<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect Posture Module between Client and Stealth Mode in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3699274#M508380</link>
    <description>&lt;P&gt;I found it best to also define the ISE Posture profile in ASA; e.g.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;# show running-config webvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;webvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; enable outside&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-win-4.6.01103-webdeploy-k9.pkg 1 regex "Windows NT"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-linux64-4.6.01103-webdeploy-k9.pkg 2 regex "Linux"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-macos-4.6.01103-webdeploy-k9.pkg 3 regex "Intel Mac OS X"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect profiles ISEPosture1 disk0:/ISEPostureCFG.xml&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect profiles ise-vpn-lab disk0:/ise-vpn-lab.xml&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect enable&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; cache&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; disable&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; error-recovery disable&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Sep 2018 02:06:38 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-09-02T02:06:38Z</dc:date>
    <item>
      <title>AnyConnect Posture Module between Client and Stealth Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687402#M508371</link>
      <description>&lt;P&gt;Customer is running AnyConnect and Posture Module on Windows endpoints. When connected to VPN, customer would like the posture module to show up and show status. When connected to LAN and WLAN, customer would like Stealth Mode. We got this to work by configuring different Client Provisioning Policies under Posture for each connection. So when an end user connects and authenticates via VPN on the ASA, the Posture Module runs and is visible, but when connecting to LAN or WLAN, the Posture Module disappears and runs in Stealth Mode. One issue when bouncing back between LAN/WLAN and VPN is that it take 30 seconds or so for the Posture Module to appear and scan the device after VPN connection and Authentication. Is there a way to have the module run quicker?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 18:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687402#M508371</guid>
      <dc:creator>edmcnich</dc:creator>
      <dc:date>2018-08-13T18:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect Posture Module between Client and Stealth Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687494#M508372</link>
      <description>You need the Posture Module to send it’s Discovery requests more quickly, but I’m not sure there is an easy way to do this, though I have similar frustrations so it’d be good if someone knew a way!</description>
      <pubDate>Mon, 13 Aug 2018 20:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687494#M508372</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-08-13T20:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect Posture Module between Client and Stealth Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687556#M508375</link>
      <description>&lt;P&gt;What trick are you using for posture discovery when on VPN?&amp;nbsp; Are you redirecting one of the know calls like enroll.cisco.com?&amp;nbsp; Or using a posture discovery host?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 22:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3687556#M508375</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-13T22:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect Posture Module between Client and Stealth Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3689260#M508378</link>
      <description>&lt;P&gt;Basically in the client provisioning policy we created a condition for Windows devices that if authentication from VPN_Group (which is the ASAs doing RAVPN), Results will be posture module. For all other NAS devices (WLC, Switches), results will be AnyConnect Stealth. Only issue is that when we switch from wireless to VPN, it takes about 30-40 seconds for the posture module to enable.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 20:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3689260#M508378</guid>
      <dc:creator>edmcnich</dc:creator>
      <dc:date>2018-08-15T20:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect Posture Module between Client and Stealth Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3699274#M508380</link>
      <description>&lt;P&gt;I found it best to also define the ISE Posture profile in ASA; e.g.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="3"&gt;# show running-config webvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt;webvpn&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; enable outside&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-win-4.6.01103-webdeploy-k9.pkg 1 regex "Windows NT"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-linux64-4.6.01103-webdeploy-k9.pkg 2 regex "Linux"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect image disk0:/anyconnect-macos-4.6.01103-webdeploy-k9.pkg 3 regex "Intel Mac OS X"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect profiles ISEPosture1 disk0:/ISEPostureCFG.xml&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect profiles ise-vpn-lab disk0:/ise-vpn-lab.xml&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; anyconnect enable&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; cache&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; disable&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="3"&gt; error-recovery disable&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Sep 2018 02:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-module-between-client-and-stealth-mode/m-p/3699274#M508380</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-02T02:06:38Z</dc:date>
    </item>
  </channel>
</rss>

