<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture problem in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5220195#M8623</link>
    <description>&lt;P&gt;Thank you for your all help. The problem has been solved. Problem was anyconnect version&lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2024 08:12:15 GMT</pubDate>
    <dc:creator>fikret-arazbeyli</dc:creator>
    <dc:date>2024-11-05T08:12:15Z</dc:date>
    <item>
      <title>ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212814#M8581</link>
      <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;A user connected to a Cisco 2960X switch was re-authenticated every 30 minutes. I replaced the switch with a 9200L model, and now when the user re-authenticates every 1800 seconds, the Posture process shows the error "Posture failed due to Server issue."Posture What could be the cause, and how can I fix it?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 22 Oct 2024 09:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212814#M8581</guid>
      <dc:creator>fikret-arazbeyli</dc:creator>
      <dc:date>2024-10-22T09:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212856#M8582</link>
      <description>&lt;P&gt;Could you please share the related configs on the 9200 switch for review including the redirect ACL please?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 10:45:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212856#M8582</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-22T10:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212905#M8584</link>
      <description>&lt;P&gt;No ACL configured. What configurations are needed? Radius or all configurations?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 12:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5212905#M8584</guid>
      <dc:creator>fikret-arazbeyli</dc:creator>
      <dc:date>2024-10-22T12:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213026#M8587</link>
      <description>&lt;P&gt;If you don't have any redirect ACL created then I think you would need one. This redirect ACL would need to be called exactly with the same name as you configured it in the redirection authorization profile on ISE.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 15:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213026#M8587</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-22T15:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213468#M8588</link>
      <description>&lt;P&gt;I looked at the cisco ISE logs and when that error occurs, authentication goes through but authorization does not go through and it closes the session,even went through the CoA configurations.Could it be from the firmware version?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 08:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213468#M8588</guid>
      <dc:creator>fikret-arazbeyli</dc:creator>
      <dc:date>2024-10-23T08:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213538#M8589</link>
      <description>&lt;P&gt;Could you share the failure log in ISE for review please? I don't think the firmware version in itself is the issue, however, it could be that some of the commands have not been applied to the 9200 switch. Did you cross check all the commands you had on the 2960 with the ones you applied to the 9200?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 10:04:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5213538#M8589</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-23T10:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5214348#M8593</link>
      <description>&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11027&lt;/TD&gt;&lt;TD&gt;Detected Host Lookup UseCase (Service-Type = Call Check (10))&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Location&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Device Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15041&lt;/TD&gt;&lt;TD&gt;Evaluating Identity Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15013&lt;/TD&gt;&lt;TD&gt;Selected Identity Source - Internal Endpoints&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24209&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Looking up Endpoint in Internal Endpoints IDStore - XX:XX:XX:XX:XX:XX&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24211&lt;/TD&gt;&lt;TD&gt;Found Endpoint in Internal Endpoints IDStore&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22037&lt;/TD&gt;&lt;TD&gt;Authentication Passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15036&lt;/TD&gt;&lt;TD&gt;Evaluating Authorization Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11055&lt;/TD&gt;&lt;TD&gt;User name change detected for the session. Attributes for the session will be removed from the cache&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Location&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Device Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Network Access.EapAuthentication (192 times)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Normalised Radius.RadiusFlowType&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15016&lt;/TD&gt;&lt;TD&gt;Selected Authorization Profile - DenyAccess&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15039&lt;/TD&gt;&lt;TD&gt;Rejected per authorization profile&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11003&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Reject&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;These are the logs from ISE. I have compared the configurations of 2960X and 9200L, they are all the same.&amp;nbsp;Radius has session-timeout set to 1800 seconds. After this period expires, it checks again, at which point the posture gives an error and the connection is interrupted for 15 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 10:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5214348#M8593</guid>
      <dc:creator>fikret-arazbeyli</dc:creator>
      <dc:date>2024-10-24T10:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5218559#M8619</link>
      <description>&lt;P&gt;Not sure, sorry, but from the log you shared it does seem that the wrong authorization profile is being hit. I think I would need to see all your sanitized configs of this whole posture assessment flow to see if anything else come to mind that could help.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 12:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5218559#M8619</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-11-01T12:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5220195#M8623</link>
      <description>&lt;P&gt;Thank you for your all help. The problem has been solved. Problem was anyconnect version&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 08:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5220195#M8623</guid>
      <dc:creator>fikret-arazbeyli</dc:creator>
      <dc:date>2024-11-05T08:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture problem</title>
      <link>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5220227#M8624</link>
      <description>&lt;P&gt;You are welcome, and thanks for sharing the root cause.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 09:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/ise-posture-problem/m-p/5220227#M8624</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-11-05T09:20:06Z</dc:date>
    </item>
  </channel>
</rss>

