<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi, all. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3838369#M57166</link>
    <description>&lt;P&gt;Was there a resolution to this?&amp;nbsp;I am facing the exact same issue. Anyconnect posture module stays in 'complaint' status but is in 'Unknown' state, and no new server discovery is initiated or reposturing is done.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2019 00:27:46 GMT</pubDate>
    <dc:creator>Madura Malwatte</dc:creator>
    <dc:date>2019-04-15T00:27:46Z</dc:date>
    <item>
      <title>Cisco Anyconnect &amp; ISE  behavior with Machine comes back from sleep mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761130#M57142</link>
      <description>&lt;P&gt;I have an ISE setup (Eap-chaining &amp;amp; &amp;nbsp;posturing ) for wired using Cisco Anyconnect 4.1 . I'm facing two issues with anyconnect , and hopefully some one can help me out ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-&amp;nbsp;When machine moves from sleep mode to live &amp;nbsp;, ISE is not allowing users full access to network&lt;/P&gt;&lt;P&gt;Any connect shows it as connected &amp;nbsp;and system scan shows complaint &amp;nbsp;but user is not getting access &amp;nbsp;and he has to manually reconnect using any connect to get the services back&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-&amp;nbsp;&amp;nbsp;anyconnect client keep showing as "updating requirements" for Long time sometimes&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached error “keep updating”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any hints?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761130#M57142</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2019-03-11T06:09:10Z</dc:date>
    </item>
    <item>
      <title>1.- Does ISE authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761131#M57144</link>
      <description>&lt;P&gt;1.&lt;/P&gt;&lt;P&gt;- Does ISE authenticate your machines once they "wake up" and then sends an authorization result?&lt;/P&gt;&lt;P&gt;- What authorization attributes are you sending to the switch, vlan change, acl or both?&lt;/P&gt;&lt;P&gt;- What host mode are you using on the switch ports ? ( maybe post interface config)&lt;/P&gt;&lt;P&gt;- What does a "show auth sess interface &amp;lt;port the pc is in&amp;gt; when it's ok, and when this problem is happening (before the manual reconnect)?&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;&lt;P&gt;- What posture checks are you running ?&lt;/P&gt;&lt;P&gt;- What remediation actions are you trying to take ?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 18:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761131#M57144</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-10-14T18:29:32Z</dc:date>
    </item>
    <item>
      <title>Hi Jan , Thanks for your</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761132#M57145</link>
      <description>&lt;P&gt;Hi Jan ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply , Actually these two issues happened randomly , sometime it works and sometimes it did not . I have regenerate the problem or wait until it happened again and I will capture the outputs from the&amp;nbsp;switch side and ISE side and post here .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port configuration is as follows :&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 121&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 130&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action reinitialize vlan 121&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&amp;nbsp;&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change added&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change removed&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- For the second issue : the machine was already complaint , and this happens when re-posture is happening , the machine need no remediation as it is already complaint . Posture check includes AV check and some services check and it is all OK with that machine. It is just annoying the user and he is asking why it is doing that from time to time , sometimes it happens fast , and sometimes takes long time to complete.&lt;/P&gt;&lt;P&gt;I will gather more information about this issue and post it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 05:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761132#M57145</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2015-10-15T05:52:13Z</dc:date>
    </item>
    <item>
      <title>Hello Jan,The problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761133#M57146</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Hello Jan,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;The problem happened again , to answer your questions :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;-&lt;STRONG&gt; Does ISE authenticate your machines once they "wake up" and then sends an authorization result?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;after the machine wake up , ISE authenticate the machine , but the authorization profile given is the one given when the machine do &amp;nbsp;not have anyconnect installed (CPP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;in my case this authorization profile named "XYZ-ISE-POSTURE-UNKNOWN"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;- &lt;STRONG&gt;What authorization attributes are you sending to the switch, vlan change, acl or both?