<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.3 unable to detect Anyconnect posture agent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3677282#M495877</link>
    <description>&lt;P&gt;I will open TAC for sure, my deployment information is here:&lt;/P&gt;
&lt;P&gt;Cisco ISE 2.3&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;AnyConnectDesktopWindows 4.5.2036.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;AnyConnectComplianceModuleWindows 4.3.122.0&lt;/P&gt;
&lt;P&gt;I created 3 authorization profile in cisco ise : 1-compliant 2-non-compliant&amp;nbsp; 3- unknown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access list on switch for redirection purpose (I use this access list in unknown authorization profile)&lt;/P&gt;
&lt;P&gt;Extended IP access list ACL_REDIRECT&lt;BR /&gt; 10 deny udp any eq bootpc any eq bootps&lt;BR /&gt; 20 deny udp any any eq domain&amp;nbsp;&lt;BR /&gt; 30 deny ip any host &amp;lt;cisco ise ip address&amp;gt;&lt;BR /&gt; 40 permit tcp any any eq www&amp;nbsp;&lt;BR /&gt; 50 permit tcp any any eq 443&amp;nbsp;&lt;BR /&gt; 60 deny ip any any&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;unknown DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;permit udp any eq bootpc any eq bootps&lt;BR /&gt;permit udp any any eq 53&lt;BR /&gt;permit ip any host&amp;nbsp;&amp;lt;ise ip address&amp;gt;&lt;BR /&gt;deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Non-compliant DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;compliant DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;permit ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jul 2018 09:34:05 GMT</pubDate>
    <dc:creator>f.arabi1991</dc:creator>
    <dc:date>2018-07-30T09:34:05Z</dc:date>
    <item>
      <title>Cisco ISE 2.3 unable to detect Anyconnect posture agent</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3676765#M495875</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I deployed Cisco ISE 2.3 posture assessment,end user anyconnect is installed, everything in posture work fine but the problem is sometimes when user login ,&amp;nbsp; redirection to provisioning portal (for downloading anyconnect) occured and this massage appear : "Cisco ISE unable to detect Anyconnect posture agent" and user network access facing with problem , what can I do for solving this problem, Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2018 12:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3676765#M495875</guid>
      <dc:creator>f.arabi1991</dc:creator>
      <dc:date>2018-07-28T12:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 unable to detect Anyconnect posture agent</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3676797#M495876</link>
      <description>&lt;P&gt;As your issue happening sometimes, please open a Cisco TAC case, if not done so already. We &amp;nbsp;need to analyze the states of the network device, ISE PSN, and AnyConnect ISE posture module together when such occurs. At very least, provide TAC with the DART support bundles taken from clients experiencing it and the approximate time points.&lt;/P&gt;
&lt;P&gt;You might want to try the latest of AnyConnect 4.6 and see if it improves.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2018 16:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3676797#M495876</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-28T16:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 unable to detect Anyconnect posture agent</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3677282#M495877</link>
      <description>&lt;P&gt;I will open TAC for sure, my deployment information is here:&lt;/P&gt;
&lt;P&gt;Cisco ISE 2.3&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;AnyConnectDesktopWindows 4.5.2036.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;AnyConnectComplianceModuleWindows 4.3.122.0&lt;/P&gt;
&lt;P&gt;I created 3 authorization profile in cisco ise : 1-compliant 2-non-compliant&amp;nbsp; 3- unknown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access list on switch for redirection purpose (I use this access list in unknown authorization profile)&lt;/P&gt;
&lt;P&gt;Extended IP access list ACL_REDIRECT&lt;BR /&gt; 10 deny udp any eq bootpc any eq bootps&lt;BR /&gt; 20 deny udp any any eq domain&amp;nbsp;&lt;BR /&gt; 30 deny ip any host &amp;lt;cisco ise ip address&amp;gt;&lt;BR /&gt; 40 permit tcp any any eq www&amp;nbsp;&lt;BR /&gt; 50 permit tcp any any eq 443&amp;nbsp;&lt;BR /&gt; 60 deny ip any any&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;unknown DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;permit udp any eq bootpc any eq bootps&lt;BR /&gt;permit udp any any eq 53&lt;BR /&gt;permit ip any host&amp;nbsp;&amp;lt;ise ip address&amp;gt;&lt;BR /&gt;deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Non-compliant DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;compliant DACL:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;permit ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 09:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-unable-to-detect-anyconnect-posture-agent/m-p/3677282#M495877</guid>
      <dc:creator>f.arabi1991</dc:creator>
      <dc:date>2018-07-30T09:34:05Z</dc:date>
    </item>
  </channel>
</rss>

