<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Grace period configuration for non compliance endpoints in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392158#M566846</link>
    <description>&lt;P&gt;Dear Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will these non-compliant machines require full network access in that 8 hour window?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ans-: Yes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How much time user will get the Grace period notification that he/her was running in grace period ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can we configured that notification time in periodic manner ? For ex. In 8 hours of grace period, can user get grace period notification eight times i.e. for every hour ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;warm regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ishwar B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 12:41:39 GMT</pubDate>
    <dc:creator>IshwarBamane2910</dc:creator>
    <dc:date>2021-04-23T12:41:39Z</dc:date>
    <item>
      <title>Grace period configuration for non compliance endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392100#M566839</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;Need to configure grace period of 8 hr to non compliance endpoints,so that non compliance endpoint's user get time to make his/her system compliant as per the company policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to configure grace period ?&lt;/P&gt;&lt;P&gt;What is the best practice ?&lt;/P&gt;&lt;P&gt;Can we set the grace period notification in periodic manner so that user get to know he was running in grace period time ?&lt;/P&gt;&lt;P&gt;maximum how much time we can set the notification for grace period ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kindly help me with this ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;warm regards,&lt;/P&gt;&lt;P&gt;Ishwar B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 10:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392100#M566839</guid>
      <dc:creator>IshwarBamane2910</dc:creator>
      <dc:date>2021-04-23T10:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Grace period configuration for non compliance endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392149#M566844</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Need to configure grace period of 8 hr to non compliance endpoints,so that non compliance endpoint's user get time to make his/her system compliant as per the company policy.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Will these non-compliant machines require full network access in that 8 hour window? Why not consider setting the remediation timer longer (can be up to 5 hours) in the posture global settings?&amp;nbsp; In this window the client is neither compliant nor non-compliant yet.&amp;nbsp; Essentially it is still deemed unknown since the scan would still be going, and the "non-compliant" machines would be stuck on a missing check.&amp;nbsp; In this AnyConnect unknown state you could have a dacl limiting network access, but grant the ability to reach resources that would allow your clients a window to patch/remediate to become compliant.&amp;nbsp; Then if clients are unable to get compliant within the remediation allowed window, they then move into a Non-compliant state, which limits network access and at this point is deemed non-compliant per policy assessment (sitting in a quarantine restricted state).&amp;nbsp; Note that you have the ability to push a 'Scan Again' button feature via the ISEPostureCFG.xml that would allow end users to initiate the module probe to ISE.&amp;nbsp; This could allow a true non-compliant client/user the ability to initiate a re-scan without the need of a DFG change, or some other action to initiate the probe.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how to configure grace period ?&lt;/P&gt;
&lt;P&gt;-See here:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273#:~:text=Cisco%20ISE%20provides%20an%20option%20to%20configure%20a,the%20device%20is%20granted%20access%20to%20the%20network." target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What is the best practice ?&lt;/P&gt;
&lt;P&gt;-IMO this depends on your requirements and will vary per use case.&lt;/P&gt;
&lt;P&gt;maximum how much time we can set the notification for grace period ?&lt;/P&gt;
&lt;P&gt;-&lt;SPAN&gt;You can configure the grace period in minutes, hours, or days (up to a maximum of 30 days).&amp;nbsp; It is important to know that an endpoint is only able to utilize a grace period if they were previously deemed compliant.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 12:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392149#M566844</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-23T12:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Grace period configuration for non compliance endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392158#M566846</link>
      <description>&lt;P&gt;Dear Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will these non-compliant machines require full network access in that 8 hour window?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ans-: Yes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How much time user will get the Grace period notification that he/her was running in grace period ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can we configured that notification time in periodic manner ? For ex. In 8 hours of grace period, can user get grace period notification eight times i.e. for every hour ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;warm regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ishwar B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 12:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392158#M566846</guid>
      <dc:creator>IshwarBamane2910</dc:creator>
      <dc:date>2021-04-23T12:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Grace period configuration for non compliance endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392169#M566847</link>
      <description>&lt;P&gt;&lt;STRONG&gt;How much time user will get the Grace period notification that he/her was running in grace period ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-This is configurable within the posture policy under the 'Policy Options' column.&amp;nbsp; If you want to delay the notification you have the ability to select a specific percentage of the actual grace period before it actually notifies the user.&amp;nbsp; If you want the client/user to see that they are in the grace period immediately then leave the delay period at 0% (default setting).&amp;nbsp; Note that the grace period notification is never displayed if the endpoint is compliant.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of grace period notification: You set the grace period on a posture policy to 20 minutes, with a delayed notification of 50%.&amp;nbsp; In this configuration the client/user will not be notified until the 10 minute mark.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can we configured that notification time in periodic manner ? For ex. In 8 hours of grace period, can user get grace period notification eight times i.e. for every hour ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- AFAIK, no.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 12:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392169#M566847</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-23T12:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Grace period configuration for non compliance endpoints</title>
      <link>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392520#M566858</link>
      <description>&lt;P&gt;Hi Mike ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for information .&lt;/P&gt;</description>
      <pubDate>Sat, 24 Apr 2021 14:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/grace-period-configuration-for-non-compliance-endpoints/m-p/4392520#M566858</guid>
      <dc:creator>IshwarBamane2910</dc:creator>
      <dc:date>2021-04-24T14:54:52Z</dc:date>
    </item>
  </channel>
</rss>

