<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Posture no policy server detected in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312996#M566390</link>
    <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to&amp;nbsp; use DART and get some log and I see about why client request http to gateway&amp;nbsp; *192.168.10.1* of client not request URL from redirect from ISE authorization.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;======================================================================&lt;/P&gt;&lt;P&gt;2021/03/24 17:00:35 [Information] aciseagent Function: Target::fetchPostureStatus Thread Id: 0x644 File: target.cpp Line: 407 Level: debug POST request to URL (&lt;A href="https://enroll.cisco.com:8905/auth/ng-discovery" target="_blank"&gt;https://enroll.cisco.com:8905/auth/ng-discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:35 [Information] aciseagent Function: Target::Probe Thread Id: 0x644 File: target.cpp Line: 201 Level: debug Status of Ng-Discovery target enroll.cisco.com with path /auth/ng-discovery is 6 &amp;lt;Not Reachable.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: hs_transport_winhttp_get Thread Id: 0x1664 File: hs_transport_winhttp.c Line: 4808 Level: debug unable to send request: 12002.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::probeDiscoveryUrl Thread Id: 0x1664 File: target.cpp Line: 250 Level: debug GET request to URL (&lt;A href="http://192.168.10.1/auth/discovery" target="_blank"&gt;http://192.168.10.1/auth/discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::Probe Thread Id: 0x1664 File: target.cpp Line: 201 Level: debug Status of Redirection target 192.168.10.1 is 6 &amp;lt;Not Reachable.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: hs_transport_winhttp_get Thread Id: 0xDDC File: hs_transport_winhttp.c Line: 4808 Level: debug unable to send request: 12002.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::probeDiscoveryUrl Thread Id: 0xDDC File: target.cpp Line: 250 Level: debug GET request to URL (&lt;A href="http://192.168.20.1/auth/discovery" target="_blank"&gt;http://192.168.20.1/auth/discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 10:57:57 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2021-03-24T10:57:57Z</dc:date>
    <item>
      <title>Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312962#M566387</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;I found the the issue&amp;nbsp;ISE Posture no policy server detected . I try to find the topic on community and found the same issue with me but I try to many method to fix the issue example . fix&amp;nbsp; discovery host / call-home list . but still facing the issue .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Noted : I configure ASAv for Anyconnect VPN&amp;nbsp; with ISE Posture .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise me .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="123.JPG" style="width: 354px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/107102i78BAE71D1DC1721A/image-size/large?v=v2&amp;amp;px=999" role="button" title="123.JPG" alt="123.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 09:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312962#M566387</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-03-24T09:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312994#M566389</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;FYI :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-no-policy-server-detected/td-p/3883122" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-no-policy-server-detected/td-p/3883122&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 10:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312994#M566389</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-24T10:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312996#M566390</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to&amp;nbsp; use DART and get some log and I see about why client request http to gateway&amp;nbsp; *192.168.10.1* of client not request URL from redirect from ISE authorization.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;======================================================================&lt;/P&gt;&lt;P&gt;2021/03/24 17:00:35 [Information] aciseagent Function: Target::fetchPostureStatus Thread Id: 0x644 File: target.cpp Line: 407 Level: debug POST request to URL (&lt;A href="https://enroll.cisco.com:8905/auth/ng-discovery" target="_blank"&gt;https://enroll.cisco.com:8905/auth/ng-discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:35 [Information] aciseagent Function: Target::Probe Thread Id: 0x644 File: target.cpp Line: 201 Level: debug Status of Ng-Discovery target enroll.cisco.com with path /auth/ng-discovery is 6 &amp;lt;Not Reachable.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: hs_transport_winhttp_get Thread Id: 0x1664 File: hs_transport_winhttp.c Line: 4808 Level: debug unable to send request: 12002.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::probeDiscoveryUrl Thread Id: 0x1664 File: target.cpp Line: 250 Level: debug GET request to URL (&lt;A href="http://192.168.10.1/auth/discovery" target="_blank"&gt;http://192.168.10.1/auth/discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::Probe Thread Id: 0x1664 File: target.cpp Line: 201 Level: debug Status of Redirection target 192.168.10.1 is 6 &amp;lt;Not Reachable.&amp;gt;.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: hs_transport_winhttp_get Thread Id: 0xDDC File: hs_transport_winhttp.c Line: 4808 Level: debug unable to send request: 12002.&lt;BR /&gt;2021/03/24 17:00:37 [Information] aciseagent Function: Target::probeDiscoveryUrl Thread Id: 0xDDC File: target.cpp Line: 250 Level: debug GET request to URL (&lt;A href="http://192.168.20.1/auth/discovery" target="_blank"&gt;http://192.168.20.1/auth/discovery&lt;/A&gt;), returned status -1 &amp;lt;Operation Failed.&amp;gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 10:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312996#M566390</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-03-24T10:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312998#M566391</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to following this topic but still facing the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 10:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4312998#M566391</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-03-24T10:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313034#M566395</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I found the the issue&amp;nbsp;ISE Posture no policy server detected . I try to find the topic on community and found the same issue with me but I try to many method to fix the issue example . fix&amp;nbsp; discovery host / call-home list . but still facing the issue .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A few items to check that typically cause this issue:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Are you attempting to redirect or do redirection-less posturing?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-If redirecting are you allowing connectivity to Portal in dacl?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-If no redirect, do you have an ISEPostureCFG.xml here&amp;nbsp;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture? Without redirect setup OR no ISEPostureCFG file this notice appears in AC UI.&amp;nbsp; The redirect will allow you to hit provisioning portal in which ISE will then push down the respective XML files to unprovisioned/new clients.&amp;nbsp; For redirection-less provisioning use the profile editor and either manually deploy the file to unprovisioned clients OR rely on SCCM maybe.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;See here for guide:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 12:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313034#M566395</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-24T12:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313523#M566411</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Are you attempting to redirect or do redirection-less posturing?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;You mean try to manual url: &lt;A href="https://ip-ise:8443" target="_blank"&gt;https://ip-ise:8443&lt;/A&gt;&amp;nbsp;or not ?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-If redirecting are you allowing connectivity to Portal in dacl?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; I not configure dacl on ise&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 02:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313523#M566411</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-03-25T02:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture no policy server detected</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313805#M566419</link>
      <description>&lt;P&gt;You mean try to manual url: &lt;A href="https://ip-ise:8443" target="_blank" rel="nofollow noopener noreferrer"&gt;https://ip-ise:8443&lt;/A&gt;&amp;nbsp;or not ?&lt;/P&gt;
&lt;P&gt;-No.&amp;nbsp; What I meant was that you dont necessarily have to have the portal redirect in order for posture to work.&amp;nbsp; You can pre-deploy the ISEPostureCFG.xml file to clients so that the module is able to reach ISE without the need of redirect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I not configure dacl on ise&lt;/P&gt;
&lt;P&gt;-I assume if testing/using redirect that in your ISE authz profile you have the portal assigned with a dacl to assign to sessions.&lt;/P&gt;
&lt;P&gt;I would recommend taking a peek at the link I shared above to understand options/workflows.&amp;nbsp; Also, have a peek at labminutes.com/video/sec for free tutorials. HTH!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 13:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-no-policy-server-detected/m-p/4313805#M566419</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-25T13:23:34Z</dc:date>
    </item>
  </channel>
</rss>

