<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help on NAC for VPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4321200#M566691</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/80617"&gt;@User_80617&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authorization &amp;gt; Authorization Profiles &amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;Authorization Profile&lt;/STRONG&gt;&amp;nbsp;that you use in your "&lt;EM&gt;Unknown Policy Set&lt;/EM&gt;" and at &lt;STRONG&gt;Common Task&lt;/STRONG&gt;, double check your &lt;STRONG&gt;Web Redirection&lt;/STRONG&gt; configuration.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;Double check if the name of the&amp;nbsp;&lt;STRONG&gt;ACL&lt;/STRONG&gt;&amp;nbsp;(located on the &lt;STRONG&gt;Web Redirection&lt;/STRONG&gt; configuration) must exist on your &lt;STRONG&gt;ASA&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 19:49:11 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-04-09T19:49:11Z</dc:date>
    <item>
      <title>Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310391#M566290</link>
      <description>&lt;P&gt;Hello Guys, Need you help. This will be a long post and i need help in deployment of NAC for vpn users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement is user shall connect to vpn post some checks that defined on Cisco ISE.&lt;/P&gt;&lt;P&gt;1. What config needed on Cisco ASA&lt;/P&gt;&lt;P&gt;2. What config needed on Cisco ISE&lt;/P&gt;&lt;P&gt;3. Any config related to hostscan, posturing needs to be on Cisco asa?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need suggesting on parameters to test and things to ensure before rolling out in production.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 12:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310391#M566290</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-03-19T12:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310401#M566291</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/80617"&gt;@User_80617&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the official Cisco ASA RAVPN and ISE Posture guide, this covers the ASA and ISE config.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to use Hostscan if you are doing posture on ISE.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 13:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310401#M566291</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-03-19T13:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310402#M566292</link>
      <description>&lt;P&gt;This not just few steps, this required some kind of integration expert to imlement things in step by step approach - no from day 0.&lt;/P&gt;
&lt;P&gt;you need put some time and understand how these each components works,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/nac/ta-p/3114257" target="_blank"&gt;https://community.cisco.com/t5/security-documents/nac/ta-p/3114257&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is some resource to start with :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE Community Resources&lt;/P&gt;
&lt;P&gt;&lt;A href="http://cs.co/ise-resources" target="_blank"&gt;http://cs.co/ise-resources&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;YouTube Channel: &lt;A href="http://cs.co/ise-videos" target="_blank"&gt;http://cs.co/ise-videos&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Integration Guides: &lt;A href="http://cs.co/ise-guides" target="_blank"&gt;http://cs.co/ise-guides&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 13:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310402#M566292</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-03-19T13:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310405#M566293</link>
      <description>&lt;P&gt;Also, take a peek at &lt;A href="https://labminutes.com/video/sec" target="_blank"&gt;https://labminutes.com/video/sec&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Good free tutorials there.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 13:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4310405#M566293</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-19T13:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311212#M566341</link>
      <description>&lt;P&gt;Hi.. Thanks for revert. But, this didn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compliance module says no policy server detected and user gets access even after required components missing on his endpoint.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 05:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311212#M566341</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-03-22T05:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311356#M566346</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/80617"&gt;@User_80617&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;at &lt;STRONG&gt;Operations &amp;gt; RADIUS &amp;gt; Live Logs&lt;/STRONG&gt;, check the &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt; of this particular &lt;STRONG&gt;Identity&lt;/STRONG&gt; (user).&lt;/P&gt;&lt;P&gt;&amp;nbsp;Use this information and double check at &lt;STRONG&gt;Policy &amp;gt; Policy Set&lt;/STRONG&gt; if it should be the correct &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 10:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311356#M566346</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-22T10:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311396#M566350</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Compliance module says no policy server detected and user gets access even after required components missing on his endpoint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-This is typically because your module is missing the respective posture profile xml files.