<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple PSN posture sequence in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559654#M509067</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This needs the DART files during the failures submitted to Cisco TAC and investigate further. It should not need either deleting the connectiondata.xml file or re-installing AnyConnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2018 01:46:30 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-06-14T01:46:30Z</dc:date>
    <item>
      <title>Multiple PSN posture sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559652#M509065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IHAC with 3 PSNs with NO LB in front. All 3 PSNs are load balanced based on aaa-server in switch and 3 group of switches with different priority order.&lt;/P&gt;&lt;P&gt;One of the PSN(PSN1) failed and upon RMA, some of the endpoints experienced posture failure. Based on the initial finding, switch has the following priority configured -&amp;gt; (PSN1, PSN2, PSN3).&lt;/P&gt;&lt;P&gt;During failure of PSN1, all endpoints move to PSN2 for posture assessment and upon recovering PSN1 some of the endpoints could not contact to any PSN.&lt;/P&gt;&lt;P&gt;Failed endpoint has AnyConnect connectiondata.xml with the sequence of (PSN2, PSN3, PSN1). Endpoint without issue has connectiondata.xml with the sequence of (PSN1, PSN2, PSN3).&lt;/P&gt;&lt;P&gt;Tried deleting connectiondata.xml and the sequence reflect correct sequence but endpoint still fail posture. Reinstalling AnyConnect solves the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is being cached in AnyConnect that we could revert the sequence after recovering PSN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Wing Churn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 06:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559652#M509065</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2018-06-13T06:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple PSN posture sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559653#M509066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Connectiondata.xml has last PSN information and is created dynamically on the client.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; you can make use of call home list feature in anyconnect profile. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;more details can be found here - &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html#anc6" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html#anc6"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 09:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559653#M509066</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-06-13T09:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple PSN posture sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559654#M509067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This needs the DART files during the failures submitted to Cisco TAC and investigate further. It should not need either deleting the connectiondata.xml file or re-installing AnyConnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 01:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-psn-posture-sequence/m-p/3559654#M509067</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-14T01:46:30Z</dc:date>
    </item>
  </channel>
</rss>

