<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE posture pending loop in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603448#M536549</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please tell me which version you are on? What i think this is bug &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCul66272" rel="nofollow" style="color: #4a7399; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;" target="_blank"&gt;CSCul66272&lt;/A&gt;. See the detail below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="description" style="color: #4a7399;"&gt;Description&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P style="margin: 0 0 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;Symptom:&lt;BR /&gt;The NAC Agent gets suck in a posture loop. The sequence of events seen for the agent is:&lt;BR /&gt;1) An authentication entry is seen for the host and posture is set to pending.&lt;BR /&gt;2) A CoA is sent for the host with the posture status matching the globally set default posture status.&lt;BR /&gt;3) An authentication is again seen for the host with the posture status set to pending.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;BR /&gt;ISE 1.2.0.899&lt;BR /&gt;An application is installed on the end host that sends an HTTP or HTTPS packet with an unknown user-agent.&lt;BR /&gt;Posture is configured and in use.&lt;/P&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Last Modified:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 9,2014&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Status:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fixed&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Severity:&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 Moderate&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Product:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Identity Services Engine (ISE) 3300 Series Appliances&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: 1px solid black; padding-left: 2px;"&gt;Known Affected Releases:&lt;/TD&gt;&lt;TD style="border: 1px solid black;"&gt;&lt;DIV&gt;(1)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;1.2(0.899)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE cellpadding="0" cellspacing="0" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: 1px solid black; padding-left: 2px;"&gt;Known Fixed Releases:&lt;/TD&gt;&lt;TD style="border: 1px solid black;"&gt;&lt;DIV&gt;(2)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;1.2(0.907)&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.2(1.198)&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jan 2017 08:49:54 GMT</pubDate>
    <dc:creator>Ravi Singh</dc:creator>
    <dc:date>2017-01-12T08:49:54Z</dc:date>
    <item>
      <title>ISE posture pending loop</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603447#M536548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; i'm facing a strange issue while anyconnect posture running it fails in one of the requirement and the configured remediation timer is 3 min&lt;/P&gt;&lt;P&gt;after that it should go to non-compliant with remediation vlan. but we noticed that posture tries to re-scan again every 16 seconds hence remediation timer starts again from beginning which means that user will never hit non-compliant profile !!! he will stay in unknown state forever !!!&lt;/P&gt;&lt;P&gt;it like a loop&lt;/P&gt;&lt;P&gt;1- user gets remediation text message&lt;/P&gt;&lt;P&gt;2- remediation timer starts counting&lt;/P&gt;&lt;P&gt;3- after 16 seconds anyconnect starts scanning again&lt;/P&gt;&lt;P&gt;4- back to step 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the user status in ISE always pending "unknown state" !!!&amp;nbsp; so what do you think what is maybe the issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jan 2017 13:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603447#M536548</guid>
      <dc:creator>kareali@cisco.com</dc:creator>
      <dc:date>2017-01-10T13:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture pending loop</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603448#M536549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please tell me which version you are on? What i think this is bug &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCul66272" rel="nofollow" style="color: #4a7399; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;" target="_blank"&gt;CSCul66272&lt;/A&gt;. See the detail below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;&lt;A name="description" style="color: #4a7399;"&gt;Description&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P style="margin: 0 0 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;Symptom:&lt;BR /&gt;The NAC Agent gets suck in a posture loop. The sequence of events seen for the agent is:&lt;BR /&gt;1) An authentication entry is seen for the host and posture is set to pending.&lt;BR /&gt;2) A CoA is sent for the host with the posture status matching the globally set default posture status.&lt;BR /&gt;3) An authentication is again seen for the host with the posture status set to pending.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;BR /&gt;ISE 1.2.0.899&lt;BR /&gt;An application is installed on the end host that sends an HTTP or HTTPS packet with an unknown user-agent.&lt;BR /&gt;Posture is configured and in use.&lt;/P&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Last Modified:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 9,2014&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Status:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fixed&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Severity:&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 Moderate&lt;/P&gt;&lt;/DIV&gt;&lt;P style="color: #333333; font-family: Arial, sans-serif; font-size: 14.4px; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; background-color: #f9f9f9;"&gt;&lt;/P&gt;&lt;DIV&gt;Product:&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Identity Services Engine (ISE) 3300 Series Appliances&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: 1px solid black; padding-left: 2px;"&gt;Known Affected Releases:&lt;/TD&gt;&lt;TD style="border: 1px solid black;"&gt;&lt;DIV&gt;(1)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;1.2(0.899)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;TABLE cellpadding="0" cellspacing="0" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: 1px solid black; padding-left: 2px;"&gt;Known Fixed Releases:&lt;/TD&gt;&lt;TD style="border: 1px solid black;"&gt;&lt;DIV&gt;(2)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;1.2(0.907)&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.2(1.198)&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2017 08:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603448#M536549</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2017-01-12T08:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture pending loop</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603449#M536550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got the exactly the same issue here in a new solution with version 2.2.0.470-Patch1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client just starts reassesment and stays in a posturing state, nothing happens on ISE or switch tough so it seems like a client issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 May 2017 07:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-pending-loop/m-p/3603449#M536550</guid>
      <dc:creator>Andre Liverod</dc:creator>
      <dc:date>2017-05-13T07:33:07Z</dc:date>
    </item>
  </channel>
</rss>

