<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Wired posture problem in redirect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wired-posture-problem-in-redirect/m-p/4411151#M567634</link>
    <description>&lt;P&gt;There are a number of variables with Posture, so the switch configuration would not be enough information to provide guidance. As a starting point, I would suggest you review the following guides and compare them to your lab setup.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;ISE Posture Style Comparison for Pre and Post 2.2&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273#toc-hId-61739320" target="_blank" rel="noopener"&gt;ISE Posture Prescriptive Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are also some LabMinutes videos that walk through the redirect-based Posture flow in ISE 2.2:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.labminutes.com/video/sec/ISE" target="_blank" rel="noopener"&gt;https://www.labminutes.com/video/sec/ISE&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 May 2021 23:44:28 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-05-31T23:44:28Z</dc:date>
    <item>
      <title>ISE Wired posture problem in redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-posture-problem-in-redirect/m-p/4411142#M567632</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm doing a lab ISE/Posture to homologation for our customer, I'm having trouble redirecting the posture provisioning portal,&amp;nbsp;when I manually install the anyconnect posture module and add the .xml file in the "ISE Posture" folder, it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me please???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- ISE Version 2.4/Patch 14&lt;/P&gt;&lt;P&gt;- Anyconnect/NAM/Posture Version&amp;nbsp;4.9.04053&lt;/P&gt;&lt;P&gt;- Switch C3650 Version&amp;nbsp;16.12.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show run&lt;/P&gt;&lt;P&gt;SW_C3650#show run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 13034 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 21:19:41 UTC Mon May 31 2021 by admin&lt;BR /&gt;!&lt;BR /&gt;version 16.12&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service call-home&lt;BR /&gt;platform punt-keepalive disable-kernel-core&lt;BR /&gt;!&lt;BR /&gt;hostname SW_C3650&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vrf definition Mgmt-vrf&lt;BR /&gt;!&lt;BR /&gt;address-family ipv4&lt;BR /&gt;exit-address-family&lt;BR /&gt;!&lt;BR /&gt;address-family ipv6&lt;BR /&gt;exit-address-family&lt;BR /&gt;!&lt;BR /&gt;enable secret 9 $9$uYD0YKDDx80j5E$.Q1sxBhvnx63k53r.wy9dU8i8ZPTllB9C9n3Q02/PWY&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius GP_RADIUS&lt;BR /&gt;server name ISE&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group GP_RADIUS&lt;BR /&gt;aaa authorization network default group GP_RADIUS&lt;BR /&gt;aaa authorization auth-proxy default group GP_RADIUS&lt;BR /&gt;aaa accounting update newinfo periodic 1440&lt;BR /&gt;aaa accounting network default start-stop group GP_RADIUS&lt;BR /&gt;aaa accounting system default start-stop group GP_RADIUS&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 172.16.0.12 server-key cisco123&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;switch 1 provision ws-c3650-24ps&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;call-home&lt;BR /&gt;! If contact email address in call-home is configured as sch-smart-licensing@cisco.com&lt;BR /&gt;! the email address configured in Cisco Smart License Portal will be used as contact email address to send SCH notifications.