<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need urgent help on client provisioning in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4517282#M571608</link>
    <description>&lt;P&gt;Posture module (and DART module) is downloaded because it is specified in the ASA group-policy. Use a GP for profile1 which has no module download settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compliance module is downloaded either because CPP redirection is in effect or because the client remembers a previous connection data of the ISE as policy server. (ConnectionData.xml or ISEpostureCFG.xml on client)&lt;/P&gt;</description>
    <pubDate>Sat, 11 Dec 2021 21:46:59 GMT</pubDate>
    <dc:creator>Peter Koltl</dc:creator>
    <dc:date>2021-12-11T21:46:59Z</dc:date>
    <item>
      <title>Need urgent help on client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4512783#M571424</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have following configuration on cisco asa for remote access vpn and posturing on ise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 vpn profiles on cisco asa. profile1 without posturing and profile2 with posturing. client provisioning is configured on ise with anyconnect config profile. however, ise posture module provisioning is done on cisco asa (as i was getting issues for it via cisco ise)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is with client provisioning, when user connects the vpn profile which has not enabled for posturing still client provisioning happens. Anyconnect vpn gets updated and posture and compliance modules gets donwloaded, sometimes dart and smb donwloads which are unnecessary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On cisco asa : for vpn profile1 - ise as authorization, accounting server is not configured.&lt;/P&gt;&lt;P&gt;On ise : client provisioning policy configured such a way that asa ip with tunnel group of vpn profile 2 only will be client provisioned. Also, authorisation policy for vpn profile 2 only has compliance rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dont understand why client provisioned for vpn profile 1? Need help&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 15:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4512783#M571424</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-12-03T15:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help on client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4512825#M571427</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dont understand why client provisioned for vpn profile 1? Need help&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Sounds like you are steering both VPN tunnel group clients to ISE CPP.&amp;nbsp; Do you have separate authz profiles for each one?&amp;nbsp; That may help fix your issue.&amp;nbsp; Also, double check your CPP conditions and work towards keeping the two tunnel groups separate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 16:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4512825#M571427</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-12-03T16:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help on client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4513725#M571476</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Actually both vpn profiles have separate policy sets filtered based on the tunnel groups.&lt;/P&gt;&lt;P&gt;Also, cpp is only for vpn profile 2 that is also filtered with tunnel group.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 09:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4513725#M571476</guid>
      <dc:creator>User_80617</dc:creator>
      <dc:date>2021-12-06T09:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help on client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4516404#M571581</link>
      <description>&lt;P&gt;Are you following any guides?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-configure-posture-with-anyconnect-compliance-module-and/ta-p/3647768" target="_self"&gt;&lt;SPAN class="lia-link-navigation lia-link-disabled"&gt;H&lt;/SPAN&gt;&lt;SPAN class="lia-link-navigation lia-link-disabled"&gt;ow To Configure Posture with AnyConnect Compliance Module and ISE 2.x&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Dec 2021 04:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4516404#M571581</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-10T04:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help on client provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4517282#M571608</link>
      <description>&lt;P&gt;Posture module (and DART module) is downloaded because it is specified in the ASA group-policy. Use a GP for profile1 which has no module download settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compliance module is downloaded either because CPP redirection is in effect or because the client remembers a previous connection data of the ISE as policy server. (ConnectionData.xml or ISEpostureCFG.xml on client)&lt;/P&gt;</description>
      <pubDate>Sat, 11 Dec 2021 21:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help-on-client-provisioning/m-p/4517282#M571608</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2021-12-11T21:46:59Z</dc:date>
    </item>
  </channel>
</rss>

