<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 Posture and Reauth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836207#M473985</link>
    <description>Thanks it would be good to also get logs and open a tac case to tweak what’s going on. You’re running good versions of the products.&lt;BR /&gt;&lt;BR /&gt;Also good info is what kind of authentication you’re doing. Wondering if your supplicant is not correctly syncing? But it’s a discussion for a tac case with a dedicated engineer to run through instead of back and forth here&lt;BR /&gt;</description>
    <pubDate>Wed, 10 Apr 2019 17:36:26 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-04-10T17:36:26Z</dc:date>
    <item>
      <title>ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836046#M473970</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have a customer who is utilizing the Posture module with ISE. The majority of their users lock their workstation overnight and when they log back in in the morning the posture client never kicks off for whatever reason leaving them in a remediation state and not giving them access to internal resources per the dACL. If they click the "Scan Again" button on the posture module it initiates the scan and makes them compliant and everything works as intended. Obviously this is not optimal for the entire user base as we roll this out organization wide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any best practices for re-auth or posture settings I can fidget with to try and get this to be an automated process. Users that take their laptops home with them and re-dock in the morning are not having this issue at all, it's only users who log out at night and re-login in the morning.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836046#M473970</guid>
      <dc:creator>cburger13</dc:creator>
      <dc:date>2019-04-10T15:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836118#M473972</link>
      <description>&lt;P&gt;I would investigate why the posture assessment is not happening when the user logs in.&amp;nbsp; If the customer is doing user authentication via 802.1X, then posture should be performed every time the user logs into the machine.&amp;nbsp; The fact that users who take home their workstations are postured when they connect the next day suggests that the posture lease configuration is set to perform posture every time a user connects to the network under "Posture General Settings" in ISE.&amp;nbsp; You could explore changing the posture lease or the Cached compliance status in the same menu but I would be curious as to why users who leave their workstations are not being postured when they log in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836118#M473972</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-04-10T15:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836128#M473974</link>
      <description>It turns out the users are locking their machines and not doing a logoff when they leave for the night. I’m guessing when they unlock their machines it’s not actually doing a session re-authentication thus not kicking off the posture agent.&lt;BR /&gt;&lt;BR /&gt;The posture settings are set to check when a user connects to the network, so shouldn’t that still be stored from when the user last logged in?&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836128#M473974</guid>
      <dc:creator>cburger13</dc:creator>
      <dc:date>2019-04-10T15:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836172#M473975</link>
      <description>&lt;P&gt;Do you have a reassessment timer configured?&amp;nbsp; You could configure a global 8 hour reassessment timer to see if that helps.&amp;nbsp; Administration-&amp;gt;Systems-&amp;gt;Settings-&amp;gt;Posture-&amp;gt;Reassessments.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 16:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836172#M473975</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-10T16:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836180#M473977</link>
      <description>Also wha version of ise and Anyconnect&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 16:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836180#M473977</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-10T16:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836187#M473979</link>
      <description>&lt;P&gt;ISE is 2.4 patch 5 and Anyconnect is 4.6.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836187#M473979</guid>
      <dc:creator>cburger13</dc:creator>
      <dc:date>2019-04-10T17:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836189#M473983</link>
      <description>&lt;P&gt;I thought about this, but I don't see a way to do one of these based off AD groups. Only internal user or endpoint identity groups, of which the AD users are not a part of.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836189#M473983</guid>
      <dc:creator>cburger13</dc:creator>
      <dc:date>2019-04-10T17:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836207#M473985</link>
      <description>Thanks it would be good to also get logs and open a tac case to tweak what’s going on. You’re running good versions of the products.&lt;BR /&gt;&lt;BR /&gt;Also good info is what kind of authentication you’re doing. Wondering if your supplicant is not correctly syncing? But it’s a discussion for a tac case with a dedicated engineer to run through instead of back and forth here&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836207#M473985</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-10T17:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836208#M473990</link>
      <description>Yea, I have a TAC case open, but my engineer has been less than helpful so far. Won’t return e-mails nor calls.&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836208#M473990</guid>
      <dc:creator>cburger13</dc:creator>
      <dc:date>2019-04-10T17:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836210#M473991</link>
      <description>Just sent the identity to Any.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 17:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836210#M473991</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-04-10T17:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Posture and Reauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836249#M473994</link>
      <description>I would suggest you ask for escalation to duty manager&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2019 18:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-posture-and-reauth/m-p/3836249#M473994</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-04-10T18:43:26Z</dc:date>
    </item>
  </channel>
</rss>

