<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Posture mandatory initial URL redirect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570542#M523255</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team, &lt;/P&gt;&lt;P&gt;We are working with a customer on a very large project for Posture validation checks with ISE 2.2, AnyConnect 4.4.X and Compliance Module 3.6.X and would very much appreciate your thoughts on an issue they are seeing.&lt;/P&gt;&lt;P&gt;They do not want to use ISE for the deployment of AnyConnect and want to avoid as much burden for the user as possible.&lt;/P&gt;&lt;P&gt;For the initial testing they tried doing a manual install of the client and .xml config file to the endpoint. And found that AC would not speak to ISE (although ISE server name is correct in the cfg file) until the endpoint is URL-redirected to ISE at least one first time. After that there is no need for URL redirect in the ISE policy anymore.&lt;/P&gt;&lt;P&gt;Is there a way we can avoid that first URL-Redirect? Are we maybe missing something with the manual install like an initial negotiation/id_exchange/other?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Ignacio &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Aug 2017 08:18:47 GMT</pubDate>
    <dc:creator>jbenitol</dc:creator>
    <dc:date>2017-08-02T08:18:47Z</dc:date>
    <item>
      <title>ISE Posture mandatory initial URL redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570542#M523255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team, &lt;/P&gt;&lt;P&gt;We are working with a customer on a very large project for Posture validation checks with ISE 2.2, AnyConnect 4.4.X and Compliance Module 3.6.X and would very much appreciate your thoughts on an issue they are seeing.&lt;/P&gt;&lt;P&gt;They do not want to use ISE for the deployment of AnyConnect and want to avoid as much burden for the user as possible.&lt;/P&gt;&lt;P&gt;For the initial testing they tried doing a manual install of the client and .xml config file to the endpoint. And found that AC would not speak to ISE (although ISE server name is correct in the cfg file) until the endpoint is URL-redirected to ISE at least one first time. After that there is no need for URL redirect in the ISE policy anymore.&lt;/P&gt;&lt;P&gt;Is there a way we can avoid that first URL-Redirect? Are we maybe missing something with the manual install like an initial negotiation/id_exchange/other?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Ignacio &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 08:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570542#M523255</guid>
      <dc:creator>jbenitol</dc:creator>
      <dc:date>2017-08-02T08:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture mandatory initial URL redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570543#M523256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ignacio,&lt;/P&gt;&lt;P&gt;you need to copy this file,&amp;nbsp; ConnectionData.xml into:&lt;/P&gt;&lt;P&gt; C:\Users\All Users\Cisco\Cisco AnyConnect Secure Mobility Client\ISE posture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Edit the xml&amp;nbsp; file&amp;nbsp; and instert he ISE URL:&lt;/P&gt;&lt;P&gt;t&lt;/P&gt;&lt;P&gt;ConnectionData.xml&lt;/P&gt;&lt;P&gt;&amp;lt;?xml version="1.0" ?&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;records&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;record&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;primary&amp;gt;postureportal.ise.YOUR-ISE.com&amp;lt;/primary&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;port&amp;gt;8999&amp;lt;/port&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;status_path&amp;gt;/auth/status&amp;lt;/status_path&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ng-discovery&amp;gt;/auth/ng-discovery&amp;lt;/ng-discovery&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;time&amp;gt;1495024640&amp;lt;/time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;backups&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;backup&amp;gt;SECONDARY-ISE.com&amp;lt;/backup&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/backups&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/record&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/records&amp;gt;&lt;/P&gt;&lt;P&gt;With this one, anyconnect can go straight to postureportal.&lt;/P&gt;&lt;P&gt;Remember that th URL redirect sometimes is banned from Firewalls along the way between the client with AC , the first L2 switch that intercept the URL redirect and ISE.&lt;/P&gt;&lt;P&gt;Stefano&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 13:17:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570543#M523256</guid>
      <dc:creator>stefano.marzi</dc:creator>
      <dc:date>2017-08-02T13:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture mandatory initial URL redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570544#M523257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That trick will only work if set to specific PSN or PSNs that may be RADIUS session owner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ISE 2.2 you no longer require URL redirection to trigger posture to ensure client hit the correct PSN that owns the RADIUS session.&amp;nbsp;&amp;nbsp; ISE 2.2 also adds option to deploy AC directly from a portal without redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 14:04:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570544#M523257</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-02T14:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture mandatory initial URL redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570545#M523258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding to Craig's, the AnyConnect Profile Editor for ISE Posture module, release 4.4+, has the option to define "Call Home List".&lt;/P&gt;&lt;P&gt;You might also want to take a look at &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect44/administration/guide/b_AnyConnect_Administrator_Guide_4-4/configure-posture.html#reference_288A1C28DF1549DB9CB171E085944379"&gt;AnyConnect 4.4 ISE Posture Profile Editor&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html"&gt;ISE posture style comparison for pre and post 2.2 - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-08-02 at 1.58.55 PM.png" class="image-1 jive-image" height="289" src="/legacyfs/online/fusion/109918_Screen Shot 2017-08-02 at 1.58.55 PM.png" style="height: 288.56935483870967px; width: 419px;" width="419" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 21:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-mandatory-initial-url-redirect/m-p/3570545#M523258</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-02T21:05:05Z</dc:date>
    </item>
  </channel>
</rss>

