<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy server not found in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463689#M569651</link>
    <description>Thank you, I configured the call home list and its still not working. I'm not in front of the machine to check the content of the ISEPostureCFG file.&lt;BR /&gt;By looking at the auth details in the switch the applied URL is correct. From my capture the machine is not attempting to go the ISE server.&lt;BR /&gt;</description>
    <pubDate>Fri, 10 Sep 2021 23:16:06 GMT</pubDate>
    <dc:creator>erga</dc:creator>
    <dc:date>2021-09-10T23:16:06Z</dc:date>
    <item>
      <title>Policy server not found</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463480#M569646</link>
      <description>&lt;P&gt;I am facing a very frustrating issue with newly imaged machines. Even when they have all the GPOs when connecting to wired or wireless the redirection to ISE does not happen. Proved this with a wireshark capture. They get redirected only when on VPN, the connectiondata.xml file gets created then there are no issues. They get redirected on wired/wireless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spent countless hours troubleshooting this, I'm at loss as to what is happening. All the configurations are correct, ACLs are correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other ways are there to redirect a user to the ISE portal for provisioning besides the dACL/ACL method&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 16:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463480#M569646</guid>
      <dc:creator>erga</dc:creator>
      <dc:date>2021-09-10T16:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Policy server not found</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463542#M569647</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/367654"&gt;@erga&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;if my understanding is correct, you are talking about &lt;STRONG&gt;Posture&lt;/STRONG&gt; - from &lt;STRONG&gt;Unknown&lt;/STRONG&gt; to &lt;STRONG&gt;Compliant&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;In your case it looks like that &lt;STRONG&gt;Wired &amp;amp; Wireless&lt;/STRONG&gt; reach the &lt;STRONG&gt;Posture&lt;/STRONG&gt;&amp;nbsp;status&amp;nbsp;&lt;STRONG&gt;Unknown&lt;/STRONG&gt;,&amp;nbsp;but there is no &lt;U&gt;redirection&lt;/U&gt; to &lt;STRONG&gt;Posture&lt;/STRONG&gt; status &lt;STRONG&gt;Compliant&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;if this is your case, please take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;ISE Posture Flow in ISE 2.2 Compared to Earlier ISE Versions&lt;/A&gt;, search for &lt;STRONG&gt;Posture Flow in ISE 2.2&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;"...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Step 12&lt;/STRONG&gt;. In &lt;STRONG&gt;ISE 2.2&lt;/STRONG&gt;, &lt;STRONG&gt;Posture&lt;/STRONG&gt; process is divided into &lt;U&gt;two stages&lt;/U&gt;. &lt;U&gt;First stage&lt;/U&gt; contains set of &lt;U&gt;traditional posture discovery&lt;/U&gt; probes to support &lt;U&gt;backward compatibility&lt;/U&gt; with deployments which relays on &lt;STRONG&gt;URL Redirect&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Step 14&lt;/STRONG&gt;.&lt;U&gt;Stage two&lt;/U&gt; contains &lt;U&gt;two discovery probes&lt;/U&gt; which allows &lt;STRONG&gt;AC ISE Posture Module&lt;/STRONG&gt; to establish connection to the &lt;STRONG&gt;PSN&lt;/STRONG&gt; &lt;U&gt;where session is authenticated&lt;/U&gt; in environments where &lt;U&gt;redirection is not supported&lt;/U&gt;. &lt;U&gt;During stage two all probes are sequential&lt;/U&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;..."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463542#M569647</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-09-10T18:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Policy server not found</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463689#M569651</link>
      <description>Thank you, I configured the call home list and its still not working. I'm not in front of the machine to check the content of the ISEPostureCFG file.&lt;BR /&gt;By looking at the auth details in the switch the applied URL is correct. From my capture the machine is not attempting to go the ISE server.&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Sep 2021 23:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4463689#M569651</guid>
      <dc:creator>erga</dc:creator>
      <dc:date>2021-09-10T23:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Policy server not found</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4466113#M569678</link>
      <description>&lt;P&gt;Things to consider/check:&lt;/P&gt;
&lt;P&gt;-What are the differences in policy config between campus (wired/wireless) and VPN? Check Client Provisioning Policies/Posture Policies.&lt;/P&gt;
&lt;P&gt;-What are the differences between your authz profiles for VPN and campus?&lt;/P&gt;
&lt;P&gt;-I would verify settings in the&amp;nbsp;&lt;SPAN&gt;ISEPostureCFG file.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Do you have separate radius policies to support the 3 states: unknown, compliant, noncompliant?&lt;/P&gt;
&lt;P&gt;-Have you run a DART bundle on a respective client that is failing?&lt;/P&gt;
&lt;P&gt;-Lastly, have you looked here for tshoot help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_blank"&gt;ISE Posture Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 13:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4466113#M569678</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-09-14T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Policy server not found</title>
      <link>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4466963#M569704</link>
      <description>&lt;P&gt;Thank you for the reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authz profiles are all the same except for specific configurations to support VPN, wired and wireless. Wireless uses airspace-acl, VPN dacl is different than wired/wireless.&lt;/P&gt;&lt;P&gt;Yes, there are separate policies that support all 3 states.&lt;/P&gt;&lt;P&gt;I created a dart bundle, what I see is that enroll.cisco.com is not reachable – which should not be, its supposed to redirect the client to the ISE portal. Ran a wireshark capture and there is no attempt from the client to reach the ISE portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The isepostureCFG.xml file never gets downloaded in the affected clients. The call home list is configured there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the connectiondata.xml file gets created the redirection starts working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a TAC case open for this as I’m not sure what else to look at.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing I haven’t tested is uploading the isepostureCFG.xml file manually in the client.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 13:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/policy-server-not-found/m-p/4466963#M569704</guid>
      <dc:creator>erga</dc:creator>
      <dc:date>2021-09-15T13:13:28Z</dc:date>
    </item>
  </channel>
</rss>

