<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect and no policy server detected in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729887#M495211</link>
    <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Yes, I do agree with you! But, the client here is not ready for that approach, there is need to for the cases where, users do not have it installed or if the user is working from remote location where they are not able to contact any of our admins.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;So, that is why we are trying to get this working on HP switch as well, as there are few of the sites where we have like hundreds of HP switches.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 14:52:55 GMT</pubDate>
    <dc:creator>dgaikwad</dc:creator>
    <dc:date>2018-10-22T14:52:55Z</dc:date>
    <item>
      <title>AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725529#M495186</link>
      <description>&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;Hi Experts,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;Test environment:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;ISE 2.3 patch 3&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;HP Comware switch:&amp;nbsp;Version 7.1.070, Release 3208P03&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;I am seeing this very weird behavior with AnyConnect.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;We are using an ACL for posture redirection, so here when I have these two statements:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;rule 135 deny tcp destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt; rule 140 deny tcp destination-port eq www&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;AnyConnect says that, its failed to launch downloader&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;But when I change them to:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;&lt;SPAN&gt;rule 135 permit tcp destination-port eq 443&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;&lt;SPAN&gt;rule 140 permit tcp destination-port eq www&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;&lt;SPAN&gt;AnyConnect says, no policy server detected&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;&lt;SPAN&gt;Any idea why this could be happening?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;Following is the complete ACL:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;[NAC-5130-2]display acl 3003&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Advanced IPv4 ACL 3003, 29 rules,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ACL's step is 5, start ID is 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 0 permit ip destination &amp;lt;ISE Server&amp;gt; 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 5 permit udp destination-port eq dns&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 10 permit udp source-port eq bootpc destination-port eq bootps&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 15 permit udp source-port eq bootps destination-port eq bootpc&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 20 permit tcp destination-port eq 2967&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 25 permit tcp source-port eq 2967&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 30 permit tcp destination-port eq 7070&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 35 permit tcp source-port eq 7070&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 40 permit ip destination &amp;lt;AV Server&amp;gt; 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 45 permit tcp destination &amp;lt;AV Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 50 permit tcp destination &amp;lt;AV Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 55 permit tcp destination &amp;lt;AV Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 60 permit tcp destination &amp;lt;AV Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 65 permit tcp destination &amp;lt;AV Server&amp;gt; destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 70 permit tcp destination &amp;lt;AV Server&amp;gt; destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 75 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 80 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 85 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 90 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 95 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 100 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 105 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 110 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 115 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 120 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 125 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 130 permit tcp destination &amp;lt;SCCM Server&amp;gt; 0 destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 135 deny tcp destination-port eq www&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 140 deny tcp destination-port eq 443&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 12:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725529#M495186</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-15T12:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725596#M495190</link>
      <description>&lt;P&gt;I suggest using AnyConnect DART for more details. But, looks like denying 80 &amp;amp; 443 is the right config based on your result. You may be getting failed to launch downloader error if you are not getting redirected to the client provisioning portal so make sure when the deny is hit the endpoint can get to the portal. You can test this by opening up a web browser to confirm that browser is getting redirected to the client provisioning portal. Another cause may be that you don't have the client provisioning policy with AnyConnect defined for the client OS.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 14:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725596#M495190</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-15T14:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725622#M495193</link>
      <description>&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;There is a client provisioning policy defined for all version of this OS this machine is running.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;I see that this client is reported as&amp;nbsp;Microsoft-Workstation, so that is normal, right? If I wanted to check what OS this client is running, where I can I check that?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="book antiqua,palatino" size="2"&gt;Also, I will run the DART and see what I get from it output.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 14:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725622#M495193</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-15T14:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725624#M495195</link>
      <description>&lt;P&gt;Do you get redirected with the browser? I would confirm redirect to the client provisioning portal first before any further troubleshooting. This can happen in two ways if you are leveraging HP switch capability. Either you can send down URL-Redirect string via RADIUS (Most of Cisco devices supports this) or you have to statically define the URL string on the HP switch web auth portal settings (Most of 3rd party devices falls in to this category).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:01:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725624#M495195</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-15T15:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725848#M495197</link>
