<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE v2.1 Wired Posture check runs slow in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546740#M524848</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi we have Cisco ISE v2.1 patch 3 running for wired 802.1x with Posture checking. The end devices are Windows 10 desktop/laptop's running AnyConnect v4.4.248.&amp;nbsp; Posture works fine but it takes approx 30 seconds, which is a long time for a user to wait, if we enable SCCM check for Installtion or service runing its the same delay but if we ask for SCCM to check that patches are up to date this takes 1/5 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Authentication policy is EAP-TLS to a CAP profile, works fine&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;Authorisation rules:-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Unknown Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQALS uknown then Posture&lt;/LI&gt;&lt;LI&gt;Compliant Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQALS Compliant then Permit-All&lt;/LI&gt;&lt;LI&gt;Non Compliant Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQUALS NonCompliant then Posture_remediation&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;Authorisation rules:-&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authorisation Result Posture_remediation allows access (dACL) to backend remediation servers&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Authorisation &lt;/SPAN&gt; Result Posture =&amp;nbsp;&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;Access Type = Access_Accept&lt;/LI&gt;&lt;LI&gt;Common tasks &lt;SPAN style="font-size: 10pt;"&gt;dACL = Remediation_ACL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Web Redirection (CWA, MDM, NSP, CPP) - Client Provisioning (Posture) ACL=ACL_Redirect&amp;nbsp;&amp;nbsp;&amp;nbsp; Value = Client Provisioning Portal (default)&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;(cisco-av-pair = url-redirect-acl=ACL_Redirect&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;cisco-av-pair = url-redirect=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ip:port/portal/gateway/sessionid" rel="nofollow" target="_blank"&gt;https://ip:port/portal/gateway/sessionid&lt;/A&gt;&lt;SPAN&gt; xxxxxx)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Khalid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 May 2017 16:03:38 GMT</pubDate>
    <dc:creator>khalid_mahmood</dc:creator>
    <dc:date>2017-05-15T16:03:38Z</dc:date>
    <item>
      <title>Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546740#M524848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi we have Cisco ISE v2.1 patch 3 running for wired 802.1x with Posture checking. The end devices are Windows 10 desktop/laptop's running AnyConnect v4.4.248.&amp;nbsp; Posture works fine but it takes approx 30 seconds, which is a long time for a user to wait, if we enable SCCM check for Installtion or service runing its the same delay but if we ask for SCCM to check that patches are up to date this takes 1/5 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Authentication policy is EAP-TLS to a CAP profile, works fine&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;Authorisation rules:-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Unknown Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQALS uknown then Posture&lt;/LI&gt;&lt;LI&gt;Compliant Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQALS Compliant then Permit-All&lt;/LI&gt;&lt;LI&gt;Non Compliant Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if wired802.1x and certificate issuer common name=Company, AND Session:Posturestatus EQUALS NonCompliant then Posture_remediation&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;Authorisation rules:-&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authorisation Result Posture_remediation allows access (dACL) to backend remediation servers&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Authorisation &lt;/SPAN&gt; Result Posture =&amp;nbsp;&amp;nbsp; &lt;/LI&gt;&lt;LI&gt;Access Type = Access_Accept&lt;/LI&gt;&lt;LI&gt;Common tasks &lt;SPAN style="font-size: 10pt;"&gt;dACL = Remediation_ACL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Web Redirection (CWA, MDM, NSP, CPP) - Client Provisioning (Posture) ACL=ACL_Redirect&amp;nbsp;&amp;nbsp;&amp;nbsp; Value = Client Provisioning Portal (default)&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;(cisco-av-pair = url-redirect-acl=ACL_Redirect&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;cisco-av-pair = url-redirect=&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ip:port/portal/gateway/sessionid" rel="nofollow" target="_blank"&gt;https://ip:port/portal/gateway/sessionid&lt;/A&gt;&lt;SPAN&gt; xxxxxx)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Khalid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 May 2017 16:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546740#M524848</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-05-15T16:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546741#M524849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to engage TAC and submit the DART for investigation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 May 2017 16:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546741#M524849</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-28T16:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546742#M524850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for response Hslai,&amp;nbsp; DART or wireshark export is not possible with secure accounts such as this.&amp;nbsp;&amp;nbsp; Noticed that if I change the patch management for SCC, from up to date to enabled the process is a lot faster, not sure why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've setup a new environment and ise posture discovery completely fails now.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Big question is I have a unknown Posture Authorisation = Posture_Remedation which permits access to DNS, DHCP, HTTP, Intranet &amp;amp; general remediation services. The Redirect ACL denies any traffic which does not need to be redirected, i.e. DNS, DHCP, ISE PSN nodes but permits http &amp;amp; https:-&lt;/P&gt;&lt;P&gt;deny udp any eq bootpc any eq bootps&lt;/P&gt;&lt;P&gt;deny up any any domain&lt;/P&gt;&lt;P&gt;deny ip any host ISE PSN&lt;/P&gt;&lt;P&gt;permit tcp any any eq www&lt;/P&gt;&lt;P&gt;permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This redirect ACL is also configured on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the AnyConnect client v4.4 does not discover the ISE server during the posture discovery.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch config is configured for ip http server &amp;amp; ip http secure-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something fundamental??&amp;nbsp; Is their a good article that explains ISE Posture discovery process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx Khalid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 19:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546742#M524850</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-05-29T19:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546743#M524851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See if this link is useful : &lt;A _fcksavedurl="http://communities.labminutes.com/security/ise-posture-using-predeploy-method-and-posture-discovery/" href="http://communities.labminutes.com/security/ise-posture-using-predeploy-method-and-posture-discovery/"&gt;communities.labminutes.com/security/ise-posture-using-predeploy-method-and-posture-discovery/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also check this post, i think it might solve your problem:- &lt;A _fcksavedurl="https://cisco.jiveon.com/message/357182?commentID=357182#comment-357182" href="https://cisco.jiveon.com/message/357182?commentID=357182#comment-357182"&gt;cisco.jiveon.com/message/357182&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 11:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546743#M524851</guid>
      <dc:creator>Farhan Mohamed</dc:creator>
      <dc:date>2017-06-02T11:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546744#M524852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Farhan, the second link is a cisco internal employee only - could you please post here. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 07:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546744#M524852</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-06-06T07:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.1 Wired Posture check runs slow</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546745#M524853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-tech-notes-list.html" style="font-size: 10pt;"&gt;ISE Troubleshooting TechNotes&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; has a couple of articles on posture might help. Without sharing any debug, we can't really help you here. You should probably engage our Cisco TAC for further assistance.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Jul 2017 00:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-1-wired-posture-check-runs-slow/m-p/3546745#M524853</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-09T00:37:00Z</dc:date>
    </item>
  </channel>
</rss>

