<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic did you find a solution other in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930439#M38156</link>
    <description>&lt;P&gt;did you find a solution other than tunneling all networks? I need to have split tunneling enabled for specific networks only and i am having the same issue as you are...................&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2016 17:06:28 GMT</pubDate>
    <dc:creator>James Walsh</dc:creator>
    <dc:date>2016-11-07T17:06:28Z</dc:date>
    <item>
      <title>Anyconnect ISE posture problem</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930429#M38146</link>
      <description>&lt;P&gt;I’m trying to get posture up&amp;amp;running with anyconnect ISE posture module for VPN connections.&lt;BR /&gt;The design:&lt;BR /&gt;- ASA with 9.6.1 SW installed&lt;BR /&gt;- Win 7 with Anyconnect 4.3.02039 VPN module installed only&lt;BR /&gt;- ISE 2.1 with patch 1&lt;BR /&gt;- Windows 2008R2 server for AD&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Anyconnect profile configured on ISE:&lt;/P&gt;
&lt;P&gt;- ISE posture: checked&lt;/P&gt;
&lt;P&gt;- ISE posture (profile selection): anyconnectISEprofile&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Posture configuration:&lt;/P&gt;
&lt;P&gt;- discovery host: ISE's IP address&lt;/P&gt;
&lt;P&gt;- server name rules: *&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Authorization profile:&lt;BR /&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;DACL = PERMIT_ALL_TRAFFIC&lt;BR /&gt;cisco-av-pair = url-redirect-acl=redirect&lt;BR /&gt;cisco-av-pair = url-redirect=https://ip:port/portal/gateway?sessionId=SessionIdValue&amp;amp;portal=a1da1780-e0e7-11e5-9151-005056bf7f51&amp;amp;action=cpp&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Problem:&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Client establishes VPN connection to ASA&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Client opens web page that matches “redirect” ACL on ASA&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA redirects client to ISE provisioning portal listening on tcp/8443&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Client clicks on download link&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; File anyconnect-ise-network-assistant-win-4.3.02039.exe is downloaded&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Network Setup Assistant window opens and I got the error message: Couldn't connect to server&lt;BR /&gt;&lt;BR /&gt;It seems client can’t find ISE policy server?&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;According to the following rules found on cisco.com webpage:&lt;BR /&gt;Posture Run-time Services&lt;BR /&gt;The posture run-time services encapsulate all the interactions that happen between the client agent and the Cisco ISE server for posture assessment and remediation of clients.&lt;BR /&gt;Posture run-time services begin with the Discovery Phase. An endpoint session is created after the endpoint passes 802.1x authentication. The client agent then attempts to connect to a Cisco ISE node by sending discovery packets through different methods in the following order:&lt;BR /&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp; via HTTP to Port 80 on a Cisco ISE server (if configured)&lt;BR /&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp; via HTTPS to Port 8905 on a Cisco ISE server (if configured)&lt;BR /&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp; via HTTP to Port 80 on the default gateway&lt;BR /&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp; via HTTPS to Port 8905 to each previously contact server&lt;BR /&gt;5&amp;nbsp;&amp;nbsp;&amp;nbsp; via HTTP to Port 80 on enroll.cisco.com&lt;/P&gt;
&lt;P&gt;I can find by capturing traffic with wireshark:&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; request to port tcp/80 to default gateway – gateway sends RST packet which is expected&lt;BR /&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DNS query for enroll.cisco.com&lt;BR /&gt;I also created static enroll.cisco.com record and point it to ISE IP but it didn’t help solve the problem.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Any idea what could be wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930429#M38146</guid>
      <dc:creator>Jernej Vodopivec</dc:creator>
      <dc:date>2019-03-11T07:06:38Z</dc:date>
    </item>
    <item>
      <title>Are you allowing the DNS</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930430#M38147</link>
      <description>&lt;P&gt;Are you allowing the DNS resolution (udp/53 to the configured DNS servers) in your pre-authZ ACL?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930430#M38147</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-26T15:03:29Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930431#M38148</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;there is a DNS server configured on ASA's group policy: internal DNS server with IP .51. There is also local domain configured: test.local.&lt;/P&gt;
&lt;P&gt;There is also split tunneling configured in tunnel policy: to tunnel only local network where AD/DNS and ISE server are located.&lt;/P&gt;
&lt;P&gt;There is a rule "DACL = PERMIT_ALL_TRAFFIC" configured in pre-authZ ACL. There is "redirect" policy configured in this pre-authZ ACL: deny ip from any to AD/DNS; deny ip from any to ISE; permit tcp any any http/https.&lt;/P&gt;
&lt;P&gt;Client can successfully resolve hostname ise.test.local. Client can send DNS recursive query to local DNS server and gets respone.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930431#M38148</guid>
      <dc:creator>Jernej Vodopivec</dc:creator>
      <dc:date>2016-09-26T15:15:15Z</dc:date>
    </item>
    <item>
      <title>Hmm OK thanks Jernej.</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930432#M38149</link>
