<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Posture lease and Cache Last Known Posture Compliant Status in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4005019#M454729</link>
    <description>&lt;P&gt;Hi Experts,&lt;BR /&gt;I need some further clarifications on the above two settings that are under&amp;nbsp;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Administration&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;System&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Settings&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Posture&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;General Settings...&lt;BR /&gt;As per my understanding in the documentation, &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; is used for a specified period of time, when we do not to run posture checks everytime an endpoint detects a network change or when a user logs in and logs off the network, correct?&lt;BR /&gt;So in a nutshell ISE will keep last known posture status for, let's say 24 hours and will perform next posture check when user logs in after 24 hours...&lt;BR /&gt;Then, if that is posture lease is used, then in what scenario or use would&amp;nbsp;&lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt; be used?&lt;BR /&gt;What would be implication if I keep Posture Lease for 1 day (24 hours) and keep&amp;nbsp;Cache Last Known Posture Compliant Status for 30 hours? Will ISE then run the next posture check after 24 hours or 30 hours?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Any pointers?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2019 08:49:28 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2019-12-31T08:49:28Z</dc:date>
    <item>
      <title>Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4005019#M454729</link>
      <description>&lt;P&gt;Hi Experts,&lt;BR /&gt;I need some further clarifications on the above two settings that are under&amp;nbsp;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Administration&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;System&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Settings&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Posture&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;General Settings...&lt;BR /&gt;As per my understanding in the documentation, &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; is used for a specified period of time, when we do not to run posture checks everytime an endpoint detects a network change or when a user logs in and logs off the network, correct?&lt;BR /&gt;So in a nutshell ISE will keep last known posture status for, let's say 24 hours and will perform next posture check when user logs in after 24 hours...&lt;BR /&gt;Then, if that is posture lease is used, then in what scenario or use would&amp;nbsp;&lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt; be used?&lt;BR /&gt;What would be implication if I keep Posture Lease for 1 day (24 hours) and keep&amp;nbsp;Cache Last Known Posture Compliant Status for 30 hours? Will ISE then run the next posture check after 24 hours or 30 hours?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Any pointers?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 08:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4005019#M454729</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-12-31T08:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4302670#M565927</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Answer to this query is not documented anywhere, i think you should raise a case with TAC so that they can test it internally and present an answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 04:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4302670#M565927</guid>
      <dc:creator>Manjunath Sheregar</dc:creator>
      <dc:date>2021-03-07T04:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4302798#M565929</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/224506"&gt;@dgaikwad&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/334620"&gt;@Manjunath Sheregar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;remember that:&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;... When the &lt;U&gt;posture lease is active&lt;/U&gt;, &lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt; &lt;U&gt;will use the last known posture state&lt;/U&gt; and will &lt;U&gt;not reach out to the endpoint to check for compliance&lt;/U&gt;. But when the &lt;U&gt;posture lease expires&lt;/U&gt;, &lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt; does &lt;U&gt;not automatically trigger a re-authentication or a posture reassessment for the endpoint&lt;/U&gt;. The endpoint will stay in the same compliance state &lt;U&gt;since the same session is being used&lt;/U&gt;. When the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; &lt;U&gt;re-authenticates&lt;/U&gt;, &lt;STRONG&gt;Posture&lt;/STRONG&gt; &lt;U&gt;will be run&lt;/U&gt; and the &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; time &lt;U&gt;will be reset&lt;/U&gt;...&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;... &lt;STRONG&gt;Last Known Posture Compliant Status&lt;/STRONG&gt;: This setting only applies if you have checked &lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt;. &lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt; caches the result of posture assessment for the amount of time specified in this field. &lt;U&gt;Valid values&lt;/U&gt; are from &lt;U&gt;1 to 30 days&lt;/U&gt;, or from &lt;U&gt;1 to 720 hours&lt;/U&gt; (1 hour to 30 days),&amp;nbsp;or from &lt;U&gt;1 to 43200 minutes&lt;/U&gt; (1 minute to 30 days)...