<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736503#M488988</link>
    <description>No there is not. If you have devices staying that long then install Anyconnect to get full featured support.&lt;BR /&gt;&lt;BR /&gt;The temporal agent is for temporal users like contractors that are short stay.&lt;BR /&gt;</description>
    <pubDate>Wed, 31 Oct 2018 14:26:44 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-10-31T14:26:44Z</dc:date>
    <item>
      <title>ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3734632#M488974</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working on a POC/Test ISE deployment prior to the full production rollout and I'm encountering some odd behavior with my wireless BYOD&amp;nbsp;setup.&amp;nbsp;I'm seeing the following issues on my test machine, and it seems to happen every time I test.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;BYOD&amp;nbsp;clients lose posture status every time they log off/reboot (or perhaps more accurately, when they reconnect to the corproate SSID), but posture lease is set to 14 days and there is no periodic re-assessment configured. My understanding is that the posture lease should apply to all clients, but I may be mistaken there?&lt;/LI&gt;
&lt;LI&gt;When BYOD clients are posture-assessed using the temporal agent, the first run through doesn't update the posture status in ISE - I need to be redirected a second time, run the temporal agent a second time and then I get full network access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I have a feeling it may be related to my configuration (specifically the client provisioning/posture setup), but was curious if anyone had any thoughts on those issues? I'm going to try and get some screenshots later to illustrate my client provisioning policy setup, just in case it's something there - I've got separate lines for posture and provisioning as it was the cleanest way I could think to configure it, but there's probably a better way. I'm pretty new to ISE!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 06:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3734632#M488974</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2018-10-29T06:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3734796#M488976</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;BYOD&amp;nbsp;clients lose posture status every time they log off/reboot (or perhaps more accurately, when they reconnect to the corproate SSID), but posture lease is set to 14 days and there is no periodic re-assessment configured. My understanding is that the posture lease should apply to all clients, but I may be mistaken there?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Temporal agent does not support posture lease. Please use regular AnyConnect ISE Posture for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;When BYOD clients are posture-assessed using the temporal agent, the first run through doesn't update the posture status in ISE - I need to be redirected a second time, run the temporal agent a second time and then I get full network access.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;Please ensure ISE PSN receiving a posture report. Use the ISE RADIUS Live Logs to check the authorization policy rule matched after PSN sending out the CoA and the network device re-authenticating the endpoint.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 11:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3734796#M488976</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-29T11:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3735309#M488978</link>
      <description>&lt;P&gt;Thanks for that, appreciate the quick response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Temporal agent does not support posture lease. Please use regular AnyConnect ISE Posture for this.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I guess the clients will be committed to re-running the temporal agent every time they connect then - no way to only force clients to re-assess every X days with the temporal agent?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the posture report, I'll take a more detailed look at the live logs and also do a capture on the PSN to see if I can catch any CoA being sent to the NAD.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 01:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3735309#M488978</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2018-10-30T01:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736214#M488980</link>
      <description>&lt;P&gt;Temporal Agents doesn't get installed on the clients. So temp agent cannot perform posture lease, clients need to download and run temporal agent every time to perform posture check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution is to use Anyconnect Agent.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 07:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736214#M488980</guid>
      <dc:creator>ramkchel</dc:creator>
      <dc:date>2018-10-31T07:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736257#M488987</link>
      <description>&lt;P&gt;Sounds good - they'll just have to live with a posture assessment every time they connect or get their BYOD users to install AnyConnect then.&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;thought perhaps there was a way to have ISE do something clever with the temporal agent posture report - e.g. have it run when you connect at 1000 on Oct 31 and count that as 'valid' posture for X days, then after X days market them as non-compliant/unknown, issue a CoA to force them to re-run the temporal agent and get another X days of valid posture.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 09:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736257#M488987</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2018-10-31T09:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736503#M488988</link>
      <description>No there is not. If you have devices staying that long then install Anyconnect to get full featured support.&lt;BR /&gt;&lt;BR /&gt;The temporal agent is for temporal users like contractors that are short stay.&lt;BR /&gt;</description>
      <pubDate>Wed, 31 Oct 2018 14:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736503#M488988</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-31T14:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 BYOD with Temporal Agent - Odd Behaviour</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736873#M488989</link>
      <description>Duly noted. Thanks everyone!</description>
      <pubDate>Wed, 31 Oct 2018 21:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-byod-with-temporal-agent-odd-behaviour/m-p/3736873#M488989</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2018-10-31T21:32:13Z</dc:date>
    </item>
  </channel>
</rss>

