<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - Posture Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046129#M558904</link>
    <description>&lt;P&gt;On ISE side i have configure a Client Provisioning Policy like described below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- First download and upload to ISE the anyconnect package .&lt;/P&gt;&lt;P&gt;- Upload Compliace module&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Create a Posture Profile&lt;/P&gt;&lt;P&gt;- Create Anyconnect Configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Create Client Provisioning Policy as the image i upload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i also though that maybe i am not hitting the cpp but for this i tried to Other Conditions to import a condition that&amp;nbsp;&lt;/P&gt;&lt;P&gt;matches the endpoind Radius-Calling-Station-ID to be sure that i will match to this policy but no luck .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 15 Mar 2020 15:44:39 GMT</pubDate>
    <dc:creator>pgiouvanellis</dc:creator>
    <dc:date>2020-03-15T15:44:39Z</dc:date>
    <item>
      <title>Cisco ISE - Posture Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046092#M558902</link>
      <description>&lt;P&gt;Hello Everyone ,&lt;/P&gt;&lt;P&gt;I am facing an issue trying to implement Posturing in a customer's enviroment .&lt;/P&gt;&lt;P&gt;Below are the details of the customer's network and the implementation i have done until know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The endpoints are in vlan 100 , the switch that endpoints are connected does not have svi in vlan 100&lt;BR /&gt;but on management vlan which is vlan 50 .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway of the endpoints is a vlan interface which is on Fortigate Firewall .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use anyconnect posture agent and we have manual create ISEPostureCFG.xml profile where&lt;BR /&gt;we have assigned the domain names of ISE Nodes ( we have 2 nodes with PAN,MnT and PSN personas )&lt;BR /&gt;to Call Home List .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue that i am facing is that the end point agent is not able to retrieve configuration from ISE&lt;BR /&gt;and finally get message "Bypassing AnyConnect scan—Your network is configured to use the Cisco NAC agent."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the Dart Tool from endpoint i get the below erros : "Failed to retrieve http header X-ISE-PDP-WITH-SESSION."&lt;/P&gt;&lt;P&gt;I attached more logs from DART .&lt;/P&gt;&lt;P&gt;I tried to implement Posture with DACL and ACL Redirect but yntil know no obvious reason from not getting the agent run properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On firewall side not see any deny/block logs .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone faced the same problem with firewall in the middle of communications .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please for any help if possible .&lt;/P&gt;&lt;P&gt;Thank You ,&lt;BR /&gt;Palaiologos&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 14:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046092#M558902</guid>
      <dc:creator>pgiouvanellis</dc:creator>
      <dc:date>2020-03-15T14:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Posture Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046120#M558903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;By looking at the logs, there looks to be connectivity with ISE, and afterwards you have those 'error' messages to call it this way. So i see two options, without having too much details on the configuration and used software:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - ensure your posture is properly configured on ISE, as the messages tend to say otherwise (like the Anyconnect agent and profiles are not found in ISE policy):&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - ensure you apply the latest patch available to ISE for the version you're running, also try a stable version of Anyconnect, to avoid bugs; for example this looks similar to your setup:&amp;nbsp;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvo28970" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvo28970&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 15:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046120#M558903</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-15T15:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Posture Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046129#M558904</link>
      <description>&lt;P&gt;On ISE side i have configure a Client Provisioning Policy like described below :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- First download and upload to ISE the anyconnect package .&lt;/P&gt;&lt;P&gt;- Upload Compliace module&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Create a Posture Profile&lt;/P&gt;&lt;P&gt;- Create Anyconnect Configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Create Client Provisioning Policy as the image i upload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i also though that maybe i am not hitting the cpp but for this i tried to Other Conditions to import a condition that&amp;nbsp;&lt;/P&gt;&lt;P&gt;matches the endpoind Radius-Calling-Station-ID to be sure that i will match to this policy but no luck .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 15:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4046129#M558904</guid>
      <dc:creator>pgiouvanellis</dc:creator>
      <dc:date>2020-03-15T15:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Posture Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4090912#M560644</link>
      <description>&lt;P&gt;I ran into this same error message, but in my case the problem was that none of my Client Provisioning Policies were matching.&amp;nbsp; I had made an error in the External AD Groups selection for the EP.&lt;/P&gt;&lt;P&gt;I swam around in circles making sure my result didn't have a Temporal Agent in it....&amp;nbsp; but I guess that is some default when all your provisioning policies fail.&amp;nbsp; Once I corrected that problem the posture module popped right up and downloaded the AC Configs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**ISE 2.4 Patch 9, AC 4.8.3052 with ISE Posture module, wired dot1x.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 18:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-issues/m-p/4090912#M560644</guid>
      <dc:creator>MatthewShaw4644</dc:creator>
      <dc:date>2020-05-22T18:47:11Z</dc:date>
    </item>
  </channel>
</rss>

