<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE posture policy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-policy/m-p/3518923#M527689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Dear experts,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Please help on below two questions.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;1. How anyconnect posture module to decide the checking order of rules I configure in posture rules on ISE. The actual checking order is not the same with what I configure. In my testing, windows server update services is always the first one to be checked. Because WSUS remediation always spends more time downloading and installing patches and cause remediation time expired. So other rules are not even checked.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;2. I use the default remediation timer--4 minutes in my lab. But time of WSUS remediation which is one of three posture rules is longer than 4 minutes. So is there other specific timer for each remediation?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;ISE Version: 2.2.0.470&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Anyconnect Version: 4.4.02034&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Compliance Module: 4.2.1134.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Aug 2017 15:57:53 GMT</pubDate>
    <dc:creator>xili5</dc:creator>
    <dc:date>2017-08-11T15:57:53Z</dc:date>
    <item>
      <title>ISE posture policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-policy/m-p/3518923#M527689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Dear experts,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Please help on below two questions.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;1. How anyconnect posture module to decide the checking order of rules I configure in posture rules on ISE. The actual checking order is not the same with what I configure. In my testing, windows server update services is always the first one to be checked. Because WSUS remediation always spends more time downloading and installing patches and cause remediation time expired. So other rules are not even checked.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;2. I use the default remediation timer--4 minutes in my lab. But time of WSUS remediation which is one of three posture rules is longer than 4 minutes. So is there other specific timer for each remediation?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;ISE Version: 2.2.0.470&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Anyconnect Version: 4.4.02034&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Compliance Module: 4.2.1134.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 15:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-policy/m-p/3518923#M527689</guid>
      <dc:creator>xili5</dc:creator>
      <dc:date>2017-08-11T15:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture policy</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-policy/m-p/3518924#M527690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 1, two possibilities:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Each of posture requirements may have one or more conditions. With 2+ conditions, we may OR them by the selection of "Any selected conditions succeeds".&lt;IMG alt="Screen Shot 2017-08-11 at 6.47.09 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/110449_Screen Shot 2017-08-11 at 6.47.09 PM.png" style="height: 98px; width: 620px;" /&gt;&lt;/LI&gt;&lt;LI&gt;ISE posture policy is matched all. To have one requirement after another, we may add them into the same rule.&lt;IMG alt="Screen Shot 2017-08-11 at 6.53.47 PM.png" class="jive-image image-2" src="/legacyfs/online/fusion/110454_Screen Shot 2017-08-11 at 6.53.47 PM.png" style="height: auto; width: auto;" /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;On 2, there is no remediation timer for individual remediation so please set a longer timer for overall remediations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Aug 2017 01:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-policy/m-p/3518924#M527690</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-12T01:55:25Z</dc:date>
    </item>
  </channel>
</rss>

