<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Unknown or Pending Timeout in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106688#M589479</link>
    <description>&lt;P&gt;I suppose you could start with returning a Session-Timeout in your ISE Authorization Profile. When that timer expires, then the client will be re-auth'd and then it will be re-assessed. I am not experienced with Posture flow, but how would you like to handle endpoints that exceed their allotted time during posture assessment?&lt;/P&gt;
&lt;P&gt;The &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_self"&gt;Posturing Prescriptive Guide&lt;/A&gt; might have some insights.&lt;/P&gt;</description>
    <pubDate>Fri, 17 May 2024 00:16:12 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-05-17T00:16:12Z</dc:date>
    <item>
      <title>Cisco ISE Unknown or Pending Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106247#M589468</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;Does anyone know of way to configure a timeout or time limit for an endpoint to be in a Pending or Posture Unknown state?&lt;/P&gt;&lt;P&gt;We are concerned about credential theft and unauthorized devices remaining in this state with access.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 17:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106247#M589468</guid>
      <dc:creator>abarkley</dc:creator>
      <dc:date>2024-05-16T17:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Unknown or Pending Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106688#M589479</link>
      <description>&lt;P&gt;I suppose you could start with returning a Session-Timeout in your ISE Authorization Profile. When that timer expires, then the client will be re-auth'd and then it will be re-assessed. I am not experienced with Posture flow, but how would you like to handle endpoints that exceed their allotted time during posture assessment?&lt;/P&gt;
&lt;P&gt;The &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273" target="_self"&gt;Posturing Prescriptive Guide&lt;/A&gt; might have some insights.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 00:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106688#M589479</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-17T00:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Unknown or Pending Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106713#M589480</link>
      <description>&lt;P&gt;I haven't played around with these setting, but you can try&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Administration &amp;gt; Settings &amp;gt; Posture &amp;gt; General Settings&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;there is continuous monitoring setting, which basically states how frequently any connect will send status update to ISE. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If posture state changes to Unknown your policy should be such that it pushes different authorization profile to endpoint and limits their access to only resources required to become compliant. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;you can read more under "posture general setting" &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_client_posture_policies.html" target="_self"&gt;here&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 01:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-unknown-or-pending-timeout/m-p/5106713#M589480</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2024-05-17T01:18:43Z</dc:date>
    </item>
  </channel>
</rss>

