<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable Port 8905 on non-Policy Service nodes for Posture services in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148334#M590785</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, your understanding is correct about "&lt;EM&gt;... using &lt;STRONG&gt;ISE 2.1&lt;/STRONG&gt; for example, the use of &lt;STRONG&gt;TCP Port 8905&lt;/STRONG&gt; is mandatory ...&lt;/EM&gt;" (more detail at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;Compare ISE Posture Redirection Flow to ISE Posture Redirectionless Flow&lt;/A&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;About your other question ... "&lt;EM&gt;Why opening this &lt;STRONG&gt;Port&lt;/STRONG&gt; on &lt;STRONG&gt;non-PSNs&lt;/STRONG&gt; ?&lt;/EM&gt;" ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you take a look at &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/install_guide/b_ise_installationGuide33/b_ise_InstallationGuide33_chapter_7.html" target="_blank" rel="noopener"&gt;Cisco ISE Port References - ISE 3.3&lt;/A&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"&lt;EM&gt;...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;From &lt;STRONG&gt;Cisco ISE 3.1&lt;/STRONG&gt; onwards, &lt;STRONG&gt;port 8905&lt;/STRONG&gt; is &lt;U&gt;disabled by default&lt;/U&gt; on &lt;STRONG&gt;non-Policy Service Nodes&lt;/STRONG&gt; ...&lt;/EM&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 14:24:07 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2024-07-22T14:24:07Z</dc:date>
    <item>
      <title>Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147147#M590724</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;One of the less obvious options in ISE Posture Assessment general settings is the "&lt;STRONG&gt;Enable Port 8905 on non-Policy Service nodes for Posture services&lt;/STRONG&gt;" option. I know&amp;nbsp;from ISE 3.1 onwards, port &lt;STRONG&gt;8905&lt;/STRONG&gt; is disabled by default on non-PSNs and&amp;nbsp;the PAN should not be listening on &lt;STRONG&gt;8905&lt;/STRONG&gt; in a fully distributed deployment...&lt;/P&gt;&lt;P&gt;My question is, in which scenarios I must enable this option?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 07:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147147#M590724</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-07-19T07:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147412#M590728</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;prior to &lt;STRONG&gt;ISE 2.2&lt;/STRONG&gt; communication over &lt;STRONG&gt;port 8905&lt;/STRONG&gt; is a requirement for &lt;STRONG&gt;Posture&lt;/STRONG&gt; ... &lt;STRONG&gt;ISE 2.2+&lt;/STRONG&gt; the communication is over &lt;STRONG&gt;port 8443&lt;/STRONG&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;Compare ISE Posture Redirection Flow to ISE Posture Redirectionless Flow&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 17:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147412#M590728</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-07-19T17:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147513#M590742</link>
      <description>&lt;P&gt;Thanks for your reply. I know this but my question is why enabling this port on newer ISE versions?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 06:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147513#M590742</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-07-20T06:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147519#M590744</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;in &lt;STRONG&gt;ISE 2.2+&lt;/STRONG&gt;, the &lt;STRONG&gt;Posture&lt;/STRONG&gt; process is divided into &lt;U&gt;two stages&lt;/U&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;The &lt;STRONG&gt;1st stage&lt;/STRONG&gt; contains a set of traditional &lt;STRONG&gt;Posture Discovery Probes&lt;/STRONG&gt; to &lt;U&gt;support&lt;/U&gt; &lt;STRONG&gt;backward compatibility&lt;/STRONG&gt; with &lt;STRONG&gt;Deployments&lt;/STRONG&gt; that rely on the &lt;STRONG&gt;url redirect&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;The &lt;STRONG&gt;2nd stage&lt;/STRONG&gt;&amp;nbsp;contains two &lt;STRONG&gt;Discovery Probes&lt;/STRONG&gt; that allow the &lt;STRONG&gt;AC ISE Posture Module&lt;/STRONG&gt; to establish a connection to the &lt;STRONG&gt;PSN&lt;/STRONG&gt; where the session is authenticated in environments where &lt;U&gt;redirection is not supported&lt;/U&gt;&lt;STRONG&gt;.