<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Posture.xml in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503799#M535846</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig, thanks for prompt response, good to know it's not down to a PSN. The documentation that explains this is not quite as clear as your response. &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 May 2017 18:04:22 GMT</pubDate>
    <dc:creator>khalid_mahmood</dc:creator>
    <dc:date>2017-05-15T18:04:22Z</dc:date>
    <item>
      <title>ISE Posture.xml</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503797#M535844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have 2 datacenter sites, a primary and backup. The profile.xml file needs a DiscoveryHost defining which we've defined as the Policy Node 1 in DC1. the server rules in the profile are set as "*" for wildcard. The question is if DC1 fails how will the posture work with DC2, how will it find the Policy Nodes in DC2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using AnyConnect v4.4.243 on Windows 10&lt;/P&gt;&lt;P&gt;ISE v2.1 patch 3&lt;/P&gt;&lt;P&gt;ISE Compliance module 4.2.508&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Khalid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 May 2017 16:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503797#M535844</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-05-15T16:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture.xml</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503798#M535845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Discovery Host should NOT point to PSN.&amp;nbsp; It should point to an IP reachable network that is behind a URL redirection point and which is not permitted by NAD policy.&amp;nbsp; The PSN should return the redirect URL to point to itself.&amp;nbsp; Typically the dACL will allow access to each PSN.&amp;nbsp; Therefore, you will NEVER be redirected to PSN and discovery will fail.&amp;nbsp; In releases prior to ISE 2.2 (with AC 4.4), ISE requires that Posture traffic reaches PSN via redirection, not direct connection.&amp;nbsp; Exception is ConnectionData.xml, but this file is reserved for tracking prior connected headends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 May 2017 17:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503798#M535845</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-15T17:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Posture.xml</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503799#M535846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig, thanks for prompt response, good to know it's not down to a PSN. The documentation that explains this is not quite as clear as your response. &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 May 2017 18:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-xml/m-p/3503799#M535846</guid>
      <dc:creator>khalid_mahmood</dc:creator>
      <dc:date>2017-05-15T18:04:22Z</dc:date>
    </item>
  </channel>
</rss>

