<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about DACLS on ISE with AnyConnect Posture Checks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4404619#M567357</link>
    <description>&lt;P&gt;Good afternoon. I'm working to understand more about DACLs using Cisco ISE to perform posture checks against our AnyConnect vpn clients. I understand I need to create a few different DACLs to allow/deny traffic based on the posture checks we create. In reference to the DACLs, do they actually get configured on the Cisco ASA firewall as an ACL? More so does any configuration get add/removed/updated on the Cisco ASA by ISE? For the DACLS that I create, do I need to create the same ACLs on the ASA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx in advance for any assistance given.&lt;/P&gt;</description>
    <pubDate>Tue, 18 May 2021 13:01:42 GMT</pubDate>
    <dc:creator>hurricane05</dc:creator>
    <dc:date>2021-05-18T13:01:42Z</dc:date>
    <item>
      <title>Question about DACLS on ISE with AnyConnect Posture Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4404619#M567357</link>
      <description>&lt;P&gt;Good afternoon. I'm working to understand more about DACLs using Cisco ISE to perform posture checks against our AnyConnect vpn clients. I understand I need to create a few different DACLs to allow/deny traffic based on the posture checks we create. In reference to the DACLs, do they actually get configured on the Cisco ASA firewall as an ACL? More so does any configuration get add/removed/updated on the Cisco ASA by ISE? For the DACLS that I create, do I need to create the same ACLs on the ASA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx in advance for any assistance given.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 13:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4404619#M567357</guid>
      <dc:creator>hurricane05</dc:creator>
      <dc:date>2021-05-18T13:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about DACLS on ISE with AnyConnect Posture Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4405364#M567380</link>
      <description>&lt;P&gt;&lt;SPAN&gt;In reference to the DACLs, do they actually get configured on the Cisco ASA firewall as an ACL?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-For client provisioning web redirection, yes.&amp;nbsp; You would configure the ACL on the FW, and then inside the authz profile select Web Redirection for posturing and paste in the ACL name so that the ASA knows what ACL to apply.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More so does any configuration get add/removed/updated on the Cisco ASA by ISE? For the DACLS that I create, do I need to create the same ACLs on the ASA?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-ISE will send the remaining DACLs for compliant or noncompliant states to the ASA.&amp;nbsp; These DACLs are created in ISE and do not need to be on the ASA.&amp;nbsp; Just create them in ISE, and assign to compliant/noncompliant authz profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A few oldies, but goodies:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html#anc7" target="_blank"&gt;ASA Version 9.2.1 VPN Posture with ISE Configuration Example - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ise-and-asa-integration-using-coa-for-posture/ta-p/3630938" target="_blank"&gt;How To: ISE and ASA Integration using CoA for Posture - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 12:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4405364#M567380</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-05-19T12:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question about DACLS on ISE with AnyConnect Posture Checks</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4405390#M567381</link>
      <description>&lt;P&gt;Thx for the feedback!!!&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 12:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-dacls-on-ise-with-anyconnect-posture-checks/m-p/4405390#M567381</guid>
      <dc:creator>hurricane05</dc:creator>
      <dc:date>2021-05-19T12:49:13Z</dc:date>
    </item>
  </channel>
</rss>

