<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE inline posture node Posture assessment query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222375#M117092</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i read the user guide for the ISE 1.1 and in the Inline posture section, I picked up the following text which concerned me if I understand it right...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Times-Roman; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;"In a deployment, such as outlined in the example, when more endpoints connect to the wireless network&lt;/P&gt;&lt;P align="left"&gt;they are likely to fall into one of the identity groups that already have authenticated and authorized users&lt;/P&gt;&lt;P align="left"&gt;connected to the network.&lt;/P&gt;&lt;P align="left"&gt;For instance, there may be an employee, executive, and guest that have been granted access through the&lt;/P&gt;&lt;P align="left"&gt;outlined steps. This situation means that the respective restrictive or full-access profiles for those ID&lt;/P&gt;&lt;P align="left"&gt;groups have already been installed on the Inline Posture node. The subsequent endpoint authentication&lt;/P&gt;&lt;P align="left"&gt;and authorization uses the existing installed profiles on the Inline Posture node, unless the original&lt;/P&gt;&lt;P align="left"&gt;profiles have been modified at the Cisco ISE policy configuration. In the latter case, the modified profile&lt;/P&gt;&lt;P&gt;with ACL is downloaded and installed on the Inline Posture node, replacing the previous version."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Does this mean that if a corporate user VPNs in and successfully passes posture and gets a dACL applied to the session allowing full access, will the next user completely skip posture assessment and granted full access to the network if they are a member of the same AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning on using the iPEP for posturing VPN clients and using AD groups to determine the correct dACL to apply to a particular VPN session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:21:39 GMT</pubDate>
    <dc:creator>marioderosa2008</dc:creator>
    <dc:date>2019-03-11T03:21:39Z</dc:date>
    <item>
      <title>Cisco ISE inline posture node Posture assessment query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222375#M117092</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i read the user guide for the ISE 1.1 and in the Inline posture section, I picked up the following text which concerned me if I understand it right...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Times-Roman; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;"In a deployment, such as outlined in the example, when more endpoints connect to the wireless network&lt;/P&gt;&lt;P align="left"&gt;they are likely to fall into one of the identity groups that already have authenticated and authorized users&lt;/P&gt;&lt;P align="left"&gt;connected to the network.&lt;/P&gt;&lt;P align="left"&gt;For instance, there may be an employee, executive, and guest that have been granted access through the&lt;/P&gt;&lt;P align="left"&gt;outlined steps. This situation means that the respective restrictive or full-access profiles for those ID&lt;/P&gt;&lt;P align="left"&gt;groups have already been installed on the Inline Posture node. The subsequent endpoint authentication&lt;/P&gt;&lt;P align="left"&gt;and authorization uses the existing installed profiles on the Inline Posture node, unless the original&lt;/P&gt;&lt;P align="left"&gt;profiles have been modified at the Cisco ISE policy configuration. In the latter case, the modified profile&lt;/P&gt;&lt;P&gt;with ACL is downloaded and installed on the Inline Posture node, replacing the previous version."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Does this mean that if a corporate user VPNs in and successfully passes posture and gets a dACL applied to the session allowing full access, will the next user completely skip posture assessment and granted full access to the network if they are a member of the same AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning on using the iPEP for posturing VPN clients and using AD groups to determine the correct dACL to apply to a particular VPN session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222375#M117092</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2019-03-11T03:21:39Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE inline posture node Posture assessment query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222376#M117093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not too familiar with the actual operations of the Inline Posture node, but it seems to me that the only things that are more or less "cached" are the authentication and authorization profiles that have been previously matched. So, even if they're "cached" and a endpoint matches and authorizes based on those policies, it would match on the policy that provides a pre-posture state. So, a PRE-POSTURE ACL would be pushed and an URL redirect would also occur to the NAC agent download portal (if the endpoint doesn't have it already). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After posture is assessed, a change of authorization would occur and reauthorize that endpoint's session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in short, even if the profiles are cached, they only deliver pre-posture profiles. After posture assessment, the endpoint is goes through reauth via CoA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have access to the partner education connection, I suggest checking out the VoE deep dive series for ISE. There's a posture presentation that would probably help you out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://communities.cisco.com/docs/DOC-30977"&gt;https://communities.cisco.com/docs/DOC-30977&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 00:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222376#M117093</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2013-04-26T00:20:37Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE inline posture node Posture assessment query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222377#M117094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just went through your query and for the same I have a link to share which would help you in solving your query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_ipep_deploy.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_ipep_deploy.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 01:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222377#M117094</guid>
      <dc:creator>harvisin</dc:creator>
      <dc:date>2013-05-01T01:52:00Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE inline posture node Posture assessment query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222378#M117095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Harvinder,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes I have been using this document to design my iPEP proposal... thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 10:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222378#M117095</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2013-05-01T10:50:44Z</dc:date>
    </item>
    <item>
      <title>Cisco ISE inline posture node Posture assessment query</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222379#M117096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i do not have access to that document.. can you share?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 10:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-inline-posture-node-posture-assessment-query/m-p/2222379#M117096</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2013-05-01T10:51:34Z</dc:date>
    </item>
  </channel>
</rss>