&lt;BR /&gt;contact-email-addr sch-smart-licensing@cisco.com&lt;BR /&gt;profile "CiscoTAC-1"&lt;BR /&gt;active&lt;BR /&gt;destination transport-method http&lt;BR /&gt;no destination transport-method email&lt;BR /&gt;ip routing&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip domain name lab.local&lt;BR /&gt;ip dhcp excluded-address 172.16.0.1 172.16.0.100&lt;BR /&gt;ip dhcp excluded-address 172.16.1.1 172.16.1.100&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN11&lt;BR /&gt;network 172.16.0.0 255.255.255.0&lt;BR /&gt;default-router 172.16.0.158&lt;BR /&gt;dns-server 172.16.0.10&lt;BR /&gt;domain-name abc.local&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN12&lt;BR /&gt;network 172.16.1.0 255.255.255.0&lt;BR /&gt;default-router 172.16.1.158&lt;BR /&gt;dns-server 172.16.0.10&lt;BR /&gt;domain-name abc.local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;login on-success log&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;device-sensor filter-list dhcp list DSENSOR_DHCP&lt;BR /&gt;option name domain-name-servers&lt;BR /&gt;option name host-name&lt;BR /&gt;option name domain-name&lt;BR /&gt;option name requested-address&lt;BR /&gt;option name parameter-request-list&lt;BR /&gt;option name class-identifier&lt;BR /&gt;option name client-identifier&lt;BR /&gt;!&lt;BR /&gt;device-sensor filter-list lldp list DSENSOR_LLDP&lt;BR /&gt;tlv name system-name&lt;BR /&gt;tlv name system-description&lt;BR /&gt;tlv name system-capabilities&lt;BR /&gt;tlv name management-address&lt;BR /&gt;!&lt;BR /&gt;device-sensor filter-list cdp list DSENSOR_CDP&lt;BR /&gt;tlv name device-name&lt;BR /&gt;tlv name address-type&lt;BR /&gt;tlv name port-id-type&lt;BR /&gt;tlv name capabilities-type&lt;BR /&gt;tlv name version-type&lt;BR /&gt;tlv name platform-type&lt;BR /&gt;tlv name duplex-type&lt;BR /&gt;tlv number 34&lt;BR /&gt;device-sensor filter-spec dhcp include list DSENSOR_DHCP&lt;BR /&gt;device-sensor filter-spec lldp include list DSENSOR_LLDP&lt;BR /&gt;device-sensor filter-spec cdp include list DSENSOR_CDP&lt;BR /&gt;device-sensor accounting&lt;BR /&gt;device-sensor notify all-changes&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;epm logging&lt;BR /&gt;authentication mac-move permit&lt;BR /&gt;no device-tracking logging theft&lt;BR /&gt;device-tracking policy TRACKING&lt;BR /&gt;prefix-glean&lt;BR /&gt;no protocol ndp&lt;BR /&gt;no protocol dhcp6&lt;BR /&gt;no protocol udp&lt;BR /&gt;tracking enable&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol&lt;BR /&gt;license boot level ipservicesk9&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;diagnostic bootup level minimal&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode rapid-pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;memory free low-watermark processor 79475&lt;BR /&gt;!&lt;BR /&gt;username admin privilege 15 secret 9 $9$6OQYWT7M/bNVhU$8doFFwVZ.fnC01bMAd7BXUjp9vaNWPgEVu63yEh2bkk&lt;BR /&gt;!&lt;BR /&gt;redundancy&lt;BR /&gt;mode sso&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;transceiver type all&lt;BR /&gt;monitoring&lt;BR /&gt;lldp run&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map match-any system-cpp-police-topology-control&lt;BR /&gt;description Topology control&lt;BR /&gt;class-map match-any system-cpp-police-sw-forward&lt;BR /&gt;description Sw forwarding, L2 LVX data, LOGGING&lt;BR /&gt;class-map match-any system-cpp-default&lt;BR /&gt;description EWLC control, EWLC data, Inter FED&lt;BR /&gt;class-map match-any system-cpp-police-sys-data&lt;BR /&gt;description Learning cache ovfl, High Rate App, Exception, EGR Exception, NFL SAMPLED DATA, RPF Failed&lt;BR /&gt;class-map match-any system-cpp-police-punt-webauth&lt;BR /&gt;description Punt Webauth&lt;BR /&gt;class-map match-any system-cpp-police-l2lvx-control&lt;BR /&gt;description L2 LVX control packets&lt;BR /&gt;class-map match-any system-cpp-police-forus&lt;BR /&gt;description Forus Address resolution and Forus traffic&lt;BR /&gt;class-map match-any system-cpp-police-multicast-end-station&lt;BR /&gt;description MCAST END STATION&lt;BR /&gt;class-map match-any system-cpp-police-multicast&lt;BR /&gt;description Transit Traffic and MCAST Data&lt;BR /&gt;class-map match-any system-cpp-police-l2-control&lt;BR /&gt;description L2 control&lt;BR /&gt;class-map match-any system-cpp-police-dot1x-auth&lt;BR /&gt;description DOT1X Auth&lt;BR /&gt;class-map match-any system-cpp-police-data&lt;BR /&gt;description ICMP redirect, ICMP_GEN and BROADCAST&lt;BR /&gt;class-map match-any system-cpp-police-stackwise-virt-control&lt;BR /&gt;description Stackwise Virtual&lt;BR /&gt;class-map match-any non-client-nrt-class&lt;BR /&gt;class-map match-any system-cpp-police-routing-control&lt;BR /&gt;description Routing control and Low Latency&lt;BR /&gt;class-map match-any system-cpp-police-protocol-snooping&lt;BR /&gt;description Protocol snooping&lt;BR /&gt;class-map match-any system-cpp-police-dhcp-snooping&lt;BR /&gt;description DHCP snooping&lt;BR /&gt;class-map match-any system-cpp-police-system-critical&lt;BR /&gt;description System Critical and Gold Pkt&lt;BR /&gt;!&lt;BR /&gt;policy-map system-cpp-policy&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;vrf forwarding Mgmt-vrf&lt;BR /&gt;ip address 172.16.14.159 255.255.255.0&lt;BR /&gt;negotiation auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy TRACKING&lt;BR /&gt;ip access-group PRE_AUTHE in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan11&lt;BR /&gt;ip address 172.16.0.158 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;ip address 172.16.1.158 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan14&lt;BR /&gt;ip address 172.16.14.158 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan15&lt;BR /&gt;ip address 172.16.15.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan99&lt;BR /&gt;ip address 192.168.77.158 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip http server&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http secure-active-session-modules none&lt;BR /&gt;ip http active-session-modules none&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 172.16.15.1&lt;BR /&gt;ip route vrf Mgmt-vrf 0.0.0.0 0.0.0.0 172.16.14.158&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended PRE_AUTHE&lt;BR /&gt;10 permit udp any any eq bootps&lt;BR /&gt;20 permit udp any any eq bootpc&lt;BR /&gt;30 permit udp any any eq domain&lt;BR /&gt;40 permit ip any host 172.16.0.12&lt;BR /&gt;50 permit ip any host 172.16.0.10&lt;BR /&gt;60 deny ip any any&lt;BR /&gt;ip access-list extended UNKNOWN&lt;BR /&gt;10 deny udp any any eq bootps&lt;BR /&gt;20 deny udp any any eq bootpc&lt;BR /&gt;30 deny udp any any eq domain&lt;BR /&gt;40 deny ip any host 172.16.0.12&lt;BR /&gt;50 permit ip any any&lt;BR /&gt;!&lt;BR /&gt;ip radius source-interface Vlan11&lt;BR /&gt;ip access-list standard 1&lt;BR /&gt;10 permit any&lt;BR /&gt;ip access-list standard 2&lt;BR /&gt;10 deny any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf upper-case&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;radius-server dead-criteria time 30 tries 15&lt;BR /&gt;radius-server retransmit 5&lt;BR /&gt;radius-server timeout 7&lt;BR /&gt;radius-server deadtime 30&lt;BR /&gt;!