<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Posturing and Compliance checks on Windows 10 Virtual Machine in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395169#M548521</link>
    <description>&lt;P&gt;1. AnyConnect NAM: Not installed, using native supplicant. &lt;/P&gt;
&lt;P&gt;2. AnyConnect ISE posture module: Installed, using version 4.4.03034&lt;/P&gt;
&lt;P&gt;3. AnyConnect ISE compliance module: Not installed yet because the client has yet to talk the policy server. As I understand it, this module gets installed during the first communication with the policy server.&lt;/P&gt;
&lt;P&gt;4. ISEPostureCFG.xml in &lt;STRONG&gt;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture:&lt;/STRONG&gt;&amp;nbsp;Yes there is a valid .xml here. I copied it from a known working host.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm fairly confident the xml was created using the template in ISE. Not 100% sure though as the xml was in use before I began working on this system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Kevin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 19:05:12 GMT</pubDate>
    <dc:creator>klopez138</dc:creator>
    <dc:date>2018-06-06T19:05:12Z</dc:date>
    <item>
      <title>Posturing and Compliance checks on Windows 10 Virtual Machine</title>
      <link>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395018#M548519</link>
      <description>&lt;P&gt;We currently have a windows 10 VM running on an ESXi host (6.5.0 Build 4564106) that we're intending on using for 802.1X testing. We have a need to be able to recreate NAC issues remotely so we're trying to configure this VM as a normal wired client that we'll have remote console access to should we need to troubleshoot/reproduce dot1X issues remotely. Everything appears to be working with the exception of posturing. The VM is authenticating with ISE but AnyConnect is not detecting a policy server and ISE is reporting posturing unknown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE version is 2.2. AnyConnect version 4.4. The vmnic on the ESXi host is not tagged with a VLAN ID (set to 0) and the switchport that the vmnic is connected to is configured as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;switchport access vlan 136&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;authentication control-direction in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action reinitialize vlan 136&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize &lt;BR /&gt;&amp;nbsp;authentication host-mode multi-host&lt;BR /&gt;&amp;nbsp;authentication open&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connectivity is working just fine, just not posturing or compliance checks. Any help with this issue is greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395018#M548519</guid>
      <dc:creator>klopez138</dc:creator>
      <dc:date>2020-02-21T18:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Posturing and Compliance checks on Windows 10 Virtual Machine</title>
      <link>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395151#M548520</link>
      <description>&lt;P&gt;Let's start with the client, do you have the following installed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. AnyConnect NAM&lt;/P&gt;
&lt;P&gt;2. AnyConnect ISE posture module&lt;/P&gt;
&lt;P&gt;3. AnyConnect ISE compliance module&lt;/P&gt;
&lt;P&gt;4. ISEPostureCFG.xml in &lt;STRONG&gt;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you also have a properly configured ISEPostureCFG.xml?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you create your own file&amp;nbsp;or use the template in ISE? Found in &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Client Provisioning &amp;gt; Resources &amp;gt; Add &amp;gt; NAC agent or AnyConnect&amp;nbsp;Posture Profile &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a good place to start considering it already authenticates with your ISE.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 18:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395151#M548520</guid>
      <dc:creator>Ben Walters</dc:creator>
      <dc:date>2018-06-06T18:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Posturing and Compliance checks on Windows 10 Virtual Machine</title>
      <link>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395169#M548521</link>
      <description>&lt;P&gt;1. AnyConnect NAM: Not installed, using native supplicant. &lt;/P&gt;
&lt;P&gt;2. AnyConnect ISE posture module: Installed, using version 4.4.03034&lt;/P&gt;
&lt;P&gt;3. AnyConnect ISE compliance module: Not installed yet because the client has yet to talk the policy server. As I understand it, this module gets installed during the first communication with the policy server.&lt;/P&gt;
&lt;P&gt;4. ISEPostureCFG.xml in &lt;STRONG&gt;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture:&lt;/STRONG&gt;&amp;nbsp;Yes there is a valid .xml here. I copied it from a known working host.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm fairly confident the xml was created using the template in ISE. Not 100% sure though as the xml was in use before I began working on this system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Kevin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 19:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3395169#M548521</guid>
      <dc:creator>klopez138</dc:creator>
      <dc:date>2018-06-06T19:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Posturing and Compliance checks on Windows 10 Virtual Machine</title>
      <link>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3398063#M548522</link>
      <description>&lt;P&gt;This issue has been resolved. There was no ACL on the switch redirecting posture-unknown devices to the ISE servers. Once the ACL was in place, the VM was able to detect the policy servers.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 13:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posturing-and-compliance-checks-on-windows-10-virtual-machine/m-p/3398063#M548522</guid>
      <dc:creator>klopez138</dc:creator>
      <dc:date>2018-06-12T13:48:24Z</dc:date>
    </item>
  </channel>
</rss>

