See also attechment with some screenshots of the issue in my test enviornment ;)