<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE policy server issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy-server-issue/m-p/3917540#M457359</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have an issue on our ISE where when a user who works at another site most weeks. When they've been on the 3rd party network their anyconnect profile service updates on our laptops with the 3rd party server settings. When we inspect laptop the policy server is not auto updating by itself and still has the 3rd party server in the configuration. We must replace the cfg file to get this working again.&lt;/P&gt;&lt;P&gt;Is there anything we can do to ensure this updates to our own/stops this being overwritten froma design standpoint.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Sep 2019 08:36:08 GMT</pubDate>
    <dc:creator>GiHan55803</dc:creator>
    <dc:date>2019-09-02T08:36:08Z</dc:date>
    <item>
      <title>ISE policy server issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-server-issue/m-p/3917540#M457359</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have an issue on our ISE where when a user who works at another site most weeks. When they've been on the 3rd party network their anyconnect profile service updates on our laptops with the 3rd party server settings. When we inspect laptop the policy server is not auto updating by itself and still has the 3rd party server in the configuration. We must replace the cfg file to get this working again.&lt;/P&gt;&lt;P&gt;Is there anything we can do to ensure this updates to our own/stops this being overwritten froma design standpoint.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 08:36:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-server-issue/m-p/3917540#M457359</guid>
      <dc:creator>GiHan55803</dc:creator>
      <dc:date>2019-09-02T08:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE policy server issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-server-issue/m-p/3917769#M457360</link>
      <description>&lt;P&gt;I have to assume that you are referring to the Anyconnect ISE Posture Agent.&amp;nbsp; It will keep track of any policy servers that it has previously connected to for use in its discovery phase.&amp;nbsp; If your client provisioning/posture redirection stuff is configured correctly (i.e. redirect ACL, client provisioning policies), then this shouldn't cause a problem.&amp;nbsp; So I would double check those things first.&amp;nbsp; Then, you can modify the posture profile in ISE to limit which policy servers it can connect to so that it doesn't connect to PSNs outside of your environment.&amp;nbsp; You can also use the Discovery Host field there to force it to redirect in your environment.&amp;nbsp; Use an IP address or FQDN that you know would hit on your redirection ACLs.&amp;nbsp; Do not put a PSN in the Discovery Host field.&amp;nbsp; Following is a screenshot:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Posture_Profile.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44183i4112E41F87075B3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Posture_Profile.jpg" alt="Posture_Profile.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 17:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-server-issue/m-p/3917769#M457360</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-09-02T17:30:37Z</dc:date>
    </item>
  </channel>
</rss>