&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; When machine is authenticated and authorized , ACL list is pushed to the switch. no vlan change.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;-&lt;STRONG&gt; What host mode are you using on the switch ports ? ( maybe post interface config)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&amp;nbsp; host mode multi-auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;- &lt;STRONG&gt;What does a "show auth sess interface &amp;lt;port the pc is in&amp;gt; when it's ok, and when this problem is happening (before the manual reconnect)?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;when the problem&amp;nbsp;happens and before disconnect and connect &amp;nbsp;:&lt;BR /&gt;=====================================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;ZI-IT-021#Show auth session int &amp;nbsp;gig1/0/11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;GigabitEthernet1/0/11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;fc15.b4ec.f432&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;172.16.21.8&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name: &amp;nbsp;z8785&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Authz Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;DATA&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;multi-auth&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;in&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Authorized By: &amp;nbsp;Authentication Server&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vlan Policy: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ACS ACL: &amp;nbsp;xACSACLx-&lt;STRONG&gt;IP-XYZ-ISE-POSTURE-UNKNOWN&lt;/STRONG&gt;-55ebe7ee&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;URL Redirect ACL: &amp;nbsp;ACL-REDIRECT&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;URL Redirect: &amp;nbsp;https://XYZ-ise-01.xyzq.net:8443/portal/gateway?sessionId=AC10321500016725166C9573&amp;amp;portal=bd13d762-fd2c-11e4-a063-b83861d7efc6&amp;amp;action=cpp&amp;amp;token=acbfea3c5e84d2d7e3cbff8c72c23b47&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;AC10321500016725166C9573&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x00019575&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0x510006E0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Authc Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mab &amp;nbsp; &amp;nbsp; &amp;nbsp;Not run&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;======================================&lt;BR /&gt;After disconnect and connect&lt;BR /&gt;======================================&lt;BR /&gt;XXIT-021#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;917334: Oct 20 2015 10:47:24.538 KSA: %DOT1X-5-SUCCESS: Authentication successful for client (fc15.b4ec.f432) on Interface Gi1/0/11 AuditSessionID AC10321500016725166C9573&lt;BR /&gt;917335: Oct 20 2015 10:47:24.538 KSA: %AUTHMGR-7-RESULT: Authentication result 'success' from 'dot1x' for client (fc15.b4ec.f432) on Interface Gi1/0/11 AuditSessionID AC10321500016725166C9573&lt;BR /&gt;917336: Oct 20 2015 10:47:24.538 KSA: %EPM-6-POLICY_REQ: IP 172.16.21.8| MAC fc15.b4ec.f432| AuditSessionID AC10321500016725166C9573| AUTHTYPE DOT1X| EVENT APPLY&lt;BR /&gt;917337: Oct 20 2015 10:47:24.545 KSA: %EPM-6-POLICY_APP_SUCCESS: IP 172.16.21.8| MAC fc15.b4ec.f432| AuditSessionID AC10321500016725166C9573| AUTHTYPE DOT1X| POLICY_TYPE Named ACL| POLICY_NAME xACSACLx-IP-XYZ-PERMIT-ALL-547d7b63| RESULT SUCCESS&lt;BR /&gt;917338: Oct 20 2015 10:47:25.289 KSA: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (fc15.b4ec.f432) on Interface Gi1/0/11 AuditSessionID AC10321500016725166C9573&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;XXIT-021#sh authentication sessions int gigabitEthernet 1/0/11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;GigabitEthernet1/0/11&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;fc15.b4ec.f432&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;172.16.21.8&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name: &amp;nbsp;z8785&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Authz Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;DATA&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;multi-auth&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;in&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Authorized By: &amp;nbsp;Authentication Server&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vlan Policy: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ACS ACL: &amp;nbsp;xACSACLx-IP-XYZ-PERMIT-ALL-547d7b63&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;AC10321500016725166C9573&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x00019575&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0x510006E0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Authc Success&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as you can see , it looks like when the machine comes back from sleep mode , the Cisco Anyconnect can not be detected by ISE .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas ?!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 08:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761133#M57146</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2015-10-20T08:31:17Z</dc:date>