&lt;BR /&gt;radius server ISE&lt;BR /&gt;address ipv4 172.16.0.12 auth-port 1645 acct-port 1646&lt;BR /&gt;key cisco123&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;service-policy input system-cpp-policy&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;stopbits 1&lt;BR /&gt;line aux 0&lt;BR /&gt;stopbits 1&lt;BR /&gt;line vty 0 4&lt;BR /&gt;login authentication LOCAL&lt;BR /&gt;line vty 5 15&lt;BR /&gt;login authentication LOCAL&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mac address-table notification change&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===================================================&lt;/P&gt;&lt;P&gt;SW_C3650#show authentication sessions interface gigabitEthernet 1/0/1 details&lt;BR /&gt;Interface: GigabitEthernet1/0/1&lt;BR /&gt;IIF-ID: 0x1B57FDDD&lt;BR /&gt;MAC Address: 18d6.c71f.196e&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.16.1.101&lt;BR /&gt;User-Name: user01&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC10009E0000000DC4812006&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x11000003&lt;BR /&gt;Current Policy: POLICY_Gi1/0/1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecured&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: 12&lt;BR /&gt;URL Redirect ACL: UNKNOWN&lt;BR /&gt;URL Redirect: &lt;A href="https://lab-ise001.abc.local:8443/portal/gateway?sessionId=AC10009E0000000DC4812006&amp;amp;portal=40f01bd0-2e02-11e8-ba71-005056872c7f&amp;amp;action=cpp&amp;amp;token=0307268d7ed20b2d3597a92cff9fed0f" target="_blank" rel="noopener"&gt;https://lab-ise001.abc.local:8443/portal/gateway?sessionId=AC10009E0000000DC4812006&amp;amp;portal=40f01bd0-2e02-11e8-ba71-005056872c7f&amp;amp;action=cpp&amp;amp;token=0307268d7ed20b2d3597a92cff9fed0f&lt;/A&gt;&lt;BR /&gt;ACS ACL: xACSACLx-IP-DACL_UNKNOWN-60b3ca7a&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;dot1x Authc Success&lt;/P&gt;&lt;P&gt;SW_C3650#&lt;/P&gt;&lt;P&gt;SW_C3650#show ip access-lists UNKNOWN&lt;/P&gt;&lt;P&gt;Extended IP access list UNKNOWN&lt;BR /&gt;10 deny udp any any eq bootps&lt;BR /&gt;20 deny udp any any eq bootpc&lt;BR /&gt;30 deny udp any any eq domain&lt;BR /&gt;40 deny ip any host 172.16.0.12&lt;BR /&gt;50 permit ip any any&lt;BR /&gt;SW_C3650#&lt;/P&gt;&lt;P&gt;SW_C3650#show ip access-lists xACSACLx-IP-DACL_UNKNOWN-60b3ca7a&lt;BR /&gt;Extended IP access list xACSACLx-IP-DACL_UNKNOWN-60b3ca7a&lt;BR /&gt;1 permit udp any any eq domain&lt;BR /&gt;2 permit udp any any eq bootps&lt;BR /&gt;3 permit udp any any eq bootpc&lt;BR /&gt;5 permit ip any host 172.16.0.12&lt;BR /&gt;7 deny icmp any host 172.16.0.10&lt;BR /&gt;8 deny ip any any&lt;BR /&gt;SW_C3650#&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 23:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-posture-problem-in-redirect/m-p/4411142#M567632</guid>
      <dc:creator>Claudio L. de Matos Jr</dc:creator>
      <dc:date>2021-05-31T23:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Wired posture problem in redirect</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wired-posture-problem-in-redirect/m-p/4411151#M567634</link>
      <description>&lt;P&gt;There are a number of variables with Posture, so the switch configuration would not be enough information to provide guidance. As a starting point, I would suggest you review the following guides and compare them to your lab setup.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;ISE Posture Style Comparison for Pre and Post 2.2&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273#toc-hId-61739320" target="_blank" rel="noopener"&gt;ISE Posture Prescriptive Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are also some LabMinutes videos that walk through the redirect-based Posture flow in ISE 2.2:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.labminutes.com/video/sec/ISE" target="_blank" rel="noopener"&gt;https://www.labminutes.com/video/sec/ISE&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 23:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wired-posture-problem-in-redirect/m-p/4411151#M567634</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-05-31T23:44:28Z</dc:date>
    </item>
  </channel>
</rss>

