RADIUS CoA Configuration for Multiple Sessions
A network engineer received alerts from the monitoring platform that a switch port exists with multiple sessions. RADIUS CoA using Cisco ISE must be used to address the issue. Which RADIUS CoA configuration must be used?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the correct RADIUS CoA action for ports with multiple active sessions, where the common trap is assuming Port Bounce is universally applicable for clearing sessions.
When a switch port has multiple active sessions, Cisco ISE must use the RADIUS Change of Authorization (CoA) Reauth configuration to address the issue. This page establishes that Port Bounce is only for single-session ports and Reauth is required for multi-session ports.
Selecting Port Bounce (A) because it resets the port, ignoring the official ISE rule that Port Bounce is only for single-session ports and Reauth must be used for multiple sessions.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is D (reauth) because Cisco ISE documentation explicitly states that the Reauth option must be used for switch ports with multiple active sessions. When multiple endpoints are attached to a single port, issuing a Port Bounce would disrupt all endpoints unnecessarily, whereas Reauth enforces reauthentication appropriately for profiled endpoints without bouncing the port.Why the Other Options Are Wrong
Option A (port bounce) is incorrect because it is strictly intended for ports with only one session (one active endpoint). Option B (no CoA) disables the global CoA configuration and does not address the issue. Option C (exception) is not a standard RADIUS CoA action in this context and does not resolve multiple active sessions.Community Comment Notes
Several community members correctly pointed out that the ISE documentation specifies Reauth for multiple sessions, as An312 noted by quoting "If ports shall have multiple sessions, then use the Reauth option." BoxChevy also highlighted that the profiler service issues a CoA with the Reauth option for multiple active sessions even if Port Bounce is configured. ZoneHacker incorrectly assumed Port Bounce was best to clear sessions, ignoring the multi-session constraint.Official Reference
Exam Strategy
Pay close attention to the number of active sessions on a port when choosing a CoA type. Remember that Port Bounce is exclusively for single-session ports, while Reauth is required for multi-session ports.