      <description>&lt;P&gt;Hmm OK thanks Jernej.&lt;/P&gt;
&lt;P&gt;It sounds like you've pretty much got a textbook setup.&lt;/P&gt;
&lt;P&gt;Are you able to see in your packet capture what query it is trying while the Network Setup Assistant is running?&lt;/P&gt;
&lt;P&gt;Have you tried pre-installing the ISE Posture Module along with the VPN module in AnyConnect?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 17:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930432#M38149</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-26T17:15:42Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin, I can see only one</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930433#M38150</link>
      <description>&lt;P&gt;Hi Marvin, I can see only one DNS query: enroll.cisco.com.&lt;/P&gt;
&lt;P&gt;But I've manage to solve the problem by reconfiguring ASA's group policy from "tunnel specific network list" to "tunnel all networks".&lt;/P&gt;
&lt;P&gt;Thank you for you help anyway. Much appreciate it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 04:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930433#M38150</guid>
      <dc:creator>Jernej Vodopivec</dc:creator>
      <dc:date>2016-09-28T04:00:06Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930434#M38151</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Thanks for letting us know the resolution that worked for you.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 04:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930434#M38151</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-28T04:05:52Z</dc:date>
    </item>
    <item>
      <title>Hi Team,</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930435#M38152</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I've got exactly the same issue. ISE 2.1, Anyconnect 4.2.05015, ASA 9.5.(2). Turning off split tunnel resolves the issue but I need split tunneling feature. How to resolve it?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 09:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930435#M38152</guid>
      <dc:creator>Bob Goal</dc:creator>
      <dc:date>2016-10-24T09:09:34Z</dc:date>
    </item>
    <item>
      <title>If you absolutely need split</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930436#M38153</link>
      <description>&lt;P&gt;If you absolutely need split tunnel you can narrow down which public block in the split tunnel the client requires. You can start with 0.0.0.0-31.255.255.255 etc.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 05:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930436#M38153</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2016-10-25T05:42:48Z</dc:date>
    </item>
    <item>
      <title>In this topic are some</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930437#M38154</link>
      <description>&lt;P&gt;In this topic are some interesting hints&amp;nbsp;&lt;A href="https://supportforums.cisco.com/discussion/11795926/ise-redirect-install-nac-agent-anyconnect-users-split-tunnel"&gt;https://supportforums.cisco.com/discussion/11795926/ise-redirect-install-nac-agent-anyconnect-users-split-tunnel&lt;/A&gt;&amp;nbsp;I'm going to test it and give a feedback.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 05:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930437#M38154</guid>
      <dc:creator>Bob Goal</dc:creator>
      <dc:date>2016-10-25T05:51:31Z</dc:date>
    </item>
    <item>
      <title>I found that tunneling all</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930438#M38155</link>
      <description>&lt;P&gt;I found that tunneling all traffic is not required, Anyconnect tries to connect to enroll.cisco.com. I found&amp;nbsp;its IP and added it to spilt tunnel ACL. That is working fine.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;$ dig @192.168.201.48 enroll.cisco.com +short&lt;BR /&gt;mus.cisco.com.&lt;BR /&gt;72.163.1.80&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;Add host to split ACL:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;access-list ACL_SPLIT standard permit host 72.163.1.80&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 Oct 2016 08:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930438#M38155</guid>
      <dc:creator>Bob Goal</dc:creator>
      <dc:date>2016-10-25T08:30:40Z</dc:date>
    </item>
    <item>
      <title>did you find a solution other</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930439#M38156</link>
      <description>&lt;P&gt;did you find a solution other than tunneling all networks? I need to have split tunneling enabled for specific networks only and i am having the same issue as you are...................&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 17:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930439#M38156</guid>
      <dc:creator>James Walsh</dc:creator>
      <dc:date>2016-11-07T17:06:28Z</dc:date>
    </item>
    <item>
      <title>Hi, the solution is in other</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930440#M38157</link>
      <description>&lt;P&gt;Hi, the solution is in other of my post in this topic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 18:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930440#M38157</guid>
      <dc:creator>Bob Goal</dc:creator>
      <dc:date>2016-11-07T18:20:40Z</dc:date>
    </item>
    <item>
      <title>can you send me the link to</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930441#M38158</link>
      <description>&lt;P&gt;can you send me the link to that post? I can't find it. thanks for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 18:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-ise-posture-problem/m-p/2930441#M38158</guid>
      <dc:creator>James Walsh</dc:creator>
      <dc:date>2016-11-07T18:25:48Z</dc:date>
    </item>
  </channel>
</rss>