&amp;nbsp; The URL redirect should point a new/unprovisioned client to your portal in which ISE will then push down your configured profiles/modules/etc.&amp;nbsp; Another option you could test is manually adding the profiles to your test client.&amp;nbsp; I suspect this may be a missing piece as well as how you have your client provisioning portal setup.&amp;nbsp; That guide shared definitely covers the necessary steps involved.&amp;nbsp; However, its screenshots/demos are from a very old version of ISE.&amp;nbsp; I would suggest taking a look at some lab tutorials from links already shared in this post as well as having a look here:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4311396#M566350</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-22T12:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4320972#M566682</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;below were the live logs output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001 Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;11017 RADIUS created a new session&lt;/P&gt;&lt;P&gt;15049 Evaluating Policy Group&lt;/P&gt;&lt;P&gt;15008 Evaluating Service Selection Policy&lt;/P&gt;&lt;P&gt;15048 Queried PIP - Network Access.NetworkDeviceName&lt;/P&gt;&lt;P&gt;24715 ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/P&gt;&lt;P&gt;15036 Evaluating Authorization Policy&lt;/P&gt;&lt;P&gt;24209 Looking up Endpoint in Internal Endpoints IDStore - xxxxx&lt;/P&gt;&lt;P&gt;24211 Found Endpoint in Internal Endpoints IDStore&lt;/P&gt;&lt;P&gt;15048 Queried PIP - Session.PostureStatus&lt;/P&gt;&lt;P&gt;15016 Selected Authorization Profile ASA-Posture&lt;/P&gt;&lt;P&gt;22081 Max sessions policy passed&lt;/P&gt;&lt;P&gt;22080 New accounting session created in Session cache&lt;/P&gt;&lt;P&gt;11002 Returned RADIUS Access-Accept&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authorization Policy Posture_Policy &amp;gt;&amp;gt; Posture_Unknown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authorization Result ASA-redirect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA_redirect should direct user to ise but compliance is failing. Even posture unknow status shall get access rejected (Access Type = ACCESS_REJECT) but user can successfully connect to vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be wrong. Followed the cisco config document as it is.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:35:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4320972#M566682</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-04-09T12:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4321200#M566691</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/80617"&gt;@User_80617&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Authorization &amp;gt; Authorization Profiles &amp;gt;&lt;/STRONG&gt; select the &lt;STRONG&gt;Authorization Profile&lt;/STRONG&gt;&amp;nbsp;that you use in your "&lt;EM&gt;Unknown Policy Set&lt;/EM&gt;" and at &lt;STRONG&gt;Common Task&lt;/STRONG&gt;, double check your &lt;STRONG&gt;Web Redirection&lt;/STRONG&gt; configuration.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;Double check if the name of the&amp;nbsp;&lt;STRONG&gt;ACL&lt;/STRONG&gt;&amp;nbsp;(located on the &lt;STRONG&gt;Web Redirection&lt;/STRONG&gt; configuration) must exist on your &lt;STRONG&gt;ASA&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 19:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4321200#M566691</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-09T19:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4395959#M567014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The posturing now works ok. but i have 2 queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. It works only when the ise -posture/compliance module is installed on the system. In case when connected from a system having only anyconnect client, vpn gets connected.&lt;/P&gt;&lt;P&gt;2. What should be settings on cisco ise, if i want to apply the posturing, client provisioning only for a certain vpn profile on a perticular asa (there might be many other profiles coming to ise for authentication)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need some help on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 09:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4395959#M567014</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-04-30T09:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Need help on NAC for VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4396291#M567026</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/80617"&gt;@User_80617&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;you are able to use the &lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/P&gt;&lt;PRE&gt;Cisco-VPN3000-CVPN3000/ASA/PIX7x-Tunnel-Group-Name &lt;EM&gt;equals &lt;U&gt;&amp;lt;Tunnel Group&amp;gt;&lt;/U&gt;&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;or/and&lt;/P&gt;&lt;PRE&gt;DEVICE.Location &lt;EM&gt;equals&lt;/EM&gt; All Locations#&lt;U&gt;&lt;EM&gt;&amp;lt;Location&amp;gt;&lt;/EM&gt;&lt;/U&gt;&lt;/PRE&gt;&lt;P&gt;Note: remember to add your &lt;STRONG&gt;ASA&lt;/STRONG&gt; to the &lt;U&gt;&lt;EM&gt;&amp;lt;Location&amp;gt;&lt;/EM&gt;&lt;/U&gt; at &lt;STRONG&gt;Administration &amp;gt; Network Resources &amp;gt; Network Devices&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-help-on-nac-for-vpn/m-p/4396291#M567026</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-30T18:59:22Z</dc:date>
    </item>
  </channel>
</rss>

