<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736648#M488810</link>
    <description>&lt;P&gt;Hi all .&lt;/P&gt;
&lt;P&gt;I have specific situation/problem for Anyconnect VPN&amp;nbsp; static ip assignment. -it does not work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyconnect 4.6 client&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA 9.4.4 interim&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authentication with cetificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorization with Posture check .&lt;/P&gt;
&lt;P&gt;1. Users Authenicate on ASA with certificate , get dhcp from ASA (defined in section Anyconnect Client Profile -&amp;gt; Client Address Assigment -&amp;gt; DHCP Servers:)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Then users goes to authorization process with posture and if he is compliant, then apply access to network and apply static ip address address with rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;DACL = Anyconnect-Compliant&lt;BR /&gt;Framed-IP-Address = 10.250.200.193&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried with feching attribute from AD(what would be better solution) but situation is the same&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;DACL = Anyconnect-Compliant&lt;BR /&gt;Framed-IP-Address = AD:extensionAttribute13&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Can system coexist with dhcp assignment and static ip assignment (users that dont need static ip on vpn need to get ip from dhcp)&lt;/P&gt;
&lt;P&gt;2. How to assign static ip to users from AD , and when? Since i do authentication on ASA with cert , can be ip address be changed from DHCP to static with auth profile after posture process is complete or it need to be done on ASA when authentication process is underway ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. If under auhentication process - then how to combo ip address assignment with dhcp and ASA -&amp;gt; AD per user static ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone know to solve this , because today TAC helped little but still cant solve.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;VZ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 16:12:32 GMT</pubDate>
    <dc:creator>startx001</dc:creator>
    <dc:date>2018-10-31T16:12:32Z</dc:date>
    <item>
      <title>ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736648#M488810</link>
      <description>&lt;P&gt;Hi all .&lt;/P&gt;
&lt;P&gt;I have specific situation/problem for Anyconnect VPN&amp;nbsp; static ip assignment. -it does not work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyconnect 4.6 client&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA 9.4.4 interim&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authentication with cetificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authorization with Posture check .&lt;/P&gt;
&lt;P&gt;1. Users Authenicate on ASA with certificate , get dhcp from ASA (defined in section Anyconnect Client Profile -&amp;gt; Client Address Assigment -&amp;gt; DHCP Servers:)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Then users goes to authorization process with posture and if he is compliant, then apply access to network and apply static ip address address with rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;DACL = Anyconnect-Compliant&lt;BR /&gt;Framed-IP-Address = 10.250.200.193&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried with feching attribute from AD(what would be better solution) but situation is the same&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;DACL = Anyconnect-Compliant&lt;BR /&gt;Framed-IP-Address = AD:extensionAttribute13&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Can system coexist with dhcp assignment and static ip assignment (users that dont need static ip on vpn need to get ip from dhcp)&lt;/P&gt;
&lt;P&gt;2. How to assign static ip to users from AD , and when? Since i do authentication on ASA with cert , can be ip address be changed from DHCP to static with auth profile after posture process is complete or it need to be done on ASA when authentication process is underway ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. If under auhentication process - then how to combo ip address assignment with dhcp and ASA -&amp;gt; AD per user static ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone know to solve this , because today TAC helped little but still cant solve.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;VZ&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 16:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736648#M488810</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-10-31T16:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736683#M488813</link>
      <description>&lt;P&gt;Do you want to give specific IP address to users from ISE?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does assigning IP address with&amp;nbsp;Framed-IP-Address = 10.250.200.193 work for you ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assigning IP address with Framed-IP-Address = AD:extensionAttribute13 is not working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 16:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736683#M488813</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-31T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736970#M488815</link>
      <description>&lt;P&gt;Please review the chapter &lt;A title="IP Addresses for VPNs" href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/vpn/asa-94-vpn-config/vpn-addresses.html" target="_blank"&gt;IP Addresses for VPNs&lt;/A&gt; in Cisco ASA VPN CLI Configuration Guide.&lt;/P&gt;
&lt;P&gt;Also, a related discussion --&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/set-static-ip-to-anyconnect-user-using-ise/td-p/3358367" target="_blank"&gt;Set Static IP to Anyconnect user using ... - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 02:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3736970#M488815</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-01T02:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737087#M488817</link>
      <description>&lt;P&gt;Hi Pan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you want to give specific IP address to users from ISE?&lt;/P&gt;
&lt;P&gt;- Yes in the way, that i match attribute13 from AD with authorization policy after posture process. If this cant be a option since authentication is done on ASA with Cert , then please advise .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does assigning IP address with&amp;nbsp;Framed-IP-Address = 10.250.200.193 work for you ?&lt;/P&gt;
&lt;P&gt;- No it does not work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assigning IP address with Framed-IP-Address = AD:extensionAttribute13 is not working?&lt;/P&gt;