      <description>&lt;P&gt;Your ACL is way to big unless you are planning to actually use the client provisioning portal to install the AnyConnect software (I wouldn't recommend it).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only thing you need to redirect is port 80 to enroll.cisco.com (72.163.1.80) or port 80 to the default gateway.&amp;nbsp; On Cisco devices I use the 10.0.0.1 0.255.255.0 masking to get the default gateway, but enroll.cisco.com works.&amp;nbsp; As Howan suggested you can validate redirection is working by pulling up a web browser and going to &lt;A href="http://enroll.cisco.com" target="_blank"&gt;http://enroll.cisco.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 21:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3725848#M495197</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-15T21:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726086#M495199</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I have observed this behavior, when I type in any of the website or even IP address like 1.1.1.1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;There is nothing on the browser, the browser will just sit there...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;But, if enter the IP address or the URL to ISE server, I am presented with the redirection page!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Is this something with the switch? Is the switch not able to intercept any of the DNS requests that I am sending from the browser?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;The reason ACL is so big, is because that is the we will be using in the production when we go live.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;We are not planning on using the redirection for client provisioning, but would like to keep this function in those cases if an endpoint does not have a client or posture module, then should be able to download and connect to the corporate network.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 07:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726086#M495199</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-16T07:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726276#M495201</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you share Authorization Profile what you have configured ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also could you please try putting FQDN in the TAB which is below to Web Redirection.&lt;/P&gt;
&lt;P&gt;One more thing you can try, copy complete URL which you will find at "Attribut Details" and put into your browser and check whether its redirecting or not, Please share the output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sajid&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 11:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726276#M495201</guid>
      <dc:creator>sajid231088</dc:creator>
      <dc:date>2018-10-16T11:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726282#M495202</link>
      <description>You are going to have a host of problems if you try to use that ACL in production:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;-Windows 10 and other OSs try to do portal detection when connecting . They may pop-up the client provisioning page before the client postures causing all sorts of confusion for the end user.  Users will start clicking and trying to reinstall Any Connect or call the help desk asking what the client provisioning page is.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;-Outlook will try to connect as soon as they connect and the user will get a cert warning in Outlook because of the redirection.  All sort of fun will happen with that one.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As I have stated before on the forums the redirect ACL should only be used for posture module discovery and the only thing you need to redirect is port 80 enroll.cisco.com and/or port 80 to the default gateway.  If you want to restrict traffic pre-posture you can use a DACL (not sure if the HP switches support that).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Oct 2018 12:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726282#M495202</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-16T12:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726371#M495203</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I did some more testing with the user and his test endpoint and here are the observations:&lt;/FONT&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="text-align: left;"&gt;&lt;FONT face="helvetica" size="2"&gt;When the user connects, the ACL and redirection URL are pushed to switch from ISE&lt;/FONT&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="URL redirect.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20503i0FC8768BABC8BCB3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="URL redirect.jpg" alt="URL redirect.jpg" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI style="text-align: left;"&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;&amp;nbsp;Now user opens a browser and enters times.com. nothing happens, enters, 1.1.1.1 nothing happens&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="text-align: left;"&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;So, I manually copy and paste the above URL in the browser nothing happens&lt;/FONT&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI style="text-align: left;"&gt;&lt;FONT face="helvetica" size="2"&gt;I replace the DNS name of the ISE server with IP address, voila! I am presented with the redirection page!&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Now the question is that, is the switch not able to intercept the requests that are being sent from the browser to the outer world?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 14:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726371#M495203</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-16T14:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726375#M495204</link>
      <description>Sounds like possibly you have a DNS issue not able to resolve the ISE PSN information. Can you resolve the ISE node from the client network?&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Oct 2018 14:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726375#M495204</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-16T14:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726809#M495205</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I am not sure if that is an issue over that site, since from my site I am able to resolve to that ISE address.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I will test it from his site, using another computer that is not connected to a dot1x port.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 07:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726809#M495205</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-17T07:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726816#M495206</link>
