<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Non Compliant PC but fw enabled in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4298513#M565760</link>
    <description>&lt;P&gt;Are all of the module versions and configuration the same across the board? Have you attempted to uninstall/reinstall on the troubled client?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Feb 2021 18:02:51 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2021-02-26T18:02:51Z</dc:date>
    <item>
      <title>Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4297715#M565715</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a pc that fails posture.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The condition it fails is firewall.&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Mandatory&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Failed&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;fw_enabled_v4_fw_ANY_ANY_ANY&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the pc though the fw is open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FWEnabled1.png" style="width: 584px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/105173iD38A1D58EE1BB22C/image-size/large?v=v2&amp;amp;px=999" role="button" title="FWEnabled1.png" alt="FWEnabled1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the DART I see errors like that&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2021/02/25 15:50:57 [Error] aciseagent Function: GetCurrentUserName Thread Id: 0xE10 File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\libcommoncpp\impersonateuser.cpp Line: 34 Level: error  Failed to find an active session.. 
2021/02/25 15:50:57 [Error] aciseagent Function: GetCurrentUserName Thread Id: 0xE10 File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\libcommoncpp\impersonateuser.cpp Line: 37 Level: error  Failed to find session after enumerating each session.. 
2021/02/25 15:50:57 [Warning] aciseagent Function: SwiftHttpRunner::timer_callback Thread Id: 0xE10 File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\libswift\swifthttprunner.cpp Line: 337 Level: warn  Failed to obtain loggedIn user info, aborting discovery.. &lt;BR /&gt;2021/02/25 16:15:29 [Error] nacapi Function: CNacApiShim::StatusNotification Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\nacshim.cpp Line: 232 Level: error StatusNotification invalid state. &lt;BR /&gt;2021/02/25 16:15:29 [Error] nacapi Function: CNacApiShim::StatusNotification Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\nacshim.cpp Line: 232 Level: error StatusNotification invalid state. &lt;BR /&gt;2021/02/25 16:15:29 [Error] nacapi Function: CNacApiShim::StatusNotification Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\nacshim.cpp Line: 232 Level: error StatusNotification invalid state. &lt;BR /&gt;2021/02/25 16:15:29 [Error] nacapi Function: CNacApiShim::StatusNotification Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\nacshim.cpp Line: 232 Level: error StatusNotification invalid state. &lt;BR /&gt;2021/02/25 16:36:37 [Error] nacapi Function: IpcWrap::_recv Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\ipcwrap.cpp Line: 106 Level: error Failed to read packet length: -6 - Connection Aborted. &lt;BR /&gt;2021/02/25 16:36:37 [Error] nacapi Function: IpcWrap::_recvThread Thread Id: 0x146C File: c:\temp\build\thehoff\negasonic_mr30.550195061902\negasonic_mr3\posture\ise\nacshim\ipcwrap.cpp Line: 342 Level: error _recv returned: -6 - Connection Aborted. &lt;/PRE&gt;&lt;P&gt;What might be wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 15:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4297715#M565715</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-25T15:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4297725#M565718</link>
      <description>&lt;P&gt;In my experience those conditions can be tricky.&amp;nbsp; Are you simply trying to ensure that clients have a local firewall enabled and running? If so, my suggestion would be to identify the target service within services and create a service condition.&amp;nbsp; For example, here is a service condition that checks to ensure McAfee HIPS is running:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="svc_cond.PNG" style="width: 364px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/105175i8ABA98953E51F39F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="svc_cond.PNG" alt="svc_cond.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 15:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4297725#M565718</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-02-25T15:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4298328#M565753</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually the condition is working fine for the rest of the PCs, but there is this one that while the fw is enabled ISE show that the condition is not met.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 12:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4298328#M565753</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-02-26T12:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4298513#M565760</link>
      <description>&lt;P&gt;Are all of the module versions and configuration the same across the board? Have you attempted to uninstall/reinstall on the troubled client?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 18:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4298513#M565760</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-02-26T18:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299168#M565792</link>
      <description>&lt;P&gt;Hello Mike,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;uninstall/reinstall did not change the result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This machine is Windows 8 the others are windows 10&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 06:11:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299168#M565792</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-03-01T06:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299536#M565815</link>
      <description>&lt;P&gt;Are you running the same AC module &amp;amp; compliance module versions on both the Win10 &amp;amp; Win8 clients? For the Win8 would it be possible to utilize another check that would meet the firewall check requirement? IMO you have other options.&amp;nbsp; However, your best bet may be to generate a DART bundle and engage with TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 19:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299536#M565815</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-01T19:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Non Compliant PC but fw enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299725#M565820</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The modules are the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will look into the different version of the rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have uploaded the DART and the errors from AnyConnect_ISEPosture.txt, but i do not recognize if they are relevant.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 06:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-compliant-pc-but-fw-enabled/m-p/4299725#M565820</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-03-02T06:11:20Z</dc:date>
    </item>
  </channel>
</rss>

