<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571013#M518128</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t think so.  I never us the GUI.  I do it all from the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Feb 2018 22:45:00 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-02-02T22:45:00Z</dc:date>
    <item>
      <title>Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571009#M518121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just need to clear out some doubts about Posture:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. When the user is in Unknown --&amp;gt; ISE should use Redirect ACL + Client Provisioning Portal --&amp;gt; CORRECT??&lt;/P&gt;&lt;P&gt;2. When the user is in Non Complaint --&amp;gt; ISE should send DACL for the traffic which is allowed or it should be REDIRECT ACL + CLIENT PROVISIONING + DACL???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just need to clarify this point.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 20:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571009#M518121</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2018-02-02T20:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571010#M518124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it depends on how you want to handle it, but I have 1 rule for unknown or non-compliant that redirects to the MDM so they can become compliant. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, are these wired, or wireless clients? DACLs are only for wired, wireless you would have to call an ACL on the WLC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 21:22:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571010#M518124</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-02-02T21:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571011#M518125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically, assuming you have the ISE posture module installed via your software distribution software the Unknown state uses the redirect ACL for posture discovery only.&amp;nbsp; If you aren't planning to use the client provisioning portal (I usually don't) your redirect ACL could just redirect port 80 going to the default gateway to allow posture discovery.&amp;nbsp; Then you can also apply a DACL to limit access to the network when in Unknown, but be careful with that because posture isn't reported until the user is logged in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For non-compliant I usually just use a DACL to restrict access and no redirect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 21:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571011#M518125</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-02-02T21:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571012#M518127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure why I got MDM in my head for the question. Yes as Paul said, it depends on if you want to use the portal and such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case, since we use posture on wireless. Instead of an ACL due to WLC limits, we leave them on our limited onboarding network until compliant. Once compliant, we assign a vlan based on status.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 22:00:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571012#M518127</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-02-02T22:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571013#M518128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t think so.  I never us the GUI.  I do it all from the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 22:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571013#M518128</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-02-02T22:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571014#M518129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The windows edge popup was fixed when i allowed required traffic in the switch but IE still going for redirection and its automatically opening.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 11:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571014#M518129</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2018-02-05T11:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571015#M518130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please clarify what's expected and what's not.&lt;/P&gt;&lt;P&gt;It seems you meant different browsers giving you different results. Edge is not redirecting while IE is?? Please check what web site IE is going and triggering the redirect. You might want to take a look at &lt;A href="https://en.wikibooks.org/wiki/Windows_Troubleshooter_Guide/Network_Location_Awareness" title="https://en.wikibooks.org/wiki/Windows_Troubleshooter_Guide/Network_Location_Awareness"&gt;https://en.wikibooks.org/wiki/Windows_Troubleshooter_Guide/Network_Location_Awareness&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 12:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture/m-p/3571015#M518130</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-05T12:11:24Z</dc:date>
    </item>
  </channel>
</rss>

