<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE-VPN-Posture-Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594612#M538528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with one of the customers for ISE POC-VPN-Posture. Following is the Lab setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. ISE 2.0 patch 3 (Standalone)&lt;/P&gt;&lt;P&gt;2. Anyconnect 4.3 / 4.2 ( I have defined discovery host in posture profile)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Posture checks and remediation is working as expected on domain laptops. But we are observing following with respect to posture module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. When we disconnect the VPN connection, posture assessment kicks in again and does the all the posture checks and remediation.&lt;/P&gt;&lt;P&gt;2. When we connect to any other non-posture VPN profile (different ASA, different radius server), posture assessment kicks in and does all the posture checks and remediation. But it does not affect the connectivity even it shows non-compliant. Discovery host is reachable from all other VPN profiles and Lan network.&lt;/P&gt;&lt;P&gt;3. On non-domain laptops, getting no policy server found. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please throw some light on this. Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Jun 2016 16:30:04 GMT</pubDate>
    <dc:creator>Neelesh Marathe</dc:creator>
    <dc:date>2016-06-22T16:30:04Z</dc:date>
    <item>
      <title>ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594612#M538528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working with one of the customers for ISE POC-VPN-Posture. Following is the Lab setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. ISE 2.0 patch 3 (Standalone)&lt;/P&gt;&lt;P&gt;2. Anyconnect 4.3 / 4.2 ( I have defined discovery host in posture profile)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Posture checks and remediation is working as expected on domain laptops. But we are observing following with respect to posture module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. When we disconnect the VPN connection, posture assessment kicks in again and does the all the posture checks and remediation.&lt;/P&gt;&lt;P&gt;2. When we connect to any other non-posture VPN profile (different ASA, different radius server), posture assessment kicks in and does all the posture checks and remediation. But it does not affect the connectivity even it shows non-compliant. Discovery host is reachable from all other VPN profiles and Lan network.&lt;/P&gt;&lt;P&gt;3. On non-domain laptops, getting no policy server found. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please throw some light on this. Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2016 16:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594612#M538528</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-06-22T16:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594613#M538529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Neelesh, I've asked our AnyConnect and Posture TMEs to review this and provide a response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2016 15:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594613#M538529</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-23T15:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594614#M538531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need some clarification. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;1. When we disconnect the VPN connection, posture assessment kicks in again and does the all the posture checks and remediation."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Is the test machine for VPN on the 'Outside' interface security level 0&amp;nbsp; of the ASA with no access to the internal' Inside'&amp;nbsp; security level 100&amp;nbsp; unless VPN is established ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;"&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;2. When we connect to any other non-posture VPN profile (different ASA, different radius server), posture assessment kicks in and does all the posture checks and remediation. But it does not affect the connectivity even it shows non-compliant. Discovery host is reachable from all other VPN profiles and Lan network."&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;You do mean Tunnel-group/Connection profile - correct ?&amp;nbsp;&amp;nbsp;&amp;nbsp; Can you email me the ASA configuration directly it may help clear things up. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;"3. On non-domain laptops, getting no policy server found."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;With the vpn established to ASA ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;Paul&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2016 16:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594614#M538531</guid>
      <dc:creator>pcarco</dc:creator>
      <dc:date>2016-06-23T16:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594615#M538534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Hello Thomas,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Thanks..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Hello Paul,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Please find my answers &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Is the test machine for VPN on the 'Outside' interface security level 0&amp;nbsp; of te ASA with no access to the internal' Inside'&amp;nbsp; security level 100&amp;nbsp; unless VPN is established ? &lt;STRONG&gt;We only have one Inside interface on ASA. Public IP address is natted to this Inside interface IP address on Checkpoint which is installed before ASA. So its a same interface scenario. Radius and other traffic comes in and goes out from same interface.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;You do mean Tunnel-group/Connection profile - correct ?&amp;nbsp;&amp;nbsp;&amp;nbsp; Can you email me the ASA configuration directly it may help clear things up. &lt;/SPAN&gt;&amp;nbsp; - &lt;STRONG&gt;Correct. I have asked customer to share running configuration. I dont have access to ASA. I am also not sure if customer will share ASA config.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;With the vpn established to ASA ? &lt;STRONG&gt;Yes after VPN established. &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;&lt;SPAN style="color: #3d3d3d; font-size: 12px; font-family: arial;"&gt;Neelesh Marathe&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2016 06:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594615#M538534</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-06-24T06:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594616#M538536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please provide you inputs. I have responded to your queries. I dont have ASA running config yet. Once I get I will provide it to you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 09:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594616#M538536</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-06-27T09:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594617#M538537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion I think this topology is only going to complicate troubleshooting this and without the ASA configuration it is even more difficult.&amp;nbsp;&amp;nbsp; Why are they only using a single interface for VPN ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) what&amp;nbsp; network is the endpoint on when establishing the vpn session&amp;nbsp;&amp;nbsp; - is this the same network as ISE ?&lt;/P&gt;&lt;P&gt;2.)&amp;nbsp; What is the local ip pool or dhcp scope assigned to the user when the session is established ?&amp;nbsp; - Is this the same network as ISE and the same network that they established the session from ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please send the ASA configuration ASAP.&amp;nbsp; If they dont want to share then maybe they should open a TAC case and do a webex with them to troubleshoot this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jun 2016 20:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594617#M538537</guid>
      <dc:creator>pcarco</dc:creator>
      <dc:date>2016-06-27T20:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594618#M538538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem seems to be resolved after configuring ISE-group in radius-accounting configuration in ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Neelesh Marathe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jul 2016 16:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594618#M538538</guid>
      <dc:creator>Neelesh Marathe</dc:creator>
      <dc:date>2016-07-03T16:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE-VPN-Posture-Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594619#M538539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear its resolved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jul 2016 19:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-vpn-posture-issue/m-p/3594619#M538539</guid>
      <dc:creator>pcarco</dc:creator>
      <dc:date>2016-07-12T19:05:25Z</dc:date>
    </item>
  </channel>
</rss>

