<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 posturing MacOS installation issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281621#M565096</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415766"&gt;@KelvinT&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;first of all ... you said "&lt;EM&gt;ISE 2.7 P3&lt;/EM&gt;" ... could you please double check ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Your REDIRECT ACL looks fine ... could you please:&lt;/P&gt;&lt;P&gt;1. delete the &lt;STRONG&gt;/opt/cisco/anyconnect/profile/ISEPostureCFG.xml&lt;/STRONG&gt; file&lt;/P&gt;&lt;P&gt;2. connect again&lt;/P&gt;&lt;P&gt;3. double check if the &lt;STRONG&gt;Supplicant&lt;/STRONG&gt; is able to download the&amp;nbsp;&lt;STRONG&gt;ISEPostureCFG.xml&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 18:42:52 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-01-28T18:42:52Z</dc:date>
    <item>
      <title>ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279048#M564974</link>
      <description>&lt;P&gt;ISE 2.7 patch 3&lt;/P&gt;&lt;P&gt;AnyConnect 4.8&lt;/P&gt;&lt;P&gt;MacOS&lt;/P&gt;&lt;P&gt;Smartcard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to install Anyconnect posturing on a MacOS manually (i.e. no JAMF or Mac Server).&amp;nbsp; I install the application and place the ISEPostureCFG.xml file in the opt/cisco/anyconnect/profile/ folder.&amp;nbsp; This file points to the correct PSNs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When We attempt to scan it can't locate the servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea why?&amp;nbsp; I don't believe it's a firewall issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 15:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279048#M564974</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2021-01-25T15:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279088#M564982</link>
      <description>&lt;P&gt;During client onboarding when the client posture status is 'Posture Unknown' do you apply a dacl of some sort limiting connectivity? Ensure that in this state access to the PSNs is allowed.&amp;nbsp; List of ports:&lt;/P&gt;
&lt;P&gt;----&lt;/P&gt;
&lt;P&gt;Posture&lt;BR /&gt;- Discovery&lt;BR /&gt;- Provisioning&lt;BR /&gt;- Assessment/ Heartbeat&lt;/P&gt;
&lt;P&gt;Discovery (Client side): TCP/80 (HTTP), TCP/8905 (HTTPS)&lt;/P&gt;
&lt;P&gt;Note : By default, TCP/80 is redirected to TCP/8443. See Web Portal Services: Guest Portal and Client Provisioning.&lt;/P&gt;
&lt;P&gt;Cisco ISE presents the Admin certificate for Posture and Client Provisioning on TCP port 8905.&lt;/P&gt;
&lt;P&gt;Cisco ISE presents the Portal certificate on TCP port 8443 (or the port that you have configured for portal use).&lt;/P&gt;
&lt;P&gt;Discovery (Policy Service Node side): TCP/8443, 8905 (HTTPS)&lt;/P&gt;
&lt;P&gt;Provisioning - URL Redirection: See Web Portal Services: Guest Portal and Client Provisioning&lt;/P&gt;
&lt;P&gt;Provisioning - Active-X and Java Applet Install including IP refresh, Web Agent Install, and launch NAC Agent Install: See Web Portal Services: Guest Portal and Client Provisioning.&lt;/P&gt;
&lt;P&gt;Provisioning - NAC Agent Install: TCP/8443&lt;/P&gt;
&lt;P&gt;Provisioning - NAC Agent Update Notification: UDP/8905&lt;/P&gt;
&lt;P&gt;Provisioning - NAC Agent and Other Package/Module Updates: TCP/8905 (HTTPS)&lt;/P&gt;
&lt;P&gt;Assessment - Posture Negotiation and Agent Reports: TCP/8905 (HTTPS)&lt;/P&gt;
&lt;P&gt;Assessment - PRA/Keep-alive: UDP/8905&lt;/P&gt;
&lt;P&gt;----&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 16:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279088#M564982</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-01-25T16:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279098#M564984</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; The switch's local ACL is "Deny" (i.e. no redirect) ISE ip with the listed ports.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 17:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279098#M564984</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2021-01-25T17:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279317#M564998</link>
      <description>&lt;P&gt;If possible please share your ACL.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4279317#M564998</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-01-25T21:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281556#M565095</link>
      <description>&lt;P&gt;POSTURE-REDIRECT&lt;BR /&gt;remark DNS&lt;BR /&gt;deny udp any any eq domain&lt;BR /&gt;remark DHCP&lt;BR /&gt;deny udp any eq bootpc any eq bootps&lt;BR /&gt;remark RDP connection&lt;BR /&gt;deny tcp any eq 3389 any&lt;BR /&gt;remark Drive Mapping ports&lt;BR /&gt;deny udp any any range netbios-ns netbios-dgm&lt;BR /&gt;deny tcp any any eq 139&lt;BR /&gt;deny tcp any any eq 445&lt;BR /&gt;remark ISE Server&lt;BR /&gt;deny tcp any host ISE1 eq 8905&lt;BR /&gt;deny udp any host ISE1 eq 8905&lt;BR /&gt;deny tcp any host ISE1 eq 8909&lt;BR /&gt;deny udp any host ISE1 eq 8909&lt;BR /&gt;deny tcp any host ISE1 eq 8443&lt;BR /&gt;deny udp any host ISE2 eq 8905&lt;BR /&gt;deny tcp any host ISE2 eq 8905&lt;BR /&gt;deny udp any host ISE2 eq 8909&lt;BR /&gt;deny tcp any host ISE2 eq 8909&lt;BR /&gt;deny tcp any host ISE2 eq 8443&lt;BR /&gt;remark Redirect everything else&lt;BR /&gt;permit ip any any&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281556#M565095</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2021-01-28T17:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281621#M565096</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415766"&gt;@KelvinT&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;first of all ... you said "&lt;EM&gt;ISE 2.7 P3&lt;/EM&gt;" ... could you please double check ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Your REDIRECT ACL looks fine ... could you please:&lt;/P&gt;&lt;P&gt;1. delete the &lt;STRONG&gt;/opt/cisco/anyconnect/profile/ISEPostureCFG.xml&lt;/STRONG&gt; file&lt;/P&gt;&lt;P&gt;2. connect again&lt;/P&gt;&lt;P&gt;3. double check if the &lt;STRONG&gt;Supplicant&lt;/STRONG&gt; is able to download the&amp;nbsp;&lt;STRONG&gt;ISEPostureCFG.xml&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 18:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281621#M565096</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-01-28T18:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 posturing MacOS installation issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281677#M565098</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually ISE 2.7 P2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ill try this and let you know what happen.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 19:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-posturing-macos-installation-issue/m-p/4281677#M565098</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2021-01-28T19:56:56Z</dc:date>
    </item>
  </channel>
</rss>

