<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE VPN POSTURE notworking in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987312#M541157</link>
    <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have cisco ISE SSH VPN , posture scan i snot working .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on Anyconnect Posture module&amp;nbsp; showing '' No Policy Server Detected ''&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the End-point -CMD , nslookup to the ISE server FQDN is showing timeout (Screenshot is attached )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 15:37:03 GMT</pubDate>
    <dc:creator>aslam.bajwa</dc:creator>
    <dc:date>2019-11-21T15:37:03Z</dc:date>
    <item>
      <title>Cisco ISE VPN POSTURE notworking</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987312#M541157</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have cisco ISE SSH VPN , posture scan i snot working .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on Anyconnect Posture module&amp;nbsp; showing '' No Policy Server Detected ''&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the End-point -CMD , nslookup to the ISE server FQDN is showing timeout (Screenshot is attached )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 15:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987312#M541157</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-11-21T15:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE VPN POSTURE notworking</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987324#M541158</link>
      <description>Hi,&lt;BR /&gt;If you cannot resolve DNS names, are you pushing down a DACL which could be blocking DNS? Try without applying the DACL to the user session to determine if a DACL issue.</description>
      <pubDate>Thu, 21 Nov 2019 15:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987324#M541158</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-11-21T15:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE VPN POSTURE notworking</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987445#M541159</link>
      <description>More than likely this is a dacl issue as already mentioned. You have options within ISE to statically set the ip in the authz profile that would help eliminate the name resolution issue as a connectivity test. Obviously your restricted area must be able to reach your ISE PSN that will be performing the posture checks. Something else you could try as a quick test is using your hosts file locally if you are running Windows to statically provide dns. As far as CoA things are concerned for applying different dacls etc. make sure that udp port 1700 is not blocked along the path between your NAD &amp;amp; ISE OR for VPN between your ASA &amp;amp; ISE. HTH!</description>
      <pubDate>Thu, 21 Nov 2019 19:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987445#M541159</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-11-21T19:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE VPN POSTURE notworking</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987933#M541160</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;More than likely this is a dacl issue as already mentioned. You have options within ISE to statically set the ip in the authz profile that would help eliminate the name resolution issue as a connectivity test. Obviously your restricted area must be able to reach your ISE PSN that will be performing the posture checks. Something else you could try as a quick test is using your hosts file locally if you are running Windows to statically provide dns. As far as CoA things are concerned for applying different dacls etc. make sure that udp port 1700 is not blocked along the path between your NAD &amp;amp; ISE OR for VPN between your ASA &amp;amp; ISE. HTH!&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;yes and also checked out the&amp;nbsp;&lt;A href="https://cs.co/ise-guides" target="_blank"&gt;https://cs.co/ise-guides&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;in particular the one titled&amp;nbsp;&lt;A title="ISE Posture Prescriptive Deployment Guide" href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank" rel="noopener"&gt;ISE Posture Prescriptive Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If still having issues please work through tac&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 15:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-notworking/m-p/3987933#M541160</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-22T15:14:52Z</dc:date>
    </item>
  </channel>
</rss>

