1. The unit of change
One identity can have several sessions. In the exercise, analyst has S1 and S2 on edge-a; operator has another S1 on edge-b. A session identifier has meaning in its corresponding NAS context. Before changing access, record the active session, its hosting device, observation time and objective. A worksheet containing only the username may select more than the incident laptop. The same care applies to reused names and old records: an earlier snapshot does not prove a session remains active after reconnection.
2. Protocols and capabilities
CoA can change authorization for existing sessions; it is not a generic replacement for the device’s entire configuration. The ISE profile describes NAD capabilities and attributes. Confirm the supported operation, message origin and port configuration on both sides rather than assuming identical actions across vendors. In this lesson, the fictional change contract authorizes one target at a time. The RFC permits actions on multiple matching sessions under defined conditions. Therefore, the code’s ambiguity rejection is a local planning safeguard rather than a universal prediction of a RADIUS response.
3. Work through ambiguous selection
In the same Python program, select nas=edge-a and user=analyst. Both S1 and S2 match, so the proposal stops with stop-ambiguous. Adding sid=S2 scopes one target; ready-for-human-review still sends nothing. Selecting only sid=S1 is also ambiguous because two NAS devices match. Try S0, marked inactive: the model stops with no active match. Finally, combine edge-a S1 with user=operator and confirm that contradictory attributes are not reconciled approximately. Keep predictions and results. This exercise trains selector quality without generating RADIUS datagrams, secrets or switch changes.
4. Read the response before retrying
Missing responses call for investigation of path, destination and transport controls. A NAK carrying Error-Cause 503 points to missing session context; repeat correlation using current evidence before repeating the same operation. Code 508 identifies unsupported multiple-session selection. There is also the specific Authorize Only case: a NAK with 507 can indicate initiation of the subsequent flow rather than a failure equivalent to 503. Distinguish these messages instead of automating “every NAK is a secret error.” Do not weaken channel authentication to resolve a selection issue or an unsupported operation.
5. Confirm access and continuity
After the expected response, inspect the session on the NAD and test intended access. Protocol success has a scope; it does not prove DNS resolution, a correct lease or a working application. If the plan changes VLAN, include address and dependency validation. During a closing shift, retain a business-test owner and an approved recovery path. An acceptable alternative may be postponement or supported controlled reauthentication when impact and authorization permit it. Summary: select from recent evidence, interpret the specific response, verify the session and close with service results.
edge-a/S1 and edge-b/S1 are different sessions. A selector without NAS does not scope intervention in this inventory.
Common pitfalls
Username as unique session; 503 as password failure; every NAK as the same error; ACK as complete application proof; model as real NAS.
Related topics: AAA · Endpoint posture · Incident management
A change should target the authorized session and produce verifiable access, with message-specific interpretation.
Reference: Dynamic Authorization Extensions to RADIUS · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security