      <description>&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I have attached the authorization profile here.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I have not tested putting in the ISE FQDN in the tab, will test that and see if can get through.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;When I copy and paste the URL in browser, I get a error 500 page.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 07:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3726816#M495206</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-17T07:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729610#M495207</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;It seems that it was not a DNS issue after-all, and something different. Here are some of my observations regarding the issue:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;White testing I observed something really peculiar, ISE we define the attribute to carry the redirection URL in the network device profile, here:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="URL redirect 003.JPG" style="width: 449px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/20845i93A6BF12D95AC2BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="URL redirect 003.JPG" alt="URL redirect 003.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;When I use attribute, H3C-Web-URL, I see that the URL does get pushed to the switch in the authorization URL part, but then endpoints is just not able to communicate with DNS at all.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;But, if I enter the URL directly in the browser, its take me to login page from Cisco without any issues. The other side effect of this is the posture scan stops, working as AnyConnect client is unable to find ISE server.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;But, I remove the attribute H3C-Web-URL and use, HPE-Captive-Portal-URL instead, there is no URL pushed for redirection. But, posture works just fine.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I am not sure about this behavior, if its from ISE, the NAD profile or if the switch stops processing any DNS requests when it sees the URL pushed.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 07:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729610#M495207</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-22T07:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729623#M495208</link>
      <description>Hi, &lt;BR /&gt;&lt;BR /&gt;Please try to change Anyconnect angent/ compliance module. &lt;BR /&gt;&lt;BR /&gt;Hope it would work. &lt;BR /&gt;&lt;BR /&gt;Regards &lt;BR /&gt;Sajid Baig</description>
      <pubDate>Mon, 22 Oct 2018 07:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729623#M495208</guid>
      <dc:creator>sajid231088</dc:creator>
      <dc:date>2018-10-22T07:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729814#M495209</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;While testing, we tweaked the posture redirect ACL:&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 0 permit udp destination-port eq bootps&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 5 permit udp destination-port eq bootpc&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 10 permit udp destination-port eq dns&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt; rule 15 permit ip destination 10.24.213.108 0&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Post this change I was able to get to the redirection page fine.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;But, then I hit another, the user goes through the detecting AnyConnect and then get to a page where it asks, to download the AnyConnect posture module.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Clicking the download, like I just get a blank page instead of downloading the agent.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I am starting a new thread to work on it.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 13:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729814#M495209</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-22T13:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729837#M495210</link>
      <description>You really don't want users installing AnyConnect from the client provisioning portal.  It is fine during testing, but you should be pushing it out with SCCM or some other software distribution tool.  If you allow the provisioning portal to come up, users that already have AnyConnect and Posture Module installed may try to install it again. The OS portal detection may automatically kick up the client provisioning portal.  You should only try to redirect the calls necessary for posture discovery.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 22 Oct 2018 14:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729837#M495210</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-22T14:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729887#M495211</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Yes, I do agree with you! But, the client here is not ready for that approach, there is need to for the cases where, users do not have it installed or if the user is working from remote location where they are not able to contact any of our admins.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;So, that is why we are trying to get this working on HP switch as well, as there are few of the sites where we have like hundreds of HP switches.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 14:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729887#M495211</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-22T14:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729895#M495212</link>
      <description>Understood, just so long as the customer understands the issues they will see with this approach.  In addition to the OS portal detection issue, they will probably also see Outlook certificate warning issues.  As soon as the device is connected to the network Outlook tries to connect to the servers over HTTPs.  If that is being redirected to the client provisioning page then Outlook will throw a certificate warning.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 22 Oct 2018 15:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3729895#M495212</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-22T15:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3730572#M495213</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Thanks for the response.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;Yes, the customer is aware of the implications and issues pertaining this use case.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;There is this another issue I am seeing, I have opened a new thread for the same, where when the user clicks on download link for AnyConnect, a blank page is presented.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I checked for the page source and saw that there is nothing in the URL which sends for downloading AnyConnect client, as below:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Download URL code.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/21022i747D34CDE6E98B87/image-size/large?v=v2&amp;amp;px=999" role="button" title="Download URL code.jpg" alt="Download URL code.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 09:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3730572#M495213</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2018-10-23T09:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect and no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3732953#M495214</link>
      <description>&lt;P&gt;Can you post your current posture redirect ACL that is configured on the switch in its entirety?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 17:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-and-no-policy-server-detected/m-p/3732953#M495214</guid>
      <dc:creator>jordanburnett</dc:creator>
      <dc:date>2018-10-25T17:37:16Z</dc:date>
    </item>
  </channel>
</rss>

