<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE posture VPN anyconnect module without using provisioning portal in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4388941#M566783</link>
    <description>&lt;P&gt;thx Mike. i have already tried in the past and aware of the ISE config requirements.. I am not sure if there are any recent enhancement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My feeling is that since posture agent required admin privileges etc, especially in the case of exiting anyconnect VPN users, doing CPP is cumbersome and may be difficult without admin privileges.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would personally think the following are much more cleaner:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;1) Install via anyconnect as module and requires no admin privileges&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 2) install using SMS, altiris etc to a machine thats already VPN connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would imagine that CPP would make more sense in case of BYOD or non-company owned machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i know with ISE 3.0 there is agentless module, but it looks like that also need admin privileges to run.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanted to know how others are deploying posture using CPP to download the posture module even for anyconnect VPN users ? or using the ISE posture vpn module from ASA/FTD headend ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Apr 2021 09:45:24 GMT</pubDate>
    <dc:creator>tomalexis</dc:creator>
    <dc:date>2021-04-18T09:45:24Z</dc:date>
    <item>
      <title>ISE posture VPN anyconnect module without using provisioning portal</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4387911#M566765</link>
      <description>&lt;P&gt;Howdy&lt;/P&gt;&lt;P&gt;I am trying to figure out the best option to install the ISE posture module for existing VPN anyconnect users ONLY.&amp;nbsp;&lt;/P&gt;&lt;P&gt;REading&amp;nbsp; the docs and samples, all of them show installing the profile / pkg on ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I feel thats more cumbersome especially without admin privileges etc ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wouldnt it be a lot easier if the ISE posture module was pushed down from ASA/headend with profile, and then only posture results are sent to ISE ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any plan for ISE to just push down the posture module when the redirect happens without any user intervention - kind of like how the ISE posture module gets installed from ASA ?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 04:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4387911#M566765</guid>
      <dc:creator>tomalexis</dc:creator>
      <dc:date>2021-04-16T04:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture VPN anyconnect module without using provisioning portal</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4388343#M566768</link>
      <description>&lt;P&gt;Adding my opinions:&lt;/P&gt;
&lt;P&gt;Wouldnt it be a lot easier if the ISE posture module was pushed down from ASA/headend with profile, and then only posture results are sent to ISE ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-You still have to have things built out in ISE for this solution to work.&amp;nbsp; The main pieces being the actual posture policies/requirements (what to assess) on the remote endpoints.&lt;/P&gt;
&lt;P&gt;Is there any plan for ISE to just push down the posture module when the redirect happens without any user intervention - kind of like how the ISE posture module gets installed from ASA ?&lt;/P&gt;
&lt;P&gt;-If clients have already been previously provisioned then the ISE webdeploy upgrade process is pretty much seamless IMO.&amp;nbsp; For those un-provisioned clients there is some user intervention required.&lt;/P&gt;
&lt;P&gt;Lastly, once you get a hang of relying on ISE CPP and posture configuration I truthfully like it &amp;amp; would recommend it.&amp;nbsp; From my experience the easiest deployment of all the required modules for this solution to work is the compliance module across any network type (vpn, wired, or wireless).&amp;nbsp; I would strongly suggest taking a peek at the following resources to understand structure &amp;amp; workflow.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture/ta-p/3657443" target="_blank"&gt;ISE Posture - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=6Kj8P8Hn7dY" target="_blank"&gt;Cisco ISE Posture Configuration Part 1 - Posture Conditions - YouTube&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.labminutes.com/video/sec" target="_blank"&gt;Video: Security | Lab Minutes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 12:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4388343#M566768</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-16T12:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture VPN anyconnect module without using provisioning portal</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4388941#M566783</link>
      <description>&lt;P&gt;thx Mike. i have already tried in the past and aware of the ISE config requirements.. I am not sure if there are any recent enhancement.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My feeling is that since posture agent required admin privileges etc, especially in the case of exiting anyconnect VPN users, doing CPP is cumbersome and may be difficult without admin privileges.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would personally think the following are much more cleaner:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;1) Install via anyconnect as module and requires no admin privileges&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; 2) install using SMS, altiris etc to a machine thats already VPN connected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would imagine that CPP would make more sense in case of BYOD or non-company owned machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i know with ISE 3.0 there is agentless module, but it looks like that also need admin privileges to run.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just wanted to know how others are deploying posture using CPP to download the posture module even for anyconnect VPN users ? or using the ISE posture vpn module from ASA/FTD headend ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 09:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-vpn-anyconnect-module-without-using-provisioning/m-p/4388941#M566783</guid>
      <dc:creator>tomalexis</dc:creator>
      <dc:date>2021-04-18T09:45:24Z</dc:date>
    </item>
  </channel>
</rss>

