<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Posture Assessment passed in Error using Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248837#M160518</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; one thing i have noticed is that this particular laptop is not being profiled correctly. Its endpoint group is "Unknown" whereas a majority of all our Windows machines get profiled properly as "WorkStation".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have compared the RADIUS output on the ISE for a working laptop and this not working laptop and there is no difference in terms of the attributes listed in the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that in order to hit the built in profiling rule for windows 7, the User Agent Attribute must contain "Windows NT 6.1".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I find out on my windows machine what is contained in the attribute? can the NAC agent help provide me with this information? or the Windows registry perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Apr 2013 15:05:29 GMT</pubDate>
    <dc:creator>marioderosa2008</dc:creator>
    <dc:date>2013-04-29T15:05:29Z</dc:date>
    <item>
      <title>Posture Assessment passed in Error using Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248835#M160513</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like some help trying to understand why a client that has not been connected to the network for just over a month was allowed full network access despite the AV definitions being over 28days old.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 mandatory posture requirements,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Symantec Av MUST be installed&lt;/P&gt;&lt;P&gt;2. the AV definitions MUST be LESS THAN 28 days out of date&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, the machine I have is showing the AV defs as being 25th March 2013.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I produce the detailed posture report, it even shows me that the two mandatory requirements as described above were successfully meant meaning the endpoint is posture compliant. Clearly this is not the case though...!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I can check on the ISE to help debug this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248835#M160513</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2019-03-11T03:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Assessment passed in Error using Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248836#M160516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Attached are exports of the authenticvation session pre-posture &amp;amp; post-posture &amp;amp; also the full posture report from the Cisco ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 14:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248836#M160516</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2013-04-29T14:06:44Z</dc:date>
    </item>
    <item>
      <title>Posture Assessment passed in Error using Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248837#M160518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; one thing i have noticed is that this particular laptop is not being profiled correctly. Its endpoint group is "Unknown" whereas a majority of all our Windows machines get profiled properly as "WorkStation".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have compared the RADIUS output on the ISE for a working laptop and this not working laptop and there is no difference in terms of the attributes listed in the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that in order to hit the built in profiling rule for windows 7, the User Agent Attribute must contain "Windows NT 6.1".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I find out on my windows machine what is contained in the attribute? can the NAC agent help provide me with this information? or the Windows registry perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 15:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248837#M160518</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2013-04-29T15:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Assessment passed in Error using Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248838#M160520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might have two problems: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In ISE you have a gobal setting regarding the unsupported NAC Agent clients (Android, etc) that specifies what is their default compliance status. If the default setting is "compliant" and &lt;SPAN style="text-decoration: underline;"&gt;you don't have a provisioning rule for that client or you simply don't have client provisioning rules&lt;/SPAN&gt;, any machine that doesn't fit in the provisioning rule (ie ISE thinks that is not supported) will get a compliance status of compliant event though NAC Agent is installed and the rules are not satisfied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. NAC Agent version problem? &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;I've seen in logs that you're using NAC Agent 4.9.1.6 but the latest recommended version of NAC Agent to be used with (the latest) ISE is version 4.9.0.51. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version 4.9.1.6 is a NAC Appliance release and Cisco offers no guarantee that is 100% compatible with ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/compatibility/ise_sdt.html#wp78131" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/compatibility/ise_sdt.html#wp78131&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; Cisco NAC Agent Interoperability Between NAC Appliance and Identity Services Engine (ISE) &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;A name="wp78132"&gt;&lt;/A&gt;&lt;P&gt; Cisco supports different versions of the NAC Agent for integration with&amp;nbsp; NAC Appliance and ISE. Current releases are developed to work in either&amp;nbsp; environment, however, interoperability between deployments is not&amp;nbsp; guaranteed. Therefore, there is no explicit interoperability support for&amp;nbsp; a given NAC Agent version intended for one environment that will&amp;nbsp; necessarily work in the other. If you require support for both NAC&amp;nbsp; Appliance and ISE using a single NAC Agent, be sure to test NAC Agent in&amp;nbsp; your specific environment to verify compatibility. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;A name="wp78133"&gt;&lt;/A&gt;&lt;P&gt; Unless there is a specific defect or feature required for your NAC&amp;nbsp; Appliance deployment, Cisco recommends deploying the most current agent&amp;nbsp; certified for your ISE deployment. If an issue arises, Cisco recommends&amp;nbsp; restricting the NAC Agent's use to its intended environment and&amp;nbsp; contacting Cisco TAC for assistance. Cisco will be addressing this issue&amp;nbsp; through the standard Cisco TAC support escalation process, but NAC&amp;nbsp; Agent interoperability is not guaranteed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;A name="wp78134"&gt;&lt;/A&gt;&lt;P&gt; Cisco is working on an approach to address NAC Agent interoperability testing and support in an upcoming release. &lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248838#M160520</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2013-04-30T13:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Assessment passed in Error using Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248839#M160523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks mate!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the NAC agent version is the issue. I wonder why that is why our NAC agent customisation packages aren't working too!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 22:20:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-assessment-passed-in-error-using-cisco-ise/m-p/2248839#M160523</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2013-04-30T22:20:58Z</dc:date>
    </item>
  </channel>
</rss>

