<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Profiling and Posturing support for PAN VPN users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466730#M519221</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently that is correct.&amp;nbsp; Without a way to trigger CoA, then user may be deemed posture compliant but no way to reauthorize after initial quarantine without manual intervention by user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Dec 2017 20:22:21 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-12-11T20:22:21Z</dc:date>
    <item>
      <title>ISE Profiling and Posturing support for PAN VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466728#M519217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Experts! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a requirement where ISE needs to do Profiling and Posturing for VPN endpoints using PAN's GlobalProtect, I &lt;SPAN style="font-size: 13.3333px;"&gt;want your opinion on how to support Posturing and Profiling for VPN users connecting to the network using PAN's GlobalProtect.&lt;/SPAN&gt; I have an assumption on the following info which I got from a Cisco Engineer.&lt;/P&gt;&lt;OL class="ol1"&gt;&lt;LI&gt;&lt;SPAN class="s2"&gt;Palo Alto does not support RADIUS CoA (Change of Authorization) [RFC-3576]. As a result, most advanced ISE features (Posture, BYOD, Profiling, etc) on VPN would not be supported when integrating with PAN&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s2"&gt;PAN does support standard RADIUS attributes. As a result, we can perform basic RADIUS based authentication for RA-VPN clients&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s2"&gt;PAN does support both RADIUS and TACACS+ for device administration. Thus, ISE can be configured to provide AAA services for PAN based administrators&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 19:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466728#M519217</guid>
      <dc:creator>Vijaykumar Mittimani</dc:creator>
      <dc:date>2017-12-11T19:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiling and Posturing support for PAN VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466729#M519220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct on all 3! The only posture integrated service we have is with Cisco based vpn concentrator (ex: ASA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think you will gain much visibility with profiling as well. I have asked another SME to be sure&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 19:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466729#M519220</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-11T19:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiling and Posturing support for PAN VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466730#M519221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently that is correct.&amp;nbsp; Without a way to trigger CoA, then user may be deemed posture compliant but no way to reauthorize after initial quarantine without manual intervention by user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 20:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-and-posturing-support-for-pan-vpn-users/m-p/3466730#M519221</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-12-11T20:22:21Z</dc:date>
    </item>
  </channel>
</rss>