&lt;P&gt;- Yes it does not working, please look at case number&amp;nbsp;SR 685357314 from yesterday if you have access.&lt;/P&gt;
&lt;P&gt;- There is a cosmetic bug, when i put that ISE mark&amp;nbsp;&lt;SPAN&gt;AD:extensionAttribute13 with red (as it is not correct value) but allow to config be saved. In report log i see that attribute is unavailabe.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 08:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737087#M488817</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-11-01T08:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737090#M488818</link>
      <description>&lt;P&gt;HI hslai,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already read those documents , but it does not help.&lt;/P&gt;
&lt;P&gt;On ASA with version 9.4.4 i already have config "&lt;STRONG class="cCN_CmdName"&gt;vpn-addr-assign aaa"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="cCN_CmdName"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="cCN_CmdName"&gt;&lt;SPAN&gt;KR&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="cCN_CmdName"&gt;&lt;SPAN&gt;VZ&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 08:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737090#M488818</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-11-01T08:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737356#M488819</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;Does assigning IP address with&amp;nbsp;Framed-IP-Address = 10.250.200.193 work for you ?&lt;/P&gt;
&lt;P&gt;- No it does not work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I am now believing this expected. When this CoA feature added in ASA for ISE Posture enforcements on Remote Access VPN users, the policy elements CoA updates are not supported are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;VLAN assignment&lt;/LI&gt;
&lt;LI&gt;IP address assignment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Instead, please use those supported, such as dynamic ACL (dACL) and security group tag (SGT).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;Assigning IP address with Framed-IP-Address = AD:extensionAttribute13 is not working?&lt;/P&gt;
&lt;P&gt;- Yes it does not working, please look at case number&amp;nbsp;SR 685357314 from yesterday if you have access.&lt;/P&gt;
&lt;P&gt;- There is a cosmetic bug, when i put that ISE mark&amp;nbsp;&lt;SPAN&gt;AD:extensionAttribute13 with red (as it is not correct value) but allow to config be saved. In report log i see that attribute is unavailabe.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;Unable to retrieve an AD attribute and the web UI bug are separate issues but would not help with this use case.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 15:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737356#M488819</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-01T15:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737634#M488820</link>
      <description>&lt;P&gt;OK,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if&amp;nbsp;&lt;SPAN&gt;Framed-IP-Address = 10.250.200.193 is not working&amp;nbsp; and&amp;nbsp;Framed-IP-Address = AD:extensionAttribute13 is not working&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;what would be recommended solution ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to assign ip address from ASA ?&lt;/P&gt;
&lt;P&gt;Summary:&lt;/P&gt;
&lt;P&gt;i need to use certificate authentication, then to give ip address from dhcp pool , and for specific users to assign ip statically.&lt;/P&gt;
&lt;P&gt;In authorization to use posture process, dacl for network access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VZ&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 00:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737634#M488820</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-11-02T00:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737650#M488821</link>
      <description>&lt;P&gt;Please work with TAC to come up a good solution for your use case. I am no expert with ASA remote VPN and I read through your case notes and the assigned TAC has been helpful and resolved a couple of your other issues in the same case.&lt;/P&gt;
&lt;P&gt;Anyway, I think the static IP assignment could take place at the initial authentication and/or authorization (i.e. before the posture assessment).&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 01:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737650#M488821</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-02T01:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737805#M488898</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;But if&amp;nbsp;&lt;SPAN&gt;the static ip assignment&amp;nbsp;take place&amp;nbsp;at the authorization(i.e. before the posture assessment) then it is CoA, what is not supported under remote VPN, right?&amp;nbsp; becase i already have ip&amp;nbsp;assignment&amp;nbsp;with dhcp from ASA after authentication process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I will try to find out diffrent aproach for this, but anyway i have this on ACS right now in production and it works fine. Dunno why ISE cant ...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 10:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737805#M488898</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-11-02T10:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737966#M488899</link>
      <description>&lt;P&gt;AFAIK, the static IP assignment should be fine during the initial auth and before CoA. The limitation in ASA applies only as part of the CoA push to update the authorization.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2018 14:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3737966#M488899</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-02T14:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3738655#M488900</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;&lt;/STRIKE&gt;&lt;STRIKE&gt;&lt;/STRIKE&gt;Solved with&amp;nbsp;&lt;SPAN&gt;Local Exception rule in authorization before posture go in&amp;nbsp; place.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Nov 2018 10:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/3738655#M488900</guid>
      <dc:creator>startx001</dc:creator>
      <dc:date>2018-11-04T10:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Anyconnect VPN static IP assigment / DHCP -CoA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/4195090#M564218</link>
      <description>&lt;P&gt;I am experiencing the same problem.&lt;BR /&gt;Can you provide a solution how I solved it??&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 10:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-anyconnect-vpn-static-ip-assigment-dhcp-coa/m-p/4195090#M564218</guid>
      <dc:creator>JustTakeTheFirstStep</dc:creator>
      <dc:date>2020-12-08T10:58:53Z</dc:date>
    </item>
  </channel>
</rss>