&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; is &lt;STRONG&gt;24h&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Posture Compliance Status&lt;/STRONG&gt; is &lt;STRONG&gt;30h&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Last Compliance Status&lt;/STRONG&gt; is &lt;STRONG&gt;Compliant&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;then:&lt;/P&gt;&lt;PRE&gt;before 24h:&lt;BR /&gt;. if the user &lt;U&gt;logs off&lt;/U&gt; and &lt;U&gt;logs on&lt;/U&gt;, since the &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; and the &lt;STRONG&gt;Last Compliance Status&lt;/STRONG&gt; is &lt;STRONG&gt;Compliant&lt;/STRONG&gt;, then the user is provided access without &lt;STRONG&gt;Posture&lt;/STRONG&gt; being run on the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;.&lt;BR /&gt;after 24h:&lt;BR /&gt;. if the user &lt;U&gt;logs off&lt;/U&gt; and &lt;U&gt;logs on&lt;/U&gt;, since the &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; has expired, a &lt;STRONG&gt;Posture Assessment&lt;/STRONG&gt; is performed.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 07 Mar 2021 17:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4302798#M565929</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-07T17:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4605004#M574564</link>
      <description>&lt;P&gt;I interviewed the lecturer about this on Cisco Live and these are my notes:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;&lt;SPAN&gt;Perform posture assessment every .. days&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;A lease. Does not remember last state. Skips check within the lease time (That is why PRA should be used too.)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;&lt;SPAN&gt;Cache Last Known Posture Compliant Status&lt;/SPAN&gt;&lt;SPAN&gt; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Remembers last Compliant or NonCompliant status. &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lease off, Cache on:&lt;/STRONG&gt; allows to connect as compliant but start posture check after connecting&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lease on, Cache off:&lt;/STRONG&gt; posture not checked and allowed immediately as compliant (should combine with PRA)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I still did not understand after the explanation. )-:&lt;/P&gt;&lt;P&gt;The other 2 combinations were not discussed.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 10:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4605004#M574564</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2022-05-05T10:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4605039#M574567</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285490"&gt;@Peter Koltl&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;you are able to find these options at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Posture &amp;gt; General Settings&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;a &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; can't be "Off", the options are:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. Perform Posture Assessment every time a User connects to the network&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. Perform Posture Assessment every 1-365 days. (this configuration &lt;U&gt;ONLY&lt;/U&gt; applies to &lt;STRONG&gt;AnyConnect Agent&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;a &lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt; can be "Off" or "On".&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 12:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/4605039#M574567</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-05T12:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5013534#M587108</link>
      <description>&lt;P&gt;The above explanations are helpful.&amp;nbsp; Thank you.&amp;nbsp; I have more questions.&lt;/P&gt;&lt;P&gt;I think I am interested in daily scans.&amp;nbsp; Much of my organization works Monday-Friday.&amp;nbsp; 8a to 5p.&amp;nbsp; Staff are remote one day and in the office the next.&lt;/P&gt;&lt;P&gt;Setting perform posture assessment every 1 day - seems like the correct setting.&lt;/P&gt;&lt;P&gt;Why would I enable cache last known?&amp;nbsp; Is there a recommended length of time?&lt;/P&gt;&lt;P&gt;If someone starts their day at 8:15a and the next day at 7:50a, will the perform posture every day scan?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5013534#M587108</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2024-02-06T12:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5020941#M587460</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323562"&gt;@rmeans&lt;/a&gt;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Q.:&lt;/STRONG&gt; &lt;EM&gt;I think I am interested in daily scans&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;A.:&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Posture Assessment&lt;/STRONG&gt; &lt;U&gt;every day&lt;/U&gt;&amp;nbsp;is a good option !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Q.:&lt;/STRONG&gt; &lt;EM&gt;Why would I enable cache last known? Is there a recommended length of time?