<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Posture Flexibility Question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539983#M536695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need an additional ASA for this.&amp;nbsp; You can use a different Tunnel Group.&amp;nbsp; You can then use that tunnel group to determine which Policy Set is used in ISE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="VPN_Group.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/103359_VPN_Group.PNG" style="height: 69px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taking it a step further, you can use the AD Group membership in the Authorization Policy to state that if a contractor connects to the Employee VPN tunnel, then they are either denied access or are redirected to a "Hotspot as a Message Portal" giving specific instruction on which VPN Group is to be connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also do the reverse with Employees connecting to the Contractor's VPN Tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Start here for the basic set up for the Hotspot as a Message configuration:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68167"&gt;How To: ISE Web Portal Customization Options&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow Exercise 1.&amp;nbsp; When you get to Step 7, here is the script:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="HotspotAsMessage.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/103360_HotspotAsMessage.PNG" style="height: 267px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also be sure to use any AD Group Memberships in the Posture Policy "Other Conditions" field to assign Posture Policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can use Endpoint Identity Groups in the Authorization Policy to determine Corp Owned Devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Dec 2016 14:38:38 GMT</pubDate>
    <dc:creator>Charlie Moreton</dc:creator>
    <dc:date>2016-12-19T14:38:38Z</dc:date>
    <item>
      <title>VPN Posture Flexibility Question</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539982#M536694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;We're finding it difficult to put a specific use case into practice with the Posture options.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Employees + Corporate Assets = Posture checking and Remediation&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Employees + BYOD devices = Posture checking with no Remediation (AV presence)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Contractors + Corporate Assets = Posture checking but no remediation (authZ denied)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Contractors + BYOD devices = Posture checking with no Remediation (AV presence)&amp;nbsp; Same as Employees&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;The problem is by the time the posture policy is invoked for all of these use cases, there is no way to differentiate the user’s role from the endpoint they have.&amp;nbsp; It wouldn’t be a problem except the remediations are different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;My solution so far has been that the contractors need their own ASA.&amp;nbsp; The posture policy in ISE can use the ASA IP (or type/location) as a constraint to match the rule.&amp;nbsp; Hopefully someone here has a more elegant solution.&amp;nbsp; It seems like it should be doable but it isn’t looking obvious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I was thinking it would be great if we had policy sets for the Posture policy.&amp;nbsp; Maybe the authZ policy could cite Posture policyX for example.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Dec 2016 04:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539982#M536694</guid>
      <dc:creator>GQ</dc:creator>
      <dc:date>2016-12-17T04:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Posture Flexibility Question</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539983#M536695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need an additional ASA for this.&amp;nbsp; You can use a different Tunnel Group.&amp;nbsp; You can then use that tunnel group to determine which Policy Set is used in ISE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="VPN_Group.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/103359_VPN_Group.PNG" style="height: 69px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taking it a step further, you can use the AD Group membership in the Authorization Policy to state that if a contractor connects to the Employee VPN tunnel, then they are either denied access or are redirected to a "Hotspot as a Message Portal" giving specific instruction on which VPN Group is to be connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also do the reverse with Employees connecting to the Contractor's VPN Tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Start here for the basic set up for the Hotspot as a Message configuration:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68167"&gt;How To: ISE Web Portal Customization Options&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow Exercise 1.&amp;nbsp; When you get to Step 7, here is the script:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="HotspotAsMessage.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/103360_HotspotAsMessage.PNG" style="height: 267px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also be sure to use any AD Group Memberships in the Posture Policy "Other Conditions" field to assign Posture Policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can use Endpoint Identity Groups in the Authorization Policy to determine Corp Owned Devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2016 14:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539983#M536695</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-12-19T14:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Posture Flexibility Question</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539984#M536696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is how do you allow for Contractors using both corporate assets and BYOD devices?&amp;nbsp; You have to use posture checks for that but the different posture checks can't be used as posture inputs.&amp;nbsp; meaning&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Contractors connect to Tunnel Group 'Contractors'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;posture check looks for TG=Contractors + AD Group Contractors...&amp;nbsp; but now I need two different postures.&amp;nbsp; one is if it's a Corp asset then patches/AV/etc.&amp;nbsp; If it's a BYOD device, only need AV.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By using a second ASA, the posture check can now be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;TG=Contractors + AD Group Contractors + ASA=Contractors&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;versus&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;TG=Contractors + AD Group Contractors + ASA=Employees&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Trust me, the partner, TAC, and myself have looked it every which way.&amp;nbsp; There just aren't a lot of selectable criteria in the Posture Policy for granular results like the customer wants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2017 17:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539984#M536696</guid>
      <dc:creator>GQ</dc:creator>
      <dc:date>2017-01-03T17:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Posture Flexibility Question</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539985#M536697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of the features in the upcoming ISE release might help. I would suggest to join the ISE beta community, if not already done, to get more details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2017 04:47:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-posture-flexibility-question/m-p/3539985#M536697</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-01-18T04:47:14Z</dc:date>
    </item>
  </channel>
</rss>

