<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE posture setup in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456854#M569345</link>
    <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;I have installed the ISE posture agent manually and I have the same problem.&lt;/P&gt;&lt;P&gt;I have also created a profile with the tool "ISE Posture Profile Editor" I have saved it with the name ISEPostureCFG.xml and I have saved it in the path %program data%\Cisco\Cisco AnyConnect Secure Mobility Client \ISE Posture\ but it does not work for me .&lt;/P&gt;&lt;P&gt;Seeing your answer I have created the Anyconnect Posture Profile in Cisco ISE, how can I download it to copy it to the path you indicate?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Aug 2021 10:54:59 GMT</pubDate>
    <dc:creator>albertofdez</dc:creator>
    <dc:date>2021-08-30T10:54:59Z</dc:date>
    <item>
      <title>ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456197#M569323</link>
      <description>&lt;P&gt;I am having issues getting ISE posturing to work.&amp;nbsp; Had issues with the client and tried to set it up in the lab and still can't get it to work right.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Using an older windows 7 laptop with Anyconnect and the ISE posture module installed (4.10).&amp;nbsp; Switch is a 9300 with basically the template from ise-support.com for denali+.&amp;nbsp; ISE server is setup from cisco videos where I have an initial policy for "unknown posture" doing a ISE posture redirect and then my other rules (which work without posturing) looking at user is in a certain group and put them in this VLAN I added posture compliant to the rule.&amp;nbsp; I do have a basic posture policy setup just looking for windows firewall is enabled.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I see when I connect is the windows laptop goes to "trying to authenticate".&amp;nbsp; Switch very quickly shows dot1x succeeded on access-session but shows nothing at this time on the redirect.&amp;nbsp; Posture anyconnect module kicks in and says searching for policy server.&amp;nbsp; &amp;nbsp;Nothing changes on either side.&amp;nbsp; Eventually posture module switches back to "cannot find policy server" and windows shows "Authentication Failed".&amp;nbsp; At this point the switch access-session starts showing the redirect.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;On the logs on the ISE server I do initially see the 802.1X success message with posture "unknown" and then a series of failures saying did not receive all the radius information expected.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I think my issue is getting the posture module to talk to ISE and download the posture policy on a new setup when it hasn't talked to the policy server previously.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any ideas?&amp;nbsp; What is the best way to get a new install to connect to ISE from the anyconnect module and get the posture policy?&amp;nbsp; I thought that is what the redirect was supposed to do but that doesn't seem to be sent (according to the switch) until after the posture module has stopped searching.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I know I'm missing something simple in this whole flow.&amp;nbsp; and yes this is using new-format switch configs with service policy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 06:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456197#M569323</guid>
      <dc:creator>bhartsfield</dc:creator>
      <dc:date>2022-03-10T06:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456307#M569324</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Do you have ISEPostureCFG.xml in the client machine at the path %program&lt;BR /&gt;data%\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture\&lt;BR /&gt;&lt;BR /&gt;If you are deploying a posture agent manually or using SCCM, for example,&lt;BR /&gt;the XML file should be created in ISE server, downloaded to your machine&lt;BR /&gt;and copied to your clients at this path. If you are using client&lt;BR /&gt;provisioning portal to install posture agent, then XML will downloaded to&lt;BR /&gt;clients part of posture agent installation.&lt;BR /&gt;&lt;BR /&gt;Try this and if all required ports are allowed between clients and PSN,&lt;BR /&gt;discovery process will work.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sat, 28 Aug 2021 13:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456307#M569324</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-08-28T13:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456385#M569328</link>
      <description>&lt;P&gt;Appreciate your reply.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So I think I was under the understanding that an "unknown posture" redirect would then direct the anyconnect posture client to download the ISE posture config.&amp;nbsp; &amp;nbsp;Was that an incorrect assumption?&amp;nbsp; I don't want to mess with the portal since we are rolling this out to a large enterprise so in that case my best option is push the xml out with the posture module?&lt;BR /&gt;&lt;BR /&gt;So, how do I get this&amp;nbsp; ISEPostureCFG.xml file?&amp;nbsp; I have configured all the anyconect profiles and all that in ISE but where do I go to download this config?&lt;BR /&gt;&lt;BR /&gt;First time dealing with posturing so sorry for the what are probbaly easy questions.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 02:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456385#M569328</guid>