&amp;nbsp;&lt;/STRONG&gt;During &lt;U&gt;stage two&lt;/U&gt;, all &lt;STRONG&gt;Probes&lt;/STRONG&gt; are sequential.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Note 1&lt;/STRONG&gt;: p&lt;/SPAN&gt;rior to &lt;STRONG&gt;ISE 2.2&lt;/STRONG&gt;, communication over &lt;STRONG&gt;Port 8905&lt;/STRONG&gt; is a &lt;U&gt;requirement&lt;/U&gt; for &lt;STRONG&gt;Posture&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;STRONG&gt;Note 2&lt;/STRONG&gt;: if you are not using the &lt;STRONG&gt;1st stage&lt;/STRONG&gt;, then you are going to use &lt;U&gt;only&lt;/U&gt; the &lt;STRONG&gt;2nd stage&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 06:55:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5147519#M590744</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-07-20T06:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148323#M590784</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;So, based on your statement, if we prefer to user URL Redirection for Posture operation and using ISE 2.1 for example, the use of TCP port &lt;STRONG&gt;8905&lt;/STRONG&gt; is mandatory and this port must be in listening state in ISE PSNs. Right?&lt;/P&gt;&lt;P&gt;Now the point I do not understand is that:&lt;/P&gt;&lt;P&gt;Why opening this port on non-PSNs (in fully distributed deployments, actually)?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148323#M590784</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-07-22T14:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148334#M590785</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, your understanding is correct about "&lt;EM&gt;... using &lt;STRONG&gt;ISE 2.1&lt;/STRONG&gt; for example, the use of &lt;STRONG&gt;TCP Port 8905&lt;/STRONG&gt; is mandatory ...&lt;/EM&gt;" (more detail at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html" target="_blank" rel="noopener"&gt;Compare ISE Posture Redirection Flow to ISE Posture Redirectionless Flow&lt;/A&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;About your other question ... "&lt;EM&gt;Why opening this &lt;STRONG&gt;Port&lt;/STRONG&gt; on &lt;STRONG&gt;non-PSNs&lt;/STRONG&gt; ?&lt;/EM&gt;" ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you take a look at &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/install_guide/b_ise_installationGuide33/b_ise_InstallationGuide33_chapter_7.html" target="_blank" rel="noopener"&gt;Cisco ISE Port References - ISE 3.3&lt;/A&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;"&lt;EM&gt;...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;From &lt;STRONG&gt;Cisco ISE 3.1&lt;/STRONG&gt; onwards, &lt;STRONG&gt;port 8905&lt;/STRONG&gt; is &lt;U&gt;disabled by default&lt;/U&gt; on &lt;STRONG&gt;non-Policy Service Nodes&lt;/STRONG&gt; ...&lt;/EM&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Hope this helps !!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148334#M590785</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-07-22T14:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Port 8905 on non-Policy Service nodes for Posture services</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148362#M590786</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;just adding one more thing about your &lt;STRONG&gt;2nd question&lt;/STRONG&gt;&amp;nbsp;and get ready to laugh&amp;nbsp; : )&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Please take a look at &lt;A href="https://community.cisco.com/t5/network-access-control/pan-should-be-listening-on-port-8905/td-p/4421425" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;PAN should be listening on port 8905?&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Note: take a look at&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-slow-replication/ta-p/4704536" target="_blank" rel="noopener"&gt; ISE - Slow Replication&lt;/A&gt; and search for &lt;STRONG&gt;8905&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 14:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-port-8905-on-non-policy-service-nodes-for-posture/m-p/5148362#M590786</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2024-07-22T14:49:42Z</dc:date>
    </item>
  </channel>
</rss>