&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;A.:&lt;/STRONG&gt; If you enable the&amp;nbsp;&lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt;,&amp;nbsp;&lt;STRONG&gt;ISE&lt;/STRONG&gt;&amp;nbsp;caches the result of &lt;STRONG&gt;Posture Assessment&lt;/STRONG&gt; for the amount of time specified in this field, in other words, if the &lt;STRONG&gt;Users&lt;/STRONG&gt; &lt;U&gt;log off&lt;/U&gt; and &lt;U&gt;log on&lt;/U&gt; multiples times during the &lt;STRONG&gt;Cache Last Known Posture Compliant Status&lt;/STRONG&gt;&amp;nbsp;amount of time&amp;nbsp;then the &lt;STRONG&gt;User&lt;/STRONG&gt; is provided access without &lt;STRONG&gt;Posture&lt;/STRONG&gt; being run on the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; ... pros: &lt;U&gt;faster&lt;/U&gt;, cons: &lt;U&gt;"less secure"&lt;/U&gt; (since you are trusting on the "last compliance status") ... recommended &lt;STRONG&gt;Length of Time&lt;/STRONG&gt;: IMO less than a day (for ex.: you can use &lt;STRONG&gt;4 hours&lt;/STRONG&gt; - "&lt;EM&gt;till lunch time&lt;/EM&gt;", or &lt;STRONG&gt;8 hours&lt;/STRONG&gt; - "&lt;EM&gt;during working hours&lt;/EM&gt;").&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Q.:&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;If someone starts their day at 8:15a and the next day at 7:50a, will the perform posture every day scan?&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;A.:&lt;/STRONG&gt;&amp;nbsp;Although &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; is in &lt;STRONG&gt;Days&lt;/STRONG&gt;, you have to think in &lt;STRONG&gt;Hours&lt;/STRONG&gt;, for ex:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"...&amp;nbsp;&lt;EM&gt;The &lt;STRONG&gt;user&lt;/STRONG&gt; &lt;U&gt;logs on&lt;/U&gt; to the &lt;STRONG&gt;endpoint&lt;/STRONG&gt; and gets it &lt;STRONG&gt;Posture Compliant&lt;/STRONG&gt; with the &lt;STRONG&gt;posture lease&lt;/STRONG&gt; set to &lt;U&gt;one day&lt;/U&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;EM&gt;&lt;U&gt;Four hours later&lt;/U&gt; the &lt;STRONG&gt;user&lt;/STRONG&gt; &lt;U&gt;logs off&lt;/U&gt; from the endpoint (the posture lease now has &lt;U&gt;20 hours left&lt;/U&gt;).&lt;/EM&gt;"&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: remember that you can use the&amp;nbsp;&lt;STRONG&gt;Last Known Posture Compliant State = 8 hours&lt;/STRONG&gt; and &lt;STRONG&gt;Default Posture Status = NonCompliant&lt;/STRONG&gt; with the&amp;nbsp;&lt;STRONG&gt;Perform Posture Assessment Every = 1 day&lt;/STRONG&gt;&amp;nbsp;to reach your goals !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 02:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5020941#M587460</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-02-20T02:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218040#M592876</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still a bit confused on this. Here are my current settings:&lt;/P&gt;&lt;P&gt;TEAP with EAP-TLS, we have separate authorization policies for machine (no posturing) and user authentication (yes posturing)&lt;/P&gt;&lt;P&gt;Default compliant state is set to Non-Compliant&lt;/P&gt;&lt;P&gt;Posture Lease is set for 1 day&lt;/P&gt;&lt;P&gt;Cache Last Known Posture Compliant Status is enabled for 8 hours&lt;/P&gt;&lt;P&gt;Here is the scenario:&lt;/P&gt;&lt;P&gt;When a user initially signs in on a Friday, posture assessment is performed and compliant, the user leaves at the end of the day without logging out.&lt;/P&gt;&lt;P&gt;What will happen to the posture status over the weekend when the user isn't there? Will it remain compliant until the user returns on Monday? Also, let's say over the weekend the user's computer got disconnected briefly from the wireless network but was able to reconnect, what happens then?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 12:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218040#M592876</guid>
      <dc:creator>romankielbowicz</dc:creator>
      <dc:date>2024-10-31T12:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218271#M592895</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1232995"&gt;@romankielbowicz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;On &lt;STRONG&gt;Friday&lt;/STRONG&gt; at &lt;STRONG&gt;08AM&lt;/STRONG&gt; the &lt;STRONG&gt;User&lt;/STRONG&gt; &lt;U&gt;logs on&lt;/U&gt; to the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; and gets it &lt;STRONG&gt;Posture Compliance&lt;/STRONG&gt; with the &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; set to &lt;STRONG&gt;24 Hours&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;On &lt;STRONG&gt;Saturday&lt;/STRONG&gt; at &lt;STRONG&gt;08AM&lt;/STRONG&gt;&amp;nbsp;the &lt;STRONG&gt;Posture Lease&amp;nbsp;&lt;/STRONG&gt;&lt;U&gt;expires&lt;/U&gt;, but &lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt; does &lt;U&gt;not automatically trigger a&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Re-Authentication&lt;/STRONG&gt; or a &lt;STRONG&gt;Posture Reassessment&lt;/STRONG&gt; for the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;. The &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; will stay in the &lt;U&gt;same&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Compliance State&lt;/STRONG&gt; since the &lt;U&gt;same&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Session&lt;/STRONG&gt; is being used. When the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; &lt;U&gt;re-authenticates&lt;/U&gt;, &lt;STRONG&gt;Posture&lt;/STRONG&gt; will &lt;U&gt;be run&lt;/U&gt; and the &lt;STRONG&gt;Posture Lease&lt;/STRONG&gt; time will be &lt;U&gt;reset&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 18:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218271#M592895</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-10-31T18:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218558#M592904</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;In what circumstance would the compliance state change from compliant to unknown if the same session ID is still being used?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 12:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5218558#M592904</guid>