    </item>
    <item>
      <title>This is normal, if the PC has</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761134#M57147</link>
      <description>&lt;P&gt;This is normal, if the PC has been asleep, and is re-authenticated, ISE will per default require it to go through posture assesment, so you are unknown until you are compliant or noncompliant, the redirect url you can see in the authz profile, should make the posture agent detect what PSN to talk to and start doing the posture. But you have to login to the machine for that to happen. Does your posture agent not change state to something like "searching" once you login to the machine?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 10:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761134#M57147</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-10-20T10:29:13Z</dc:date>
    </item>
    <item>
      <title>The user is already logged in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761135#M57148</link>
      <description>&lt;P&gt;The user is already logged in when the PC&amp;nbsp;comes back from sleep .I did not notice the status of the anyconnect&amp;nbsp;&amp;nbsp;if it is searching or something&amp;nbsp;when the user logged in to the machine.I have to re-check again , but apparently there is an issue between sleep mode and anyconnect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;when comes back from sleep mode , anyconnect could not be detected by ISE (or the other way around) , and therefore this machine will be seen by the ISE as it dose not have anyconnect installed. This is what we have to find a solution for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 16:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761135#M57148</guid>
      <dc:creator>Ali Koussan</dc:creator>
      <dc:date>2015-10-20T16:09:29Z</dc:date>
    </item>
    <item>
      <title>Hi Ali</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761136#M57149</link>
      <description>&lt;P&gt;Hi Ali&lt;/P&gt;
&lt;P&gt;Did you able to solve the issue?&lt;/P&gt;
&lt;P&gt;Tks&lt;/P&gt;
&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 07:39:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761136#M57149</guid>
      <dc:creator>Gaj Ana</dc:creator>
      <dc:date>2016-02-04T07:39:22Z</dc:date>
    </item>
    <item>
      <title>Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761137#M57150</link>
      <description>&lt;P&gt;Hi, all.&lt;/P&gt;
&lt;P&gt;Seems like this is still not working as desired:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- ISE V2.1 patch 2, AnyconnectComplianceModuleWindows 4.2.488&lt;/P&gt;
&lt;P&gt;- Windows 7 client running latest Anyconnect 4.3.4027 (SSL VPN module, ISE posture module, NAM Module)&lt;/P&gt;
&lt;P&gt;- EAP-TLS&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When the client is booted, authentication (EAP-TLS) runs fine, authorization puts the client into "posture unkown" (including Redirect-ACL, unkown-client-DACL and Redirect URL).&lt;/P&gt;
&lt;P&gt;ISE posture module starts up, searches for ISE server, finds server, checks version of Anyconnect and modules, executes posture checks and policies successfully, "posture compliant" profile (including PERMIT_ALL_DACL) is authorized and put onto the switchport.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;After nobody touching the client for xyz minutes, the client is locked and the screen is turned off, anybody who wants to use the client from there on, has to log in again.&lt;/P&gt;
&lt;P&gt;When reauthentication occurs while the client is in this locked state, it gets reauthenticated, but authorization stays&amp;nbsp;in "posture unknown" state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So far, so good, all parts working as they should !!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If the client is now unlocked by the user (through his/her login), the client stays in "posture unkown" state, ISE posture module still shows "compliant" state (from last successful posture) !!!!!!! No new server discovery is initiated or reposturing is done!!!&lt;/P&gt;
&lt;P&gt;The switchport however still has "posture unknown",&amp;nbsp;&lt;SPAN&gt;including Redirect-ACL, unkown-client-DACL and Redirect URL.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Only disconnecting the cable (by the user) or manually shutting the access port down and reenabling it (by me) does the trick, but this cannot be it !!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any clues ???&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 12:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761137#M57150</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2016-11-28T12:49:41Z</dc:date>
    </item>
    <item>
      <title>I also have this issue... Has</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761138#M57152</link>
      <description>&lt;P&gt;I also have this issue... Has there ever been a solution provided for this problem??&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We were running AnyConnect 4.2 and ISE v2.0, so we upgraded AnyConnect to v4.3, but we are still seeing the same problem. My Problem is almost word-for-word the same thing as &lt;STRONG&gt;Ali&lt;/STRONG&gt; and &lt;STRONG&gt;Frank&lt;/STRONG&gt;...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in Advance,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 21:14:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/2761138#M57152</guid>
