<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Posture before logon in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479744#M527015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Anshul. I believe what you are looking for is Stealth mode (Clientless) AnyConnect with ISE which was introduced with ISE 2.2 &amp;amp; AnyConnect 4.4. You can find more about this feature here: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010111.html?bookSearch=true#id_38262" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010111.html?bookSearch=true#id_38262"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.2 - Configure Client Posture Policies [Cisco Identity Ser…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Sep 2017 05:42:27 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2017-09-05T05:42:27Z</dc:date>
    <item>
      <title>Posture before logon</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479743#M527014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;Hi Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;Is there anything on the ISE\Anyconnect posture roadmap to allow for posture before logon&amp;nbsp; ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;The customers use case is to fully block machines from joining their network if they don’t have AV or up to date windows patches to stop the spread of viruses.&amp;nbsp; This isn’t possible at the present because the Anyconnect GUI only starts after the user logs on so drive mapping fails. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;This is not a BYOD or guest scenario but more about corporate machines where if they are taken off site to other premises and get infected with malware that disables the AV they shouldn’t be allowed back onto the corporate network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 11pt; font-family: Calibri,sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px;"&gt;&lt;SPAN style="color: #1f497d;"&gt;Anshul&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Sep 2017 15:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479743#M527014</guid>
      <dc:creator>ankaushi</dc:creator>
      <dc:date>2017-09-04T15:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Posture before logon</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479744#M527015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Anshul. I believe what you are looking for is Stealth mode (Clientless) AnyConnect with ISE which was introduced with ISE 2.2 &amp;amp; AnyConnect 4.4. You can find more about this feature here: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010111.html?bookSearch=true#id_38262" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010111.html?bookSearch=true#id_38262"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.2 - Configure Client Posture Policies [Cisco Identity Ser…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 05:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479744#M527015</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-09-05T05:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Posture before logon</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479745#M527016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don’t discuss roadmap in the public forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you’re asking for is likely not possible because all of the services AV etc run in user space. You wouldn’t be able to check if they are running before logon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you can severely limit your pre-health network with SGT, tag, acl controls to isolate machines before the check runs. With SGT you can even limit lateral movement between machines. Once the check is complete you give them full access by updating the controls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-before-logon/m-p/3479745#M527016</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-05T15:15:48Z</dc:date>
    </item>
  </channel>
</rss>