      <dc:creator>bhartsfield</dc:creator>
      <dc:date>2021-08-29T02:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456399#M569329</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You need to download AnyConnect Profile Editor from Cisco website. Once&lt;BR /&gt;installed, it will install AnyConnect Profile Editor - ISE Posture. From&lt;BR /&gt;there you can create the XML file. Then you push it to your clients.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sun, 29 Aug 2021 04:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456399#M569329</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-08-29T04:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456520#M569330</link>
      <description>&lt;P&gt;As mentioned you do need that xml file which will contain settings that the module will use.&amp;nbsp;&amp;nbsp; Adding an additional option besides the third party push &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt; mentioned, which btw his way is 100% a legitimate option.&amp;nbsp; Another option, which I think you were alluding to, is the ability for ISE to push the file via CPP (client provisioning portal).&amp;nbsp; In order to accomplish this you will need to setup an AnyConnect Profile, create the ISEPostureCFG.xml using the editor mentioned, and upload the xml file in ISE.&amp;nbsp; Or you can simply create the posture config file in ISE too.&amp;nbsp; Then whichever way you choose, add the xml file inside your AnyConnect Config profile that then gets assigned as your result inside of your CPP policy.&amp;nbsp; Then when clients connect, sits in unknown state at first, it should get redirected to CPP, ISE should push down the profile to the respective client.&amp;nbsp; Lastly, the posture profile is added under the profile selection section inside the AnyConnect Config profile.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 14:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456520#M569330</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-08-29T14:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456854#M569345</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;I have installed the ISE posture agent manually and I have the same problem.&lt;/P&gt;&lt;P&gt;I have also created a profile with the tool "ISE Posture Profile Editor" I have saved it with the name ISEPostureCFG.xml and I have saved it in the path %program data%\Cisco\Cisco AnyConnect Secure Mobility Client \ISE Posture\ but it does not work for me .&lt;/P&gt;&lt;P&gt;Seeing your answer I have created the Anyconnect Posture Profile in Cisco ISE, how can I download it to copy it to the path you indicate?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 10:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456854#M569345</guid>
      <dc:creator>albertofdez</dc:creator>
      <dc:date>2021-08-30T10:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456981#M569350</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What I need is to install the posture module and the posture profile manually or using SCCM or a similar tool.&lt;/P&gt;&lt;P&gt;The Cisco ISE version is 3.0 with patch 3. I attach the ISEPostureCFG.xml file that I created with the ISE Posture Profile Editor.&lt;/P&gt;&lt;P&gt;I understand that if I use the manual process and install the module and the profile, no redirection or access to the portal or anything similar is necessary, right?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 14:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4456981#M569350</guid>
      <dc:creator>albertofdez</dc:creator>
      <dc:date>2021-08-30T14:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4457512#M569387</link>
      <description>&lt;P&gt;Please take a peek at the following to better understand the workflow required:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 12:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4457512#M569387</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-08-31T12:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4511177#M571340</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;The problem was not that I did not understand the required flow, I had to open a case in the CT and I have it solved.&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 13:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/4511177#M571340</guid>
      <dc:creator>albertofdez</dc:creator>
      <dc:date>2021-12-01T13:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE posture setup</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/5223597#M593152</link>
      <description>&lt;P&gt;How did you solve it?&lt;/P&gt;&lt;P&gt;We want to use the CPP by the way to send posturecfg.xml for the first time to newly installed posture module without posturecfg.xml&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 07:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-setup/m-p/5223597#M593152</guid>
      <dc:creator>TE_SecurityAdmin</dc:creator>
      <dc:date>2024-11-13T07:15:45Z</dc:date>
    </item>
  </channel>
</rss>

