<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Posture with WLC 9800 in FlexConnect Mode - SGT Issue wi in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5204130#M592217</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - What type of firewall are you&amp;nbsp; using ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
    <pubDate>Sun, 06 Oct 2024 15:00:54 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-10-06T15:00:54Z</dc:date>
    <item>
      <title>Cisco ISE Posture with WLC 9800 in FlexConnect Mode - SGT Issue with F</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5203845#M592206</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We're currently implementing posture with Cisco ISE, and we've successfully configured policies and used dACLs (Downloadable ACLs) for wired and VPN connections. However, we're facing an issue with ISE Posture on WiFi as we can't use dACLs on the WLC 9800 in FlexConnect mode.&lt;/P&gt;
&lt;P&gt;To work around this limitation, we've created specific SGTs (Security Group Tags) to manage network access rules via FTD (Firepower Threat Defense) based on posture states (Unknown, Compliant, and Non Compliant).&lt;/P&gt;
&lt;P&gt;The problem is that the firewall doesn't seem to update the SGT tied to a particular user, even though the posture compliance status is correctly obtained.&lt;/P&gt;
&lt;P&gt;In the ISE live logs, we can clearly see that the user is assigned the "Posture-Compliant" SGT, but the firewall still sees the user with the SGT "Posture-Unknown," and as a result, their access to internal resources is blocked.&lt;/P&gt;
&lt;P&gt;Has anyone encountered this issue before? Why isn't the firewall recognizing the SGT change? What should we check or troubleshoot to resolve this?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 15:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5203845#M592206</guid>
      <dc:creator>nicoff</dc:creator>
      <dc:date>2024-10-05T15:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture with WLC 9800 in FlexConnect Mode - SGT Issue wi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5204130#M592217</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - What type of firewall are you&amp;nbsp; using ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2024 15:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5204130#M592217</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-10-06T15:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Posture with WLC 9800 in FlexConnect Mode - SGT Issue wi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5204159#M592218</link>
      <description>&lt;P&gt;Firepower 1120 v.7.2.4.1. I forgot to mention that we manage our firewalls using FMC.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2024 17:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-posture-with-wlc-9800-in-flexconnect-mode-sgt-issue/m-p/5204159#M592218</guid>
      <dc:creator>nicoff</dc:creator>
      <dc:date>2024-10-06T17:17:25Z</dc:date>
    </item>
  </channel>
</rss>

