RADIUS CoA Configuration for Multiple Sessions

Implement CoA
Answer Correct answer: D — Configure the RADIUS CoA Reauth option to enforce reauthentication on a switch port with multiple active sessions.

A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA configuration must be used?

  1. port bounce
  2. no CoA
  3. exception
  4. reauth Correct Answer

Community Votes

A
50%
D
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the correct RADIUS CoA action for ports with multiple active sessions, where the common trap is assuming Port Bounce is universally applicable for clearing sessions.

When a switch port has multiple active sessions, Cisco ISE must use the RADIUS Change of Authorization (CoA) Reauth configuration to address the issue. This page establishes that Port Bounce is only for single-session ports and Reauth is required for multi-session ports.

Selecting Port Bounce (A) because it resets the port, ignoring the official ISE rule that Port Bounce is only for single-session ports and Reauth must be used for multiple sessions.

Community Discussion (4 comments)

BoxChevy 👍 1 Selected: D
https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_prof_pol.html Reauth You can use this option to enforce reauthentication of an already authenticated endpoint when profiled. If you have multiple active sessions on a single port, the profiler service issues a CoA with the Reauth option even though you have configured CoA with the Port Bounce option. This function potentially avoids disconnecting other sessions as might occur with the Port Bounce option.
luismg 👍 1 Selected: D
It has to be D reauth because it has "Multiple sessions"
An312 👍 1 Selected: A
The available CoA options include the following: No CoA (default): Use this option to disable the global configuration of CoA. Port Bounce: Use this option if switch ports will have only one session (one active endpoint attached). If ports shall have multiple sessions, then use the Reauth option. Reauth: Use this option to enforce reauthentication as appropriate for profiled endpoints. So A would be the best answer, I think.
ZoneHacker 👍 1 Selected: A
The answer A is the best option here because port bounce action involves shutting down the port and then bringing it back up. This effectively terminates all sessions on the port and forces any connected devices to re-authenticate. This is suitable for clearing multiple sessions on a port and ensuring that the devices reconnect properly.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is D (reauth) because Cisco ISE documentation explicitly states that the Reauth option must be used for switch ports with multiple active sessions. When multiple endpoints are attached to a single port, issuing a Port Bounce would disrupt all endpoints unnecessarily, whereas Reauth enforces reauthentication appropriately for profiled endpoints without bouncing the port.

Why the Other Options Are Wrong

Option A (port bounce) is incorrect because it is strictly intended for ports with only one session (one active endpoint). Option B (no CoA) disables the global CoA configuration and does not address the issue. Option C (exception) is not a standard RADIUS CoA action in this context and does not resolve multiple active sessions.

Community Comment Notes

Several community members correctly pointed out that the ISE documentation specifies Reauth for multiple sessions, as An312 noted by quoting "If ports shall have multiple sessions, then use the Reauth option." BoxChevy also highlighted that the profiler service issues a CoA with the Reauth option for multiple active sessions even if Port Bounce is configured. ZoneHacker incorrectly assumed Port Bounce was best to clear sessions, ignoring the multi-session constraint.

Official Reference

Exam Strategy

Pay close attention to the number of active sessions on a port when choosing a CoA type. Remember that Port Bounce is exclusively for single-session ports, while Reauth is required for multi-session ports.

Related Analysis

← Back to 300-715 Study Guide