<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE anyconnect posture module with flexconnect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3776923#M486421</link>
    <description>&lt;P&gt;ISE 2.3 patch 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to do posturing of wireless connection using the anyconnect posture module, but trying to understand how the process actually works. I have AP in flexconnect local switching mode. I read &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&amp;nbsp;" target="_blank"&gt;ISE Posture Style Comparison for Pre and Post 2.2&lt;/A&gt;&amp;nbsp;where Anyconnect Posture Module initiates policy server detection by sending 4 types of probes. But is it the same process when flexconnect is configured and doing wireless?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;None of these probes will be seen by the WLC hence no redirect-url will be sent to the client. Does the AP intercept the probes instead? Using the flexconnect redirect ACL? And is the redirect-url sent by the AP to the client or by the WLC? I have a firewalls between client and data center where WLC lives, so need to know whether ports need to be open. What should I expect to see in a packet capture on the client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my situation since the client is connecting for the very first time and doing first posture, only probes 1 and 2 (&lt;SPAN&gt;HTTP get /auth/discovery to default gateway IP and&amp;nbsp;HTTP GET /auth/discovery to enroll.cisco.com)&lt;/SPAN&gt; will&amp;nbsp;be the valid probes right? Probe 3&amp;nbsp;won't apply since AC posture profile is not preconfigured on the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway my issue is that AC cannot detect the policy server, system scan shows no policy server detected. I did a debug client on the WLC and can the radius info with redirect url set from ISE:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Dot1x_NW_MsgTask_6: Jan 10 15:13:43.088: 40:a3:cc:f0:82:46 AAA Override Url-Redirect-Acl 'ACL-REDIRECT' mapped to ACL ID 255 and Flexconnect ACL ID 4&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Jan 10 15:13:43.088: 40:a3:cc:f0:82:46 AAA Override Url-Redirect '&lt;A href="https://psn01.ise.company.com:8443/portal/gateway?sessionId=3cfdca0a000e41cb76c6365c&amp;amp;portal=21f5afe0-e78b-11e8-81fe-0050568fd4cc&amp;amp;acti" target="_blank"&gt;https://psn01.ise.company.com:8443/portal/gateway?sessionId=3cfdca0a000e41cb76c6365c&amp;amp;portal=21f5afe0-e78b-11e8-81fe-0050568fd4cc&amp;amp;acti&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Except the client never seems to get it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 14:36:11 GMT</pubDate>
    <dc:creator>cisco2020</dc:creator>
    <dc:date>2019-01-10T14:36:11Z</dc:date>
    <item>
      <title>ISE anyconnect posture module with flexconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3776923#M486421</link>
      <description>&lt;P&gt;ISE 2.3 patch 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to do posturing of wireless connection using the anyconnect posture module, but trying to understand how the process actually works. I have AP in flexconnect local switching mode. I read &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&amp;nbsp;" target="_blank"&gt;ISE Posture Style Comparison for Pre and Post 2.2&lt;/A&gt;&amp;nbsp;where Anyconnect Posture Module initiates policy server detection by sending 4 types of probes. But is it the same process when flexconnect is configured and doing wireless?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;None of these probes will be seen by the WLC hence no redirect-url will be sent to the client. Does the AP intercept the probes instead? Using the flexconnect redirect ACL? And is the redirect-url sent by the AP to the client or by the WLC? I have a firewalls between client and data center where WLC lives, so need to know whether ports need to be open. What should I expect to see in a packet capture on the client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my situation since the client is connecting for the very first time and doing first posture, only probes 1 and 2 (&lt;SPAN&gt;HTTP get /auth/discovery to default gateway IP and&amp;nbsp;HTTP GET /auth/discovery to enroll.cisco.com)&lt;/SPAN&gt; will&amp;nbsp;be the valid probes right? Probe 3&amp;nbsp;won't apply since AC posture profile is not preconfigured on the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway my issue is that AC cannot detect the policy server, system scan shows no policy server detected. I did a debug client on the WLC and can the radius info with redirect url set from ISE:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Dot1x_NW_MsgTask_6: Jan 10 15:13:43.088: 40:a3:cc:f0:82:46 AAA Override Url-Redirect-Acl 'ACL-REDIRECT' mapped to ACL ID 255 and Flexconnect ACL ID 4&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Jan 10 15:13:43.088: 40:a3:cc:f0:82:46 AAA Override Url-Redirect '&lt;A href="https://psn01.ise.company.com:8443/portal/gateway?sessionId=3cfdca0a000e41cb76c6365c&amp;amp;portal=21f5afe0-e78b-11e8-81fe-0050568fd4cc&amp;amp;acti" target="_blank"&gt;https://psn01.ise.company.com:8443/portal/gateway?sessionId=3cfdca0a000e41cb76c6365c&amp;amp;portal=21f5afe0-e78b-11e8-81fe-0050568fd4cc&amp;amp;acti&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Except the client never seems to get it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3776923#M486421</guid>
      <dc:creator>cisco2020</dc:creator>
      <dc:date>2019-01-10T14:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE anyconnect posture module with flexconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3776929#M486425</link>
      <description>You might want to go through &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116087-configure-cwa-wlc-ise-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116087-configure-cwa-wlc-ise-00.html&lt;/A&gt; . Though this document is for CWA/Guest, the redirection flow and configuration is exactly the same as it does not differ for different use cases. If you configure the WLC/AP as described in the document above, you should not face any issues with redirection.&lt;BR /&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3776929#M486425</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-01-10T14:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE anyconnect posture module with flexconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3777003#M486495</link>
      <description>&lt;P&gt;Also recommend posture and wireless best practices&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/top-six-important-cisco-wlc-settings-for-ise-integration/ta-p/3643795" target="_blank"&gt;https://community.cisco.com/t5/security-documents/top-six-important-cisco-wlc-settings-for-ise-integration/ta-p/3643795&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check this site for posture guides&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture/ta-p/3657443" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-posture/ta-p/3657443&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://cs.co/ise-guides" target="_blank"&gt;http://cs.co/ise-guides&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 15:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3777003#M486495</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-10T15:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE anyconnect posture module with flexconnect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3859825#M486496</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went through the links, but doesnt explicitly mention about the ISE probes with flexconnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm the following:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;Does the AP intercept the probes instead? Using the flexconnect redirect ACL?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Is the redirect-url sent by the AP to the client or by the WLC?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am trying to figure out why probes 1 and 2 (HTTP get /auth/discovery to default gateway IP and&amp;nbsp;HTTP GET /auth/discovery to enroll.cisco.com) is showing as failing in AnyConnect DART bundle.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 03:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anyconnect-posture-module-with-flexconnect/m-p/3859825#M486496</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2019-05-21T03:15:44Z</dc:date>
    </item>
  </channel>
</rss>

