<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Policy Server Detected in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583998#M517136</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you mentioned this issue happening randomly, please engage Cisco TAC to troubleshoot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 May 2018 08:24:41 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-05-05T08:24:41Z</dc:date>
    <item>
      <title>No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583996#M517134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running with ISE 2.1 with patch 5 and Any Connect 4.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are facing some issue on the random endpoints with &lt;STRONG&gt;&lt;EM&gt;No Policy Server Detected&lt;/EM&gt;&lt;/STRONG&gt; message in Any Connect and on &lt;STRONG&gt;ISE Live logs&lt;/STRONG&gt; its showing &lt;STRONG&gt;&lt;EM&gt;Posture Unknown&lt;/EM&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Endpoint are able to Ping ISE Server as well host name, also able to resolve &lt;STRONG&gt;enroll.cisco.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Dot1x is is successfully happening for endpoint, redirection is also working, posture status is showing &lt;STRONG&gt;&lt;EM&gt;Pending&lt;/EM&gt;&lt;/STRONG&gt; under&lt;STRONG&gt; Live Session&lt;/STRONG&gt; on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does any thing i nee to look why Posture is not working ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Appreciate your Inputs here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2018 07:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583996#M517134</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-05-04T07:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583997#M517135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With ISE 2.1, you must rely on URL redirect for client to discover PSN, and it needs to be the PSN that authenticated client.&amp;nbsp; One exception is the attempt to connect to previous PSN, but let's stick to new connection case.&amp;nbsp;&amp;nbsp; Therefore, you Discovery Host or resolution of enroll.cisco.com must resolve to a target &lt;EM&gt;beyond &lt;/EM&gt;the redirection point and be a routeable target.&amp;nbsp; If DH or enroll.cisco.com resolved to PSN, it will not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 May 2018 01:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583997#M517135</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-05T01:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583998#M517136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you mentioned this issue happening randomly, please engage Cisco TAC to troubleshoot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 May 2018 08:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583998#M517136</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-05T08:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583999#M517137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt;&lt;A href="https://community.cisco.com//u1/28477"&gt;chyps&lt;/A&gt;&amp;nbsp; Thanks for the Input&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken TAC Support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More about the issue is, when user logged on one PC posture scan is working and getting C&lt;STRONG&gt;omplaint status&lt;/STRONG&gt;, when the same user is logging on different PC AnyConnect after scan showing &lt;STRONG&gt;No Policy Server Detected.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;After packet capture, we found that AnyConnect reaches the ISE and ISE was redirecting the AnyConnect to port 8905. When AnyConnect goes to that port ISE was sending &lt;STRONG&gt;Reset&lt;/STRONG&gt;, on ISE we confirmed the port was Open. This is something weird why ISE was giving Reset.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC Engineer gone through support bundle and found some bugs along with high load average and suggested either Reload the Server or Upgrade to Patch 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Temporary workaround we reloaded the box and after reload the issue got resolved of NO Policy Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything we need to look to resolve the Reset instead of going for Patch 7.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 May 2018 10:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3583999#M517137</guid>
      <dc:creator>Ali</dc:creator>
      <dc:date>2018-05-06T10:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3584000#M517138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please take the tac advice as they are tasked with troubleshooting and resolving break fix issues&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 May 2018 11:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3584000#M517138</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-06T11:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: No Policy Server Detected</title>
      <link>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3584001#M517139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suspect it is a case where posture request sent to PSN that was no longer owner.&amp;nbsp; If a specific defect flagged as being the fix, as we have added some logic to address such out of sync cases, then that would be the path to prevent future occurrences, else rely on ISE 2.2+ feature to provide Phase 2 discovery.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 May 2018 21:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-policy-server-detected/m-p/3584001#M517139</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-06T21:06:14Z</dc:date>
    </item>
  </channel>
</rss>