      <dc:creator>Matthew Martin</dc:creator>
      <dc:date>2016-12-15T21:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3382357#M57155</link>
      <description>&lt;P&gt;Hi frank,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have this issue too. how did you managed to solve this issue ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 May 2018 07:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3382357#M57155</guid>
      <dc:creator>Nishad Dadhaniya</dc:creator>
      <dc:date>2018-05-13T07:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3391376#M57157</link>
      <description>&lt;P&gt;I am also facing same issue. After a certain while when user unlocks his computer, the Anyconnect posture module is still in 'complaint' status but a per ISE operation log it is in 'Unknown' state. Anyone solved this issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 15:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3391376#M57157</guid>
      <dc:creator>sudheere</dc:creator>
      <dc:date>2018-05-30T15:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3413094#M57159</link>
      <description>&lt;P&gt;change the setting of your ISE posture instead of perform posture assessment every time a user connects to the network, use perform posture assessment every 1 day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 07:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3413094#M57159</guid>
      <dc:creator>ccg-security</dc:creator>
      <dc:date>2018-07-10T07:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3674958#M57160</link>
      <description>&lt;P&gt;Guys, we are having this issue also for a week!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone has solution?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 02:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3674958#M57160</guid>
      <dc:creator>rhuel.phils</dc:creator>
      <dc:date>2018-07-26T02:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3675700#M57162</link>
      <description>contact the TAC to debug</description>
      <pubDate>Thu, 26 Jul 2018 19:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3675700#M57162</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-07-26T19:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3838369#M57166</link>
      <description>&lt;P&gt;Was there a resolution to this?&amp;nbsp;I am facing the exact same issue. Anyconnect posture module stays in 'complaint' status but is in 'Unknown' state, and no new server discovery is initiated or reposturing is done.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 00:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3838369#M57166</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2019-04-15T00:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hi, all.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3941796#M57168</link>
      <description>&lt;P&gt;We are also facing the same issue. Anyone has a fix for this ?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 16:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/3941796#M57168</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2019-10-16T16:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Anyconnect &amp; ISE  behavior with Machine comes back from sleep mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4002802#M57170</link>
      <description>&lt;P&gt;Same here. Happens randomly. Windows native supplicant configured with machine authentication (EAP-TLS).&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2019 19:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4002802#M57170</guid>
      <dc:creator>ajtm</dc:creator>
      <dc:date>2019-12-23T19:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Anyconnect &amp; ISE  behavior with Machine comes back from sleep mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4011636#M57171</link>
      <description>&lt;P&gt;Anyone have solution for this issue? I'm facing the same issue at user site without solution now.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 06:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4011636#M57171</guid>
      <dc:creator>williamtan</dc:creator>
      <dc:date>2020-01-15T06:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Anyconnect &amp; ISE  behavior with Machine comes back from sleep mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4036683#M558414</link>
      <description>&lt;P&gt;Is there any solution for this issue?.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 07:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4036683#M558414</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2020-02-27T07:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Anyconnect &amp; ISE  behavior with Machine comes back from sleep mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4294921#M565618</link>
      <description>&lt;P&gt;Is there any solution for the issue?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 12:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-anyconnect-ise-behavior-with-machine-comes-back-from-sleep/m-p/4294921#M565618</guid>
      <dc:creator>MambaRod16</dc:creator>
      <dc:date>2021-02-21T12:35:30Z</dc:date>
    </item>
  </channel>
</rss>

