<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to keep endpoint alive after session termination in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521763#M536279</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This works great on Cisco switches, but not on HP ProCurve which this customer has. cant do dacl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Feb 2017 21:51:44 GMT</pubDate>
    <dc:creator>Jeffrey Jones</dc:creator>
    <dc:date>2017-02-02T21:51:44Z</dc:date>
    <item>
      <title>How to keep endpoint alive after session termination</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521760#M536264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Situation: User logs off system terminating session with ISE, how can an administrator still get to the device for windows updates, etc, or to log in to the system to troubleshoot. VNC is installed on endpoints, but we can not even RDP to the endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE version 2.1 patch 1 and 2, AnyConnect version 4.3 with NAM and ISE Posture, DART also installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2017 19:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521760#M536264</guid>
      <dc:creator>Jeffrey Jones</dc:creator>
      <dc:date>2017-02-01T19:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep endpoint alive after session termination</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521761#M536271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeffrey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already responded to your question in other post here: &lt;A href="https://community.cisco.com/message/244864"&gt;Re: ISE 1.4 API remove stale sessions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use Low Impact Mode or return a default MAB-based policy that grants required access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 05:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521761#M536271</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-02-02T05:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep endpoint alive after session termination</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521762#M536278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a good question.&amp;nbsp; I think that if you have implemented machine authentication (AD Domain Joined Machines), you should be able to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an Authorization Compound Condition (&lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Authorization &amp;gt; Compound Conditions&lt;/STRONG&gt;) set up like this:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="CompCond.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/104384_CompCond.png" style="height: 348px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is used in my Wired Access Policy Set (&lt;STRONG&gt;Policy &amp;gt; Policy Sets&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="machine policy.PNG" class="jive-image image-2" src="/legacyfs/online/fusion/104385_machine policy.PNG" style="height: 27px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;The permissions (AD-ONLY) given are set at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authorization Profiles&lt;/STRONG&gt;.&amp;nbsp; Of course, you'll need a DACL for this, too (&lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Downloadable ACLs&lt;/STRONG&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AuthProf.PNG" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/104386_AuthProf.PNG" style="height: 244px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that should give you the access you desire.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 18:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521762#M536278</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-02-02T18:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep endpoint alive after session termination</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521763#M536279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This works great on Cisco switches, but not on HP ProCurve which this customer has. cant do dacl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 21:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521763#M536279</guid>
      <dc:creator>Jeffrey Jones</dc:creator>
      <dc:date>2017-02-02T21:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep endpoint alive after session termination</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521764#M536281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then reference the ACL on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AuthProACL.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/104406_AuthProACL.PNG" style="height: 407px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2017 21:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-keep-endpoint-alive-after-session-termination/m-p/3521764#M536281</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-02-02T21:55:37Z</dc:date>
    </item>
  </channel>
</rss>

