<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remediation Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429027#M509947</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry to say but this one is different as the other one is about making sure that firewall is turned on for all three profiles, where as this one is more about the two remediation not working at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned earlier I can achieve the below without any issues:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) For domain profile I can enable the windows firewall using remediation (if "windows firewall" service is up and running)&lt;/P&gt;&lt;P&gt;2) I can start&amp;nbsp; the "windows firewall" service&amp;nbsp; using remediation( if all three profile are configured with firewall enabled option).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HOWEVER I cannot get both working at same time i.e.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If firewall is disabled for domain profile and windows firewall service is not running, the remediation does not start and at remediation timer expiry I am categorized as NON-COMPIANT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something we can do about this. I mean some timer or some retries or some delay for the profile firewall remediation to kick in after the services are enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some guidance there, if someone have seen it working in lab/ customer environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 May 2018 02:04:38 GMT</pubDate>
    <dc:creator>rajatsha</dc:creator>
    <dc:date>2018-05-16T02:04:38Z</dc:date>
    <item>
      <title>Remediation Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429025#M509945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to check for two things during posture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) If the Widows firewall service is running or not. (created the condition and launch program remediation&amp;nbsp; and it works fine)&lt;/P&gt;&lt;P&gt;2) To make sure that the Windows firewall is turned ON. (It is currently working for Domain and not&amp;nbsp; for other two profile, but I have raised a separate thread for that)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CURRENT ISSUE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When windows FW is turned off for Domain and I disable the service and then unplug and replug the laptop,&amp;nbsp; the posture fails as both of these are not getting triggered at the same time. If I enable the domain firewall and then disable the widows firewall service it come back fine. Similarly if I just switch off the firewall for domain it comes back fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but somehow both are not coming back at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest what I am missing or how can we get this working with ISE posture in stealth mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;REgards,&lt;/P&gt;&lt;P&gt;Rajat Sharma&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 06:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429025#M509945</guid>
      <dc:creator>rajatsha</dc:creator>
      <dc:date>2018-05-15T06:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remediation Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429026#M509946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This question appears to be a duplicate from your previous post here: &lt;A href="https://community.cisco.com/thread/91807"&gt;Firewall is not getting turned on for Private (standard) and Public profiles&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 12:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429026#M509946</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-15T12:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remediation Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429027#M509947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry to say but this one is different as the other one is about making sure that firewall is turned on for all three profiles, where as this one is more about the two remediation not working at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned earlier I can achieve the below without any issues:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) For domain profile I can enable the windows firewall using remediation (if "windows firewall" service is up and running)&lt;/P&gt;&lt;P&gt;2) I can start&amp;nbsp; the "windows firewall" service&amp;nbsp; using remediation( if all three profile are configured with firewall enabled option).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HOWEVER I cannot get both working at same time i.e.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) If firewall is disabled for domain profile and windows firewall service is not running, the remediation does not start and at remediation timer expiry I am categorized as NON-COMPIANT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something we can do about this. I mean some timer or some retries or some delay for the profile firewall remediation to kick in after the services are enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some guidance there, if someone have seen it working in lab/ customer environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 02:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/remediation-issue/m-p/3429027#M509947</guid>
      <dc:creator>rajatsha</dc:creator>
      <dc:date>2018-05-16T02:04:38Z</dc:date>
    </item>
  </channel>
</rss>