      <dc:creator>romankielbowicz</dc:creator>
      <dc:date>2024-11-01T12:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232428#M593572</link>
      <description>&lt;P&gt;My organization continues to work on posture settings.&amp;nbsp; We have had posture assessment set to 1 day and a 4-hour cache for some time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am interested in changing perform assessment to every time and either disabling cache or setting to 1-4 hrs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone doing this?&amp;nbsp; Any concerns?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My goals.&lt;/P&gt;&lt;P&gt;I noticed that not everyone does a posture assessment first thing in the morning.&amp;nbsp; Staff might work remote or late the day before.&amp;nbsp; Their posture lease continues to the next day.&amp;nbsp; When monitoring live logs, not everyone has a posture status (pending or complaint).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next, I believe the more frequent posture assessments will mean more frequent entries in the Posture End Point Assessment reports.&amp;nbsp; I find valuable info in the reports.&amp;nbsp; More frequent entries will help identify issues more quickly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My authorization policies allow the same level of network access for pending and compliant.&amp;nbsp; The laptop CPU will have increased load.&amp;nbsp; ISE might have an increased load.&amp;nbsp; But the end user’s applications (email) shouldn’t be impacted.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232428#M593572</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2024-12-04T13:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232431#M593573</link>
      <description>&lt;P&gt;Unknown (policy set config) and pending (live logs) are the same.&amp;nbsp; I see laptops go to the unknown/pending state when connecting to the network.&amp;nbsp; Followed by either compliant or non-compliant.&amp;nbsp; I haven't seen a device go from complaint to unknown/pending.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 13:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232431#M593573</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2024-12-04T13:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232437#M593574</link>
      <description>&lt;P&gt;Any reason why you have the same network access on pending and compliant? Do you pre-deploy CSC/Anyconnect or do you use the provisioning portal? If the endpoint is in a pending state, wouldn’t you want to only allow access to ISE for client provisioning using redirection or use redirectionless probes for ISE discovery? I can tell you from personal experience that doing posture assessment every time a user connects to a network is not a bad option but becomes troublesome on a Meraki wireless network where clients roam from AP to AP.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 14:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232437#M593574</guid>
      <dc:creator>romankielbowicz</dc:creator>
      <dc:date>2024-12-04T14:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232492#M593577</link>
      <description>&lt;P&gt;Originally, we had a restrictive policy with pending and a more open policy for compliant.&amp;nbsp; It has taken months; we believe the restrictive policy is preventing the normal boot up and login process from completing successfully.&amp;nbsp; We discovered applications would fail (even later in the day).&amp;nbsp; Testing is ongoing, but we believe the restrictive policy is at fault.&lt;/P&gt;&lt;P&gt;We are using TEAP with a device and user cert.&amp;nbsp; It takes up to 30 seconds from user login to posture completes.&amp;nbsp; During the 30 seconds the laptop is doing a lot.&amp;nbsp; We have not successfully defined everything the laptop needs for a successful boot up.&lt;/P&gt;&lt;P&gt;We have been trying to update AnyConnect to Secure Client.&amp;nbsp; We use the ISE provision portal.&amp;nbsp; All laptops have AnyC with posture mod installed and working.&amp;nbsp; The provisioning portal conditions trigger by area in the network (the 5th floor switch).&amp;nbsp; Staff should be able to boot up on the 5th floor and get the SecClient update.&lt;/P&gt;&lt;P&gt;If I posture assess every time but have a 1 hr cache.&amp;nbsp; Would that help wireless?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 15:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232492#M593577</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2024-12-04T15:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232530#M593579</link>
      <description>&lt;P&gt;I think that might depend on the kind of wireless infrastructure you have. Do you use Meraki APs or Cisco APs?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 16:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5232530#M593579</guid>
      <dc:creator>romankielbowicz</dc:creator>
      <dc:date>2024-12-04T16:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Posture lease and Cache Last Known Posture Compliant Status</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5297463#M596697</link>
      <description>&lt;P&gt;Hi rmeans,&lt;/P&gt;
&lt;P&gt;how does the testing go until now ?&lt;/P&gt;
&lt;P&gt;Have you come already to final tuned up settings for your environment ?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2025 13:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-lease-and-cache-last-known-posture-compliant-status/m-p/5297463#M596697</guid>
      <dc:creator>stayd</dc:creator>
      <dc:date>2025-06-07T13:22:57Z</dc:date>
    </item>
  </channel>
</rss>

