<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE trying to posture a device that should not be able to be postured in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316515#M111383</link>
    <description>&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Overview:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cisco ISE version 1.1.4. Windows PC will be postured using Web NAC agent. Mobile devices (Apple/Android) can't be postured and will be exempted from posturing. Mobile devices will be exempted using the condition &lt;SPAN style="font-size: 10pt;"&gt;EndPoints:PostureApplicable EQUALS No. This worked fine and mobile devices will be caught by this condition while Windows device will be caught by another that sends to posturing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobile device authorisation policy configured:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/2/1/148126-Authz.PNG" alt="Authz.PNG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A few days later, mobile devices doesn't seem to end up in the policy that has &lt;SPAN style="font-size: 10pt;"&gt;EndPoints:PostureApplicable EQUALS No. After having a look at monitoring, Cisco ISE is classifies&amp;nbsp; mobile devices as Posturable. The Posture Status previously was "NotApplicable" now shows up as "Pending". See below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/2/1/148124-notapplicable.PNG" alt="notapplicable.PNG" class="jive-image" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Troubleshooting:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I tried a total of 4 different mobile devices. 2 Apple and 2 Android. All of them have the Posture Status of "Pending". Interestingly after a few tries, both the Androids starting working and have the PostureStatus of "NotApplicable", no configuration changes were made. The 2 Apple device still doesn't work and show up as "Pending".&lt;/P&gt;&lt;P&gt;I have restarted ISE, Access Point and Apple device. I have also tried other Apple device. All with the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have any of you guys experienced this before?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:42:01 GMT</pubDate>
    <dc:creator>nomadicwifi</dc:creator>
    <dc:date>2019-03-11T03:42:01Z</dc:date>
    <item>
      <title>Cisco ISE trying to posture a device that should not be able to be postured</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316515#M111383</link>
      <description>&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Overview:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cisco ISE version 1.1.4. Windows PC will be postured using Web NAC agent. Mobile devices (Apple/Android) can't be postured and will be exempted from posturing. Mobile devices will be exempted using the condition &lt;SPAN style="font-size: 10pt;"&gt;EndPoints:PostureApplicable EQUALS No. This worked fine and mobile devices will be caught by this condition while Windows device will be caught by another that sends to posturing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobile device authorisation policy configured:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/2/1/148126-Authz.PNG" alt="Authz.PNG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A few days later, mobile devices doesn't seem to end up in the policy that has &lt;SPAN style="font-size: 10pt;"&gt;EndPoints:PostureApplicable EQUALS No. After having a look at monitoring, Cisco ISE is classifies&amp;nbsp; mobile devices as Posturable. The Posture Status previously was "NotApplicable" now shows up as "Pending". See below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/2/1/148124-notapplicable.PNG" alt="notapplicable.PNG" class="jive-image" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;Troubleshooting:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I tried a total of 4 different mobile devices. 2 Apple and 2 Android. All of them have the Posture Status of "Pending". Interestingly after a few tries, both the Androids starting working and have the PostureStatus of "NotApplicable", no configuration changes were made. The 2 Apple device still doesn't work and show up as "Pending".&lt;/P&gt;&lt;P&gt;I have restarted ISE, Access Point and Apple device. I have also tried other Apple device. All with the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have any of you guys experienced this before?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316515#M111383</guid>
      <dc:creator>nomadicwifi</dc:creator>
      <dc:date>2019-03-11T03:42:01Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE trying to posture a device that should not be able to</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316516#M111393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having a quick look I did find there were scenarios found in which &lt;/P&gt;&lt;P&gt;EndPoints:PostureApplicable attribute was set to null it was found in beta-testing of 1.2. &lt;/P&gt;&lt;P&gt;That could explain why some of the devices started working after a few tries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mind opening a TAC case and/or trying 1.2 release (if you have a testing ISE set up).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 11:34:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316516#M111393</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-07-29T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE trying to posture a device that should not be able to</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316517#M111406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also experienced the same issues as yourself and would recommend opening a tac case. However I have used the device registration web portal to redirect all previous detected mobile devices to accept the aup and have them statically assigned to an endpoint group so they do not hit this scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know it is a workaround but its the only way i could get this to work and not affect devices that were one time detected as such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 14:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trying-to-posture-a-device-that-should-not-be-able-to/m-p/2316517#M111406</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-07-29T14:41:36Z</dc:date>
    </item>
  </channel>
</rss>

