<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AnyConnect 4.5.04029 posture module behaviour in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-4-5-04029-posture-module-behaviour/m-p/3559463#M255</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am deploying AnyConnect 4.5.04029 at customer location for posturing. My query is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though I disable the posture Authz policies that would contain Web redirection, the posture module runs and scans the system. So, for example, if I have a policy that says "dot1x" then "permit access" and if I have the posture module, it still runs the scan which is not expected behaviour, because there is no Web redirection enabled at all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps performed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Disable client provisioning policy - If I do this, then on posture module I get message "Bypassing AnyConnect Scan. Your network is configured to use Cisco NAC Agent". Ideally it should be "Policy Server not detected. Default network access is in effect"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) As soon as I enable client provisioning policy, it goes for posture and sends report as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) I also observed that when it runs the scan without web redirection AuthZ profile, it does not honor Audit mode as well. If machine is non-compliant, remediation is attempted in spite of posture being in audit mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) It is observed for both wired and wireless&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Worked with TAC and as per TAC, it is expected behaviour beginning with ISE 2.2. I do not see this behaviour mentioned anywhere by Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would appreciate if anyone can share their thoughts. Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2018 07:20:21 GMT</pubDate>
    <dc:creator>devvv85</dc:creator>
    <dc:date>2018-06-08T07:20:21Z</dc:date>
    <item>
      <title>AnyConnect 4.5.04029 posture module behaviour</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-4-5-04029-posture-module-behaviour/m-p/3559463#M255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am deploying AnyConnect 4.5.04029 at customer location for posturing. My query is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though I disable the posture Authz policies that would contain Web redirection, the posture module runs and scans the system. So, for example, if I have a policy that says "dot1x" then "permit access" and if I have the posture module, it still runs the scan which is not expected behaviour, because there is no Web redirection enabled at all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps performed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Disable client provisioning policy - If I do this, then on posture module I get message "Bypassing AnyConnect Scan. Your network is configured to use Cisco NAC Agent". Ideally it should be "Policy Server not detected. Default network access is in effect"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) As soon as I enable client provisioning policy, it goes for posture and sends report as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) I also observed that when it runs the scan without web redirection AuthZ profile, it does not honor Audit mode as well. If machine is non-compliant, remediation is attempted in spite of posture being in audit mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) It is observed for both wired and wireless&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Worked with TAC and as per TAC, it is expected behaviour beginning with ISE 2.2. I do not see this behaviour mentioned anywhere by Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would appreciate if anyone can share their thoughts. Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 07:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-4-5-04029-posture-module-behaviour/m-p/3559463#M255</guid>
      <dc:creator>devvv85</dc:creator>
      <dc:date>2018-06-08T07:20:21Z</dc:date>
    </item>
  </channel>
</rss>

