<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Non-Compliant Status not going to Compliant State in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530253#M572165</link>
    <description>&lt;P&gt;However, when the users does get to a NonCompliant state, it does not triggert taling to the Services such as WSUS. And it gets stuck to UnCompliant status.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Not sure I am following.&amp;nbsp; Are you suggesting that the dacl does not work when clients are in the non-compliant state? Is the dacl properly assigned to the authz profile that is then used as the result for clients that match the authz condition of non-compliant?&lt;/P&gt;
&lt;P&gt;As a next step I also did install the updates manually, but the Client still gets stuck in a NonCompliant state, thus not changing to compliant state even after installing the updates.&lt;/P&gt;
&lt;P&gt;-What are you using post patching to allow the client to get out of the non-compliant state via a new assessment? Do you have the 'Scan Again' button enabled in the AC posture UI? This would allow end user to manually trigger the probe which would end up re-assessing the end client post patching.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jan 2022 15:04:54 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2022-01-12T15:04:54Z</dc:date>
    <item>
      <title>Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530235#M572164</link>
      <description>&lt;P&gt;Dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a NonCompliant DACL which does isolate the users to communicate only to some services it needs to reach in order to get compliant.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when the users does get to a NonCompliant state, it does not triggert taling to the Services such as WSUS. And it gets stuck to UnCompliant status.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a next step I also did install the updates manually, but the Client still gets stuck in a NonCompliant state, thus not changing to compliant state even after installing the updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DACL for non compliant users is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;permit udp any eq bootpc any eq bootps&lt;BR /&gt;permit udp any any eq 53&lt;BR /&gt;permit udp any any eq domain&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit ip any host 10.0.x.x&lt;BR /&gt;permit udp any eq 68 any eq 67&lt;BR /&gt;permit udp any eq 161 any&lt;BR /&gt;permit icmp any any&lt;BR /&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea why this could be the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 14:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530235#M572164</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2022-01-12T14:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530253#M572165</link>
      <description>&lt;P&gt;However, when the users does get to a NonCompliant state, it does not triggert taling to the Services such as WSUS. And it gets stuck to UnCompliant status.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Not sure I am following.&amp;nbsp; Are you suggesting that the dacl does not work when clients are in the non-compliant state? Is the dacl properly assigned to the authz profile that is then used as the result for clients that match the authz condition of non-compliant?&lt;/P&gt;
&lt;P&gt;As a next step I also did install the updates manually, but the Client still gets stuck in a NonCompliant state, thus not changing to compliant state even after installing the updates.&lt;/P&gt;
&lt;P&gt;-What are you using post patching to allow the client to get out of the non-compliant state via a new assessment? Do you have the 'Scan Again' button enabled in the AC posture UI? This would allow end user to manually trigger the probe which would end up re-assessing the end client post patching.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 15:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530253#M572165</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-01-12T15:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530259#M572167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were is the "Scan Again" located? I don't see it in the AC GUI?! Can I enable it in ISE somewhere, so when AC its downloaded, its enabled automatically!?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 15:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530259#M572167</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2022-01-12T15:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530336#M572172</link>
      <description>&lt;P&gt;The scan again feature is a setting that is enabled/disabled in the ISEPostureCFG.xml that gets deployed to clients.&amp;nbsp; This is configured in ISE under: Policy-&amp;gt;Policy Elements-&amp;gt;Results-&amp;gt;Client Provisioning-&amp;gt;Resources.&amp;nbsp; On windows clients this config file is found here:&amp;nbsp;C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Within the xml profile the tag is this (if enabled):&amp;nbsp;&amp;lt;EnableRescanButton&amp;gt;1&amp;lt;/EnableRescanButton&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE posture UI will look like this when enabled:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="pos_ui_scan_button.PNG" style="width: 396px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/141018iB207E364E8E46E3B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pos_ui_scan_button.PNG" alt="pos_ui_scan_button.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ISE admin UI profile setting:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ise_pos_cfg_scan_button.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/141019i74210E4A0DF969C6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ise_pos_cfg_scan_button.PNG" alt="ise_pos_cfg_scan_button.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This allows manual intervention if desired.&amp;nbsp; HTH!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 16:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530336#M572172</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-01-12T16:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530791#M572188</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's exactly what is was :). Amazing how you could identify the reason right away. Thank you for your support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best wishes,&lt;/P&gt;&lt;P&gt;Laura&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 12:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4530791#M572188</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2022-01-13T12:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4696935#M577504</link>
      <description>&lt;P&gt;How is this a solution?&amp;nbsp; It just states where to look but not how to enable this feature, other than on the xml file.&amp;nbsp; Changing that part will probably corrupt the file and therefore make it unusable.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 18:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4696935#M577504</guid>
      <dc:creator>rbill1967</dc:creator>
      <dc:date>2022-09-30T18:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Non-Compliant Status not going to Compliant State</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4696971#M577505</link>
      <description>&lt;P&gt;I haven't done posturing yet so you've got me curious. I think this is what they're talking about above, see this &lt;A title="Charlie Moreton / timestamp 02-14-2017 05:27 am" href="https://community.cisco.com/t5/network-access-control/ise-posture-profile-how-to-combine-with-anyconnect-without-using/m-p/3607455/highlight/true#M536120" target="_self"&gt;Charlie Moreton / timestamp 02-14-2017 05:27 am&lt;/A&gt;&lt;SPAN class=""&gt;&lt;A title="Charlie Moreton / timestamp 02-14-2017 05:27 am" href="https://community.cisco.com/t5/network-access-control/ise-posture-profile-how-to-combine-with-anyconnect-without-using/m-p/3607455/highlight/true#M536120" target="_self"&gt;05:27 AM&lt;/A&gt; post. It starts with the below.&amp;nbsp; On that page in my lab ISE v2.7 system, I can see the option to set "Enable Rescan Button", and it is disabled by default.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;EM&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Client Provisioning &amp;gt; Resources&lt;/STRONG&gt;&amp;nbsp;and download the Compliance Module you will use.&amp;nbsp; Upload the AnyConnect software here and then create and ISE Posture Profile by clicking the&amp;nbsp;&lt;STRONG&gt;+Add&lt;/STRONG&gt;&amp;nbsp;button and selecting&amp;nbsp;&lt;STRONG&gt;NAC Agent or AnyConnect Posture Profile&lt;/STRONG&gt;.&amp;nbsp; Upload any other AD Modules you will use here, as well.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;Regards,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 20:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-non-compliant-status-not-going-to-compliant-state/m-p/4696971#M577505</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2022-09-30T20:16:25Z</dc:date>
    </item>
  </channel>
</rss>

