<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Posture Unknown flow for endpoints without Posture agent Installed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208931#M592451</link>
    <description>&lt;P&gt;The desired VLAN includes both Windows 10 and Windows 7 machines and therefore, when a Windows 7 computer connects to the network, it always matches with the configured "&lt;STRONG&gt;Unknown&lt;/STRONG&gt;" policy which has very limited network connectivity and unfortunately stucks in this stage (because of Windows 7 supportability for ISE Posture Module, the client cannot include this module installed. Right?). I want to bypass this policy for Windows 7 PCs without using Profiling Policy inclusion of just Windows 10 PCs.&lt;/P&gt;&lt;P&gt;The following is the fact from the client (with Windows 7) that ISE has gathered?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="rezaalikhani_0-1728982343302.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231313i27B171D5D6D9211C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rezaalikhani_0-1728982343302.png" alt="rezaalikhani_0-1728982343302.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2024 10:36:05 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2024-10-15T10:36:05Z</dc:date>
    <item>
      <title>Posture Unknown flow for endpoints without Posture agent Installed</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5206267#M592348</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;Consider the following Authorization Policy:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1728541129931.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231023i75E605A0D192F7C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1728541129931.png" alt="rezaalikhani_0-1728541129931.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case, although I have configured the "&lt;STRONG&gt;Default Posture Status&lt;/STRONG&gt;" setting as "&lt;STRONG&gt;Compliant&lt;/STRONG&gt;", but as soon as an endpoint without posture agent installed connects to the network, it matches with the "Posture Unknown" condition and therefore, the limited dACLs applies to it.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 06:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5206267#M592348</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-10-10T06:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Unknown flow for endpoints without Posture agent Installed</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208931#M592451</link>
      <description>&lt;P&gt;The desired VLAN includes both Windows 10 and Windows 7 machines and therefore, when a Windows 7 computer connects to the network, it always matches with the configured "&lt;STRONG&gt;Unknown&lt;/STRONG&gt;" policy which has very limited network connectivity and unfortunately stucks in this stage (because of Windows 7 supportability for ISE Posture Module, the client cannot include this module installed. Right?). I want to bypass this policy for Windows 7 PCs without using Profiling Policy inclusion of just Windows 10 PCs.&lt;/P&gt;&lt;P&gt;The following is the fact from the client (with Windows 7) that ISE has gathered?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="rezaalikhani_0-1728982343302.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/231313i27B171D5D6D9211C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rezaalikhani_0-1728982343302.png" alt="rezaalikhani_0-1728982343302.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 10:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208931#M592451</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-10-15T10:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Unknown flow for endpoints without Posture agent Installed</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208939#M592455</link>
      <description>&lt;P&gt;How about selecting only Win 10 operating system in the posture assessment policy and conditions?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 10:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208939#M592455</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-15T10:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Unknown flow for endpoints without Posture agent Installed</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208975#M592461</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;This is my first possible solution but without success.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 11:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5208975#M592461</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-10-15T11:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Posture Unknown flow for endpoints without Posture agent Installed</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5209525#M592486</link>
      <description>&lt;P&gt;If you could please share the screenshot of your posture assessment configuration for review.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 09:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-unknown-flow-for-endpoints-without-posture-agent/m-p/5209525#M592486</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-16T09:51:53Z</dc:date>
    </item>
  </channel>
</rss>

