<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695087#M577428</link>
    <description>&lt;P&gt;Great! I appreciate your reply.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 00:57:03 GMT</pubDate>
    <dc:creator>LC.IT</dc:creator>
    <dc:date>2022-09-28T00:57:03Z</dc:date>
    <item>
      <title>[Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4621669#M575111</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are deploying Posture with Cisco ISE 2.7 (Patch7) and we are facing a strange issue. The machine with AnyConnect report to us the "Compliant" status with Network Access Allowed, but looking through ISE dashboard we receive "Unknown" status and the redirect for the provisioning portal.&lt;/P&gt;
&lt;P&gt;- I've already disabled all posture rules, we're not scanning for anything (just software and hardware inventory).&lt;/P&gt;
&lt;P&gt;- The CoA is correctly applied in the controller.&lt;/P&gt;
&lt;P&gt;- We are using EAP-TLS (machine cert.) for auth..&lt;/P&gt;
&lt;P&gt;- The WLC acl works good, redirecting 443, 8443, 8905 and allowing domain.&lt;/P&gt;
&lt;P&gt;- The firewall are with any any allowed.&lt;/P&gt;
&lt;P&gt;- The Authz. profiles (deny, permit and redirect for provisioning portal looks good too).&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;We don't have any kind of posture on the wired network yet.&lt;/P&gt;
&lt;P&gt;- Cisco ISE are with 'default posture status' setting as compliant&lt;/P&gt;
&lt;P&gt;- Attached are the authz. policy (PNG).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone experienced something like this?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4621669#M575111</guid>
      <dc:creator>LKL4</dc:creator>
      <dc:date>2022-05-31T15:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4622944#M575150</link>
      <description>&lt;P&gt;Please check whether the authentication, accounting, and posturing all done on the same ISE PSN node. Likely you need engage TAC to troubleshoot further.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 03:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4622944#M575150</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-02T03:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4625908#M575235</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/142597"&gt;@jhsl&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;We are running ise with just one node (standalone) and TAC&amp;nbsp;already involved in this analysis.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 12:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4625908#M575235</guid>
      <dc:creator>LKL4</dc:creator>
      <dc:date>2022-06-06T12:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4627868#M575316</link>
      <description>&lt;P&gt;Just adding the solution for my issue:&lt;BR /&gt;This is the new bug matching this behavior: CSCwa99904 17.6.2 || 9800 WLC Deletes Client when DHCP RELEASE is sent by client during Posture.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 12:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4627868#M575316</guid>
      <dc:creator>LKL4</dc:creator>
      <dc:date>2022-06-08T12:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695049#M577424</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/730677"&gt;@LKL4&lt;/a&gt;&amp;nbsp;did the workaround fix the problem described on &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCwa99904" target="_blank" rel="noopener"&gt;CSCwa99904&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 22:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695049#M577424</guid>
      <dc:creator>LC.IT</dc:creator>
      <dc:date>2022-09-27T22:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695079#M577427</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1230356"&gt;@LC.IT&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, in my case we were able to work around this by setting PMF to disabled (moved from WPA2+WPA3 to WPA+WPA2).&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 00:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695079#M577427</guid>
      <dc:creator>LKL4</dc:creator>
      <dc:date>2022-09-28T00:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ISE] Posture Status Unknown but AnyConnect as Compliant</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695087#M577428</link>
      <description>&lt;P&gt;Great! I appreciate your reply.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 00:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-status-unknown-but-anyconnect-as-compliant/m-p/4695087#M577428</guid>
      <dc:creator>LC.IT</dc:creator>
      <dc:date>2022-09-28T00:57:03Z</dc:date>
    </item>
  </channel>
</rss>

