<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE VPN posture with ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/3174902#M56844</link>
    <description>&lt;P&gt;Not using ACS, its all ISE/RADIUS now in this enviroment, but the dACL was originally imported from ACS. The dACL that ISE pushes to the ASA for the VPN session needs to use subnet mask format instead of wildcard format for dACL lines that reference networks.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Aug 2017 20:36:28 GMT</pubDate>
    <dc:creator>snicklas</dc:creator>
    <dc:date>2017-08-23T20:36:28Z</dc:date>
    <item>
      <title>Cisco ISE VPN posture with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780577#M56835</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We have a ISE 1.4 deployment in which we are doing posture assessment for VPN users connecting through ASA version 9.3(3). users are connecting normally , authentication and authorization are done succesffuly , however, when nac agent pops up anyconnect vpn client disconnects and the following message appears :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;The secure gateway has terminated the VPN connection.&lt;BR /&gt;The following message was received from the secure gateway: COA initiated&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;How could we keep the CoA initiation from disconnecting VPN client.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Appreciate your help ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Muayad Jallad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780577#M56835</guid>
      <dc:creator>M.Jallad</dc:creator>
      <dc:date>2019-03-11T06:12:39Z</dc:date>
    </item>
    <item>
      <title>Hi ,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780578#M56839</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;Just wanted to update that problem was resolved successfully , it was TACACS command authorization defined on ASA that was preventing the DACL from being configured on ASA which was triggering anyconnect VPN termination.&lt;/P&gt;
&lt;P&gt;it was resolved after configuring device administration autorization policy on ACS to give ISE authorization on ASA.&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Muayad Jallad,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 15:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780578#M56839</guid>
      <dc:creator>M.Jallad</dc:creator>
      <dc:date>2015-11-03T15:47:21Z</dc:date>
    </item>
    <item>
      <title>Hello Muayad,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780579#M56841</link>
      <description>&lt;P&gt;Hello Muayad,&lt;/P&gt;
&lt;P&gt;May I ask if this has affected all or just one of your anyconnect users?&lt;/P&gt;
&lt;P&gt;I have a similar issue but just on one user.&lt;/P&gt;
&lt;P&gt;Any advice is greatly appreciated.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Jem&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 10:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/2780579#M56841</guid>
      <dc:creator>santiago.jem</dc:creator>
      <dc:date>2016-04-27T10:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE VPN posture with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/3174902#M56844</link>
      <description>&lt;P&gt;Not using ACS, its all ISE/RADIUS now in this enviroment, but the dACL was originally imported from ACS. The dACL that ISE pushes to the ASA for the VPN session needs to use subnet mask format instead of wildcard format for dACL lines that reference networks.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 20:36:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vpn-posture-with-asa/m-p/3174902#M56844</guid>
      <dc:creator>snicklas</dc:creator>
      <dc:date>2017-08-23T20:36:28Z</dc:date>
    </item>
  </channel>
</rss>

