<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Pre and Post Posture in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3936553#M541228</link>
    <description>Please also look at the ISE posture guide and no redirect option&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&lt;/A&gt;</description>
    <pubDate>Mon, 07 Oct 2019 16:44:18 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-10-07T16:44:18Z</dc:date>
    <item>
      <title>Cisco ISE Pre and Post Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935960#M541224</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have cisco ISE 2.4 ,&amp;nbsp; Distributed deployment with Wired , Wireless and VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;currently we have&amp;nbsp; Pre-Posture configuration ( i.e. we have to enable http server on Cisco Switches for redirect ) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can we move to Post-posture configuration ? currently we have more then 800 hundred users in production ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what cisco best practices says&amp;nbsp; ? should we go for Post-Posture configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 10:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935960#M541224</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-10-06T10:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Pre and Post Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935962#M541225</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I assume you referring to post ISE 2.2 posture which does not require a redirect? You need to pre-provision the AnyConnect client and the ISEPostureCFG.XML configuration file, this need to be configured with call home list in order to start the posture process. Reference &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 10:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935962#M541225</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-06T10:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Pre and Post Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935967#M541226</link>
      <description>&lt;P&gt;Hi RJI ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks for your reply .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;correct , i am asking about&amp;nbsp;&lt;SPAN&gt;post ISE 2.2 posture , but my man concern is what is the cisco best practices and recommendations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Pre-Posture or Post posture&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 10:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935967#M541226</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-10-06T10:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Pre and Post Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935971#M541227</link>
      <description>Well if you control the endpoints and can pre-deploy the configuration xml file and anyconnect posture client, you don't need the redirect ACL. Which saves on configuration and complexity. You can also manually provision the client, but browsing to the CPP webpage.&lt;BR /&gt;&lt;BR /&gt;However if haven't pre-deployed the anyconnect client and xml configuration file and you want the client to automatically be redirected to the CPP to provision the agent and configuration then you will need the redirection ACL.&lt;BR /&gt;&lt;BR /&gt;So it's not necessarily about best practice, it's about your scenario and if the endpoints have the configuration/agent. Ideally IMO you'd pre-deploy the necessary configuration files and anyconnect agent, then you don't need the redirection ACL but just rely on the call home list.</description>
      <pubDate>Sun, 06 Oct 2019 11:21:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3935971#M541227</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-06T11:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Pre and Post Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3936553#M541228</link>
      <description>Please also look at the ISE posture guide and no redirect option&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html&lt;/A&gt;</description>
      <pubDate>Mon, 07 Oct 2019 16:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-pre-and-post-posture/m-p/3936553#M541228</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-10-07T16:44:18Z</dc:date>
    </item>
  </channel>
</rss>

