<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Posture fail when admin node is down in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878487#M472029</link>
    <description>Are your PANs configured for failover? If they are then if the primary goes down then the secondary should become the primary in X amount of time. If they are not I recommend enabling it and running a test where you basically halt services on PAN1, failover to PAN2, and run the posture test.&lt;BR /&gt;You could install and run DART on one of the workstations to gather more descriptive logs locally. Also, on the switch you could run some debugs:&lt;BR /&gt;debug aaa coa&lt;BR /&gt;debug radius&lt;BR /&gt;The default CoA port is udp 1700. Ensure that is not blocked. HTH!&lt;BR /&gt;</description>
    <pubDate>Mon, 24 Jun 2019 12:32:37 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-06-24T12:32:37Z</dc:date>
    <item>
      <title>Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878403#M472027</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running ISE 2.6 p1 in a distributed setup with separate Pri admin, Sec admin, Pri monitor, Sec montitor and a few PSN.&lt;/P&gt;&lt;P&gt;I have a wierd issue that then the PSN loose connection to the primary admin node then posture fail. Anyconnect stays on "Checking requirement 1 of 1" for a while and then gives me error "Posture failed due to server issues".&lt;/P&gt;&lt;P&gt;The only requirement I have is to check if the antimalware software is installed or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to the documentation from Cisco the admin node should be able to fail without impacting posture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't figure out why the admin node is required to be online for posture to work. Do you have any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878403#M472027</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2019-06-24T09:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878487#M472029</link>
      <description>Are your PANs configured for failover? If they are then if the primary goes down then the secondary should become the primary in X amount of time. If they are not I recommend enabling it and running a test where you basically halt services on PAN1, failover to PAN2, and run the posture test.&lt;BR /&gt;You could install and run DART on one of the workstations to gather more descriptive logs locally. Also, on the switch you could run some debugs:&lt;BR /&gt;debug aaa coa&lt;BR /&gt;debug radius&lt;BR /&gt;The default CoA port is udp 1700. Ensure that is not blocked. HTH!&lt;BR /&gt;</description>
      <pubDate>Mon, 24 Jun 2019 12:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878487#M472029</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-06-24T12:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878564#M472031</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some tests with failover. During the time of failover Posture does not work, but as son as PAN2 becomes Primary admin then Posture starts working.&lt;/P&gt;&lt;P&gt;If I cut the connection between PSN and both PANs then Posture stops working.&lt;/P&gt;&lt;P&gt;In the switch I can see that user authentication is successfull, but then nothing more happens.&lt;/P&gt;&lt;P&gt;The switch and PSN are on the same VLAN.&lt;/P&gt;&lt;P&gt;I have gathered DART logs, but I am unsure what too look for. At first glance I dont see anything special that can be wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I fail to understand is why PSN needs connection to PAN when the only thing I am doing is checking if AVG Antivirus is installed on the computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 14:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3878564#M472031</guid>
      <dc:creator>Philip Vilhelmsson</dc:creator>
      <dc:date>2019-06-24T14:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3881845#M472034</link>
      <description>&lt;P&gt;I suggest creating TAC SR to determine root cause. For that posture policy active PAN should not be needed.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2019 07:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/3881845#M472034</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-06-29T07:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4052106#M559143</link>
      <description>&lt;P&gt;Any update on this?&amp;nbsp; My 2.6 patch 5 is doing the exact same thing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every get it fixed?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 14:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4052106#M559143</guid>
      <dc:creator>jont717</dc:creator>
      <dc:date>2020-03-25T14:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4294822#M565605</link>
      <description>&lt;P&gt;Did you ever sort this out?&amp;nbsp; we saw this recently during an upgrade to 2.6.&amp;nbsp; Opened a TAC case but haven't specifically been told why it posture took a hit yet.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 00:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4294822#M565605</guid>
      <dc:creator>bravotom99</dc:creator>
      <dc:date>2021-02-21T00:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Posture fail when admin node is down</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4294832#M565609</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324181"&gt;@bravotom99&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;are you having &lt;STRONG&gt;Posture&lt;/STRONG&gt;'s issues when &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; is &lt;U&gt;shutdown&lt;/U&gt;, but &lt;STRONG&gt;Posture&lt;/STRONG&gt; has no issues when &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; has the&amp;nbsp;&lt;STRONG&gt;Database Server&lt;/STRONG&gt; state as &lt;U&gt;running&lt;/U&gt;&amp;nbsp;and the&amp;nbsp;&lt;STRONG&gt;Application Server&lt;/STRONG&gt; still in the &lt;U&gt;initializing&lt;/U&gt; state?&lt;/P&gt;&lt;P&gt;PS.: check ISE's process state with &lt;STRONG&gt;show application status ise&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 03:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-fail-when-admin-node-is-down/m-p/4294832#M565609</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-02-21T03:07:42Z</dc:date>
    </item>
  </channel>
</rss>

