<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization profile not changed after posture compliant in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032238#M450062</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've noticed a weird behavior in our ISE deployment integrated with ASA for AnyConnect authorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AnyConnect users have posture configured so every time they connect they match first the "posture unknown" authorization profile while AnyConnect runs the system scan. We observe this normal behavior in the Radius live logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the client is compliant, the status changes to "Compliant" in the "Posture Status" column, BUT the "authorization profile" column is not updated with the valid rule that matches the compliant status. However, the dACL sent to ASA and actually applied is the correct one based on the user profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE performs just authorization, not authentication which is validated by the ASA using certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summarizing: ISE sees the user as compliant, internally matches the authorization profile for a compliant user, but the Radius logs are not updated accordingly and we see all the users with the status "unknown".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2020 12:15:30 GMT</pubDate>
    <dc:creator>Antonio Macia</dc:creator>
    <dc:date>2020-02-19T12:15:30Z</dc:date>
    <item>
      <title>Authorization profile not changed after posture compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032238#M450062</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've noticed a weird behavior in our ISE deployment integrated with ASA for AnyConnect authorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AnyConnect users have posture configured so every time they connect they match first the "posture unknown" authorization profile while AnyConnect runs the system scan. We observe this normal behavior in the Radius live logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the client is compliant, the status changes to "Compliant" in the "Posture Status" column, BUT the "authorization profile" column is not updated with the valid rule that matches the compliant status. However, the dACL sent to ASA and actually applied is the correct one based on the user profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE performs just authorization, not authentication which is validated by the ASA using certificates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Summarizing: ISE sees the user as compliant, internally matches the authorization profile for a compliant user, but the Radius logs are not updated accordingly and we see all the users with the status "unknown".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 12:15:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032238#M450062</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2020-02-19T12:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization profile not changed after posture compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032571#M450065</link>
      <description>&lt;P&gt;The behaviour you're seeing could be related to this bug:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf59076" target="_self"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf59076&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 20:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032571#M450065</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-19T20:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization profile not changed after posture compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032841#M476161</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The bug description completely matches my scenario indeed. Time to patch!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 07:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-profile-not-changed-after-posture-compliant/m-p/4032841#M476161</guid>
      <dc:creator>momo2017</dc:creator>
      <dc:date>2020-02-20T07:30:21Z</dc:date>
    </item>
  </channel>
</rss>

