<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 3.0 Agentless Posture - Status remains Not-Applicable in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4486064#M570393</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We are currently doing setup for agentless posture on ISE 3.0.&amp;nbsp; So far I have got all pre-requisites listed in Cisco guideline in place, however it seems to be not working. On the ISE agentless posture reports, it shows agentless script uploaded completed, but I don`t see agentless script being executed successfully on client, thus the endpoint is not showing any posture status in the radius live logs after 802.1x authentication&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The endpoint have got below setting enabled so far :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- PSRemoting is enabled and Remote Server management through WinRM is allowed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Local admin is set for client and same is allowed for remote server management&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Firewall is set to allow port 5985, Reachability between client and ISE seems fine&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now the posture process completes below steps successfully :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Endpoint gets 802.1x authentication&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Agentless Posture option selected in authorization profile seems to be getting triggered upon 802.1x authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- ISE initiate remoteshell session on port 5985 and able to get in using local admin credential configured on ISE endpoint script.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Admin certificate chain and script provisioning on client completes successfully and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;End point does receive "admin-script-formatted-xxxx.ps1" file&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From this stage two problem starts :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1 - Script does not get execute on endpoint and the last log generated on endpoint "PostureScript xxx" output file remains - Script Provisioned Successfully, nothing beyond that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 - Sometime the script does get execute but ends further with "Curl Error code 35 Unable to download agentless posture with return code" &amp;amp; "curl: (35) schannel: next InitializeSecurityContext failed: Unknown error (0x80092013) - The revocation function was unable to check revocation because the revocation server was offline."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For point 1 - Not getting any clue what makes script to not get execute post provisioning on client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And for point 2 - CRL check failure or CRL server offline doesn't seems to be the actual cause, as from endpoint with manual checks to CDP - Certificate Distribution Path check for installed certificate i don't see any error and CRL validation complete successfully but same seems to be failing from posture script.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have been trying and looking at guides all over along with tac but so far no luck.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Has anyone got this issue with ISE 3.0 agentless posturing? Any suggestion or input for further troubleshooting would be highly appreciated.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Oct 2021 10:29:24 GMT</pubDate>
    <dc:creator>ka2tik001</dc:creator>
    <dc:date>2021-10-14T10:29:24Z</dc:date>
    <item>
      <title>Cisco ISE 3.0 Agentless Posture - Status remains Not-Applicable</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4486064#M570393</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are currently doing setup for agentless posture on ISE 3.0.&amp;nbsp; So far I have got all pre-requisites listed in Cisco guideline in place, however it seems to be not working. On the ISE agentless posture reports, it shows agentless script uploaded completed, but I don`t see agentless script being executed successfully on client, thus the endpoint is not showing any posture status in the radius live logs after 802.1x authentication&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The endpoint have got below setting enabled so far :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- PSRemoting is enabled and Remote Server management through WinRM is allowed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Local admin is set for client and same is allowed for remote server management&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Firewall is set to allow port 5985, Reachability between client and ISE seems fine&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now the posture process completes below steps successfully :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Endpoint gets 802.1x authentication&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Agentless Posture option selected in authorization profile seems to be getting triggered upon 802.1x authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- ISE initiate remoteshell session on port 5985 and able to get in using local admin credential configured on ISE endpoint script.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Admin certificate chain and script provisioning on client completes successfully and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;End point does receive "admin-script-formatted-xxxx.ps1" file&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From this stage two problem starts :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1 - Script does not get execute on endpoint and the last log generated on endpoint "PostureScript xxx" output file remains - Script Provisioned Successfully, nothing beyond that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 - Sometime the script does get execute but ends further with "Curl Error code 35 Unable to download agentless posture with return code" &amp;amp; "curl: (35) schannel: next InitializeSecurityContext failed: Unknown error (0x80092013) - The revocation function was unable to check revocation because the revocation server was offline."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For point 1 - Not getting any clue what makes script to not get execute post provisioning on client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And for point 2 - CRL check failure or CRL server offline doesn't seems to be the actual cause, as from endpoint with manual checks to CDP - Certificate Distribution Path check for installed certificate i don't see any error and CRL validation complete successfully but same seems to be failing from posture script.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have been trying and looking at guides all over along with tac but so far no luck.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Has anyone got this issue with ISE 3.0 agentless posturing? Any suggestion or input for further troubleshooting would be highly appreciated.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 10:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4486064#M570393</guid>
      <dc:creator>ka2tik001</dc:creator>
      <dc:date>2021-10-14T10:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 Agentless Posture - Status remains Not-Applicable</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4500728#M570991</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody having the solution , i am facing the same issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Posture status showing not applicable , however scrip showing uploaded completed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/481106"&gt;@ISE&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 11:28:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4500728#M570991</guid>
      <dc:creator>JALALUDDEEN A A</dc:creator>
      <dc:date>2021-11-10T11:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 Agentless Posture - Status remains Not-Applicable</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4531487#M572203</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also trying to implement Agentless posture right now.&lt;/P&gt;&lt;P&gt;What I've figured out is that in the report "Agentless Posture" even when we have "&lt;SPAN&gt;Agentless script upload completed" it doesn't mean the script was executed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can check on the endpoint (windows) in the event viewer logs : Applications &amp;amp; Services Logs &amp;gt; Microsoft &amp;gt; Windows &amp;gt; PowerShell&amp;gt; Operationnal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The user is admin, but the excecution policy is blocking :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Error Message = File C:\Users\admin_ISE\admin-script-formatted-105964.ps1 &lt;STRONG&gt;cannot be loaded&lt;/STRONG&gt;. The file C:\Users\admin_ISE\admin-script-formatted-105964.ps1 &lt;STRONG&gt;is not digitally signed&lt;/STRONG&gt;. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Indeed we have an execution policy running for our Windows float that prevents the execution of an unknown script.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It seems that we cannot write over the default endpoint script in ISE (&amp;nbsp;&lt;/SPAN&gt;powershell.exe -ScriptBlock {} )&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;, or sign it with an internal CA... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Still trying to bypass this as the GPO policy is not something I can easily change.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helped.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 10:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-agentless-posture-status-remains-not-applicable/m-p/4531487#M572203</guid>
      <dc:creator>Kalipso</dc:creator>
      <dc:date>2022-01-14T10:49:12Z</dc:date>
    </item>
  </channel>
</rss>

