<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: posture rescan in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4008020#M454764</link>
    <description>&lt;P&gt;Thanks Mike&lt;/P&gt;&lt;P&gt;took a look where you suggested&amp;nbsp;&lt;/P&gt;&lt;P&gt;- however, the lowest interval on reassessment is 1hr&amp;nbsp; in these setting ? This period for a failed compliant / rescan is obviously too long for us&lt;/P&gt;&lt;P&gt;In our senario - we wish to see if the client fails compliance - they can try again at&amp;nbsp; the clients will&amp;nbsp; - ideally using the rescan button ( in POC we've been restarting the service - not an option for users)&lt;/P&gt;&lt;P&gt;please refer to attached as an overview of what we're experiencing&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2020 10:13:25 GMT</pubDate>
    <dc:creator>adrianmadley</dc:creator>
    <dc:date>2020-01-08T10:13:25Z</dc:date>
    <item>
      <title>posture rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4007494#M454695</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;using ISE 2.2&lt;SPAN&gt;- client = anyconnect&amp;nbsp; 4.6&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;getting ready to deploy posture checking :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;when testing&amp;nbsp; - forcing failures / successes - we where using a restart of the&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;cisco anyconnect secure mobility ISE posture agent - services, in order to repeat testing - get the host scanning again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we're not expecting end users to do this - we used&amp;nbsp;ISE Posture Profile Editor on the selected host&amp;nbsp;and entered&amp;nbsp; the recommended&amp;nbsp; entry of&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;EnableRescanButton&amp;gt;1&amp;lt;/EnableRescanButton&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to the xml file&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in order to perform a rescan ....this&amp;nbsp; runs fine once.! after which I believe the following is occurring -&lt;/P&gt;&lt;P&gt;the client has made contact with ISE - which enforces it's configured&amp;nbsp; setting in&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;AnyConnect Configuration&amp;nbsp;&amp;gt;Profile Selection&amp;nbsp;&amp;gt;* ISE posture setting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the&amp;nbsp;Posture Agent Profile Settings we have defined&amp;nbsp;i cannot see a&amp;nbsp; field to enforce rescan ?..... is this s/w version related / if so, is there a work around - or have I just missed a trick here ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your continued support is greatly appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 11:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4007494#M454695</guid>
      <dc:creator>adrianmadley</dc:creator>
      <dc:date>2020-01-07T11:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: posture rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4007582#M454696</link>
      <description>Take a peek in ISE under Administration-&amp;gt;System-&amp;gt;Settings-&amp;gt;Posture-&amp;gt;Reassessments&lt;BR /&gt;Under here you can setup custom reassessment configurations and map them to certain groups.</description>
      <pubDate>Tue, 07 Jan 2020 14:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4007582#M454696</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-01-07T14:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: posture rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4008020#M454764</link>
      <description>&lt;P&gt;Thanks Mike&lt;/P&gt;&lt;P&gt;took a look where you suggested&amp;nbsp;&lt;/P&gt;&lt;P&gt;- however, the lowest interval on reassessment is 1hr&amp;nbsp; in these setting ? This period for a failed compliant / rescan is obviously too long for us&lt;/P&gt;&lt;P&gt;In our senario - we wish to see if the client fails compliance - they can try again at&amp;nbsp; the clients will&amp;nbsp; - ideally using the rescan button ( in POC we've been restarting the service - not an option for users)&lt;/P&gt;&lt;P&gt;please refer to attached as an overview of what we're experiencing&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 10:13:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4008020#M454764</guid>
      <dc:creator>adrianmadley</dc:creator>
      <dc:date>2020-01-08T10:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: posture rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4008044#M454765</link>
      <description>&lt;P&gt;ok ladies &amp;amp; gentlemen&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please stand down ...as we've managed to work it out ...&lt;/P&gt;&lt;P&gt;Ironically we had tried this previously&amp;nbsp; , however, not in the correct way ....due to restricted access of the testing client we couldn't copy the *iseposture*.xml off the host after editing - so we rudimentarily copied the .xml into notepad ++ and saved a .xml - tried to use that as a -&lt;/P&gt;&lt;P&gt;AnyConnect Configuration &amp;gt; AnyConnent Posture Agent Profile&lt;/P&gt;&lt;P&gt;when we did this the hash value was accepted ...however, we saw an error message when we tried to bind that to our posture agent profile ( must have been because of the c'n''p - saving a txt as an .xml)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyways - luckily the testing client could browser to the ISE - so we imported the /agent/ as a /customer created package/ from local disk - assigned this to our relevant / AnyConnent Posture Agent Profile/ and bingo -&amp;nbsp;&lt;/P&gt;&lt;P&gt;the rescan button stays intact post ISE comms&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks to all for looking / responding&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 11:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-rescan/m-p/4008044#M454765</guid>
      <dc:creator>adrianmadley</dc:creator>
      <dc:date>2020-01-08T11:09:23Z</dc:date>
    </item>
  </channel>
</rss>

