<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect NAM + RSA + Posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593725#M517789</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Sampath,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of Anyconnect are you using and RSA version as well.&lt;/P&gt;&lt;P&gt;I have reached out SME for Anyconnect, Paul Carco to answer this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Feb 2018 19:41:47 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2018-02-16T19:41:47Z</dc:date>
    <item>
      <title>AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593724#M517788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;One of my customer is using NAM + RSA(EAP Chaining) + Posture. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;We tested and it was working like the following earlier:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;1) User connects machine to the network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;2) User enters username and passcode(RSA) in NAM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;3) Posture starts and at 96%, CoA happens and once done, it prompts for passcode again and do the posture again, completes and compliant. I guess it's doing full auth and not silent re-auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I believe this is the known behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;But recently, the behavior changed and the second time where it asks for passcode after CoA, now it asks for both username and passcode, then it does posture and compliant.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Any idea what might be triggering it to ask for the username again?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 18:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593724#M517788</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-16T18:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593725#M517789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Sampath,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of Anyconnect are you using and RSA version as well.&lt;/P&gt;&lt;P&gt;I have reached out SME for Anyconnect, Paul Carco to answer this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 19:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593725#M517789</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2018-02-16T19:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593726#M517790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Krishnan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AnyConnect Version is 4.4.04030. Reached out to the customer to find out about the RSA Version. Will let you know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 19:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593726#M517790</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-16T19:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593727#M517791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Hey Krishnan, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;RSA version is 7.3.3.103&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Sampath&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 20:33:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593727#M517791</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-16T20:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593728#M517793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anything in particular (NAM profile or versions of AnyConnect or RSA or ISE or NAD) changed recently? I would suggest to engage Cisco TAC and submit a copy of the DART file to TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Feb 2018 02:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593728#M517793</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-18T02:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593729#M517796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hsing, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing changed recently. I will engage TAC as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With respect to the endpoint behavior, the above mentioned steps(Step 1 to Step 3) sounds right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sampath&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 15:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593729#M517796</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-19T15:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593730#M517797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The steps look fine. You are correct it expected because of OTP. ISE 2.3 has a passcode caching option that you might want to try.&lt;IMG alt="Screen Shot 2018-02-19 at 9.05.05 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/115362_Screen Shot 2018-02-19 at 9.05.05 AM.png" style="height: 342px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 17:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593730#M517797</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-19T17:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593731#M517798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hsing, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is available in ISE 2.2. I already tried this and no help out of it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand it asks for passcode the second time because of OTP, but why ask for the the username again? It was not the case earlier when tested and it use to prompt only for the passcode the second time. Could it be NAM not caching the username?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sampath&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Feb 2018 17:11:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593731#M517798</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-19T17:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM + RSA + Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593732#M517799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 16:19:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-rsa-posture/m-p/3593732#M517799</guid>
      <dc:creator>sampathss</dc:creator>
      <dc:date>2018-02-28T16:19:10Z</dc:date>
    </item>
  </channel>
</rss>

