<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect Posture issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303911#M546838</link>
    <description>&lt;P&gt;I know what you mean, when I first tried to set up provisioning it was almost impossible to find any good documentation on what is required for it to work properly. I had terrible results using the standalone &lt;STRONG&gt;ISE Posture Profile Editor&lt;/STRONG&gt; program but then I read somewhere that you can create the configuration file in ISE itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Client Provisioning &amp;gt; Resources&lt;/STRONG&gt; if you&amp;nbsp;add an&amp;nbsp;AnyConnect Posture Profile&amp;nbsp;here it actually takes you through the values and gives you notes and descriptions for various settings which allowed me to actually get a working config going.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Glad to hear it is working for you now!&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2017 14:35:57 GMT</pubDate>
    <dc:creator>Ben Walters</dc:creator>
    <dc:date>2017-12-29T14:35:57Z</dc:date>
    <item>
      <title>Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303431#M546816</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;I configured single standalone ISE 2.2 in my lab to authenticate clients and push them to install AnyConnect NAM, VPN and Compliance modules. Clients successfully authenticated and redirected to the provisioning portal. then they managed to install AnyConnect on their PCs and were asked to enter AD username/password. This was successful too and they got connected to the network. But they got "&lt;STRONG&gt;Searching For Policy Server&lt;/STRONG&gt;" and "&lt;STRONG&gt;Unauthorized Policy Server&lt;/STRONG&gt;" error messages on their Posture module (under System Scan Title). I reviewed "&lt;STRONG&gt;ISEPostureCFG.xml&lt;/STRONG&gt;" which was inside the ISE Posture Folder on their computers and IP address of ISE was there. As result, AnyConnect could not connect to ISE to report the Posture results and then they couldn't match a separate AUTHZ rule on ISE which has been configured for compliant clients. Any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303431#M546816</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2020-02-21T18:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303503#M546818</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ok you checked the profile file on the client and everything looks fine right?&lt;/P&gt;
&lt;P&gt;What are authorization and acl pushed when the client is in unknown state (at the connection) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What logs are you seeing on ISE?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 18:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303503#M546818</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-12-28T18:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303897#M546822</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;This is my Policy rules:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;A href="https://1drv.ms/i/s!AtnSgqfSTcPBxVh1negoFmBzAG5-" target="_blank"&gt;https://1drv.ms/i/s!AtnSgqfSTcPBxVh1negoFmBzAG5-&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;authz policy "&lt;STRONG&gt;TE-WIRED-PRE-nCOMPLIANT&lt;/STRONG&gt;" permits everything toward ISE server and all client networks and puts clients in vlan 500.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;A href="https://1drv.ms/i/s!AtnSgqfSTcPBxVc7nm8oVgzXWWLW" target="_blank"&gt;https://1drv.ms/i/s!AtnSgqfSTcPBxVc7nm8oVgzXWWLW&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I reviewed client PC for related files and saw there is only one file named "&lt;STRONG&gt;configuration_bad.xml&lt;/STRONG&gt;"inside "&lt;STRONG&gt;NewConfigFiles&lt;/STRONG&gt;" folder which contains my ISE IP address:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;lt;DiscoveryHost&amp;gt;10.1.204.168&amp;lt;/DiscoveryHost&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;lt;ServerNameRules&amp;gt;10.1.204.168&amp;lt;/ServerNameRules&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;STRONG&gt;ISEPostureCFG.xml&lt;/STRONG&gt;" file which resides inside "&lt;STRONG&gt;ISE Posture&lt;/STRONG&gt;" folder contains exact same content as &lt;SPAN&gt;"configuration_bad.xml"file!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "&lt;STRONG&gt;Configuration.xml&lt;/STRONG&gt;" file resides inside another folder "&lt;STRONG&gt;System&lt;/STRONG&gt;" which contains Anyconnect Connection Profile "&lt;STRONG&gt;TWired-Network&lt;/STRONG&gt;" as seen in the following image, but there is no line containing ISE IP address inside this file. Also you can see "Unauthorized Policy Server" error message has been displayed too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;A href="https://1drv.ms/i/s!AtnSgqfSTcPBxVmKu-GOati6UwQD" target="_blank"&gt;https://1drv.ms/i/s!AtnSgqfSTcPBxVmKu-GOati6UwQD&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the end, ISE shows client has been successfully authenticated and matched first authz rule (which has been created for compliant:unknown users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 13:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303897#M546822</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2017-12-29T13:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303907#M546826</link>
      <description>&lt;P&gt;It sounds like it could be an issue with the posture config file, are you able to include that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found when setting up my test environment, even though it was different from yours&amp;nbsp;(2 ISE nodes behind F5) I needed to use FQDN instead of IP address for the posture configuration so I created a host entry for my test ISE servers on my test machine.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 14:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303907#M546826</guid>
      <dc:creator>Ben Walters</dc:creator>
      <dc:date>2017-12-29T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303908#M546832</link>
      <description>Hi;&lt;BR /&gt;You're right. I managed to solve the issue. I'd written IP address of ISE for both of fields ("Discovery Host" and "Server Name Rules"). Then changed "Server Name Rules" filed to FQDN rather than actual IP and uninstall Anyconnect on client and started the whole process again, but this time everything went as expected and client was able to match against compliant authz rule. &lt;BR /&gt;This is very strange and I'm not sure I read anything about it on Cisco website.</description>
      <pubDate>Fri, 29 Dec 2017 14:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303908#M546832</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2017-12-29T14:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Posture issue</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303911#M546838</link>
      <description>&lt;P&gt;I know what you mean, when I first tried to set up provisioning it was almost impossible to find any good documentation on what is required for it to work properly. I had terrible results using the standalone &lt;STRONG&gt;ISE Posture Profile Editor&lt;/STRONG&gt; program but then I read somewhere that you can create the configuration file in ISE itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Client Provisioning &amp;gt; Resources&lt;/STRONG&gt; if you&amp;nbsp;add an&amp;nbsp;AnyConnect Posture Profile&amp;nbsp;here it actually takes you through the values and gives you notes and descriptions for various settings which allowed me to actually get a working config going.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Glad to hear it is working for you now!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 14:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-posture-issue/m-p/3303911#M546838</guid>
      <dc:creator>Ben Walters</dc:creator>
      <dc:date>2017-12-29T14:35:57Z</dc:date>
    </item>
  </channel>
</rss>

