<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Closed Mode and Posture Check in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5254647#M594637</link>
    <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Authentication is successful, but the workstation can't send its posture to ISE.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I get the error: "Cisco ISE unable to detect AnyConnect posture agent." on the workstation&lt;/P&gt;&lt;P&gt;Strangely, everything works fine after a shut/no shut action on the port. However, on the first boot, it fails at the switch redirect and doesn't let me pass this first step.&lt;BR /&gt;&lt;BR /&gt;Thanks for your help.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ISE Version: 3.4&lt;BR /&gt;ISE Secure Client: 5.1.7.80&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Extended IP access list ACL_REDIRECT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 deny udp any eq bootpc any eq bootps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;20 deny udp any any eq domain&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;30 deny ip any host &amp;lt;cisco ise ip address&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;40 permit tcp any any eq www&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;50 permit tcp any any eq 443&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;60 deny ip any any&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 30 Jan 2025 09:20:49 GMT</pubDate>
    <dc:creator>David-IT</dc:creator>
    <dc:date>2025-01-30T09:20:49Z</dc:date>
    <item>
      <title>Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251472#M594426</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm facing some challenges while configuring Posture with closed mode and an IBNS 2 setup.&lt;/P&gt;&lt;P&gt;First, is it possible to perform posture checks in closed mode?&lt;/P&gt;&lt;P&gt;How did you manage port configuration and ACL/DACL settings?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Should the ACL be used for redirection and the DACL for granting access?&lt;/LI&gt;&lt;LI&gt;Did you configure VLAN access on the switch port settings or within the authorization profile?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My configuration seems to be working, but the PC never connects when booting while already plugged in.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 09:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251472#M594426</guid>
      <dc:creator>David-IT</dc:creator>
      <dc:date>2025-01-23T09:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251478#M594427</link>
      <description>&lt;P&gt;But as I know posture not work with close mode you need low impact mode allow some traffic between client and ISE after posture success the client will get full access&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 09:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251478#M594427</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-23T09:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251488#M594428</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1835590"&gt;@David-IT&lt;/a&gt; yes you can perform ISE posture in closed mode, you just need to ensure the devices pass authentication - so ensure you have run monitor mode for a period.&lt;/P&gt;
&lt;P&gt;Typically posture is only run when the user logins in, not when the computer is authenticating. What authorisation policy rules do you have configured?&lt;/P&gt;
&lt;P&gt;You use the ACL pre-configured on the switch if you redirection based posture or use the redirectionless method, then you don't need the ACL. &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/210523-ISE-posture-style-comparison-for-pre-and.html#anc7&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Yes, the DACL is applied post authentication. You can apply a different DACL, depening on whether the device is compliant or non-compliant.&lt;/P&gt;
&lt;P&gt;Having multiple VLANs is an administrative overhead. I would typically rely on the switchport to define the VLAN, if you wish to restrict access then push down the DACL or use SGTs depending on posture compliance.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 09:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5251488#M594428</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-23T09:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5253270#M594536</link>
      <description>&lt;P&gt;Everything works well, especially when I disconnect the cable.&lt;BR /&gt;The ACL, web browser pop-up, and all checks confirm that everything is functioning correctly.&lt;/P&gt;&lt;P&gt;However, the main issue arises when I start the PC.&lt;BR /&gt;In this situation, the automatic check does not run, and even when I try to manually trigger the checks through the browser, I have error with agent is not detected. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 15:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5253270#M594536</guid>
      <dc:creator>David-IT</dc:creator>
      <dc:date>2025-01-27T15:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5253277#M594537</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1835590"&gt;@David-IT&lt;/a&gt; what policies have you configured? For computer / users etc - provide screenshots.&lt;/P&gt;
&lt;P&gt;What is the state of "show authentication session interface gig x/x/x detail" when it fails and when it does work?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 15:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5253277#M594537</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-27T15:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5254647#M594637</link>
      <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;Authentication is successful, but the workstation can't send its posture to ISE.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I get the error: "Cisco ISE unable to detect AnyConnect posture agent." on the workstation&lt;/P&gt;&lt;P&gt;Strangely, everything works fine after a shut/no shut action on the port. However, on the first boot, it fails at the switch redirect and doesn't let me pass this first step.&lt;BR /&gt;&lt;BR /&gt;Thanks for your help.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ISE Version: 3.4&lt;BR /&gt;ISE Secure Client: 5.1.7.80&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Extended IP access list ACL_REDIRECT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10 deny udp any eq bootpc any eq bootps&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;20 deny udp any any eq domain&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;30 deny ip any host &amp;lt;cisco ise ip address&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;40 permit tcp any any eq www&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;50 permit tcp any any eq 443&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;60 deny ip any any&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 30 Jan 2025 09:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5254647#M594637</guid>
      <dc:creator>David-IT</dc:creator>
      <dc:date>2025-01-30T09:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5255984#M594726</link>
      <description>&lt;P&gt;After some troubleshooting, I discovered that my laptop was making two authentication requests during a cold boot. Although both requests used the same RADIUS username, the identities in the logs were different—one was &lt;EM&gt;&lt;A rel="noopener" target="_blank"&gt;&lt;SPAN&gt;hostname&lt;/SPAN&gt;&lt;SPAN&gt;@domain&lt;/SPAN&gt;&lt;SPAN&gt;.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/EM&gt; and the other was &lt;EM&gt;host/hostname@domain.com&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;I eventually disabled both options (Stateless Session Resume and EAP-TLS Session Resume), and the authentication became unique after a cold boot. Only one request, &lt;EM&gt;&lt;A rel="noopener" target="_blank"&gt;&lt;SPAN&gt;hostname&lt;/SPAN&gt;&lt;SPAN&gt;@domain&lt;/SPAN&gt;&lt;SPAN&gt;.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/EM&gt;, remained, and the issue was resolved.&lt;/P&gt;&lt;P&gt;Any thoughts on what might have caused this?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 07:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5255984#M594726</guid>
      <dc:creator>David-IT</dc:creator>
      <dc:date>2025-02-03T07:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5256224#M594741</link>
      <description>&lt;P&gt;I think the host/hostname@domain.com would come first because that would be belonging to the machine authentication and the &lt;A href="mailto:hostname@domain.com" target="_blank"&gt;hostname@domain.com&lt;/A&gt;&amp;nbsp;would belong to the user authentication. The TLS session resume might have allowed ISE to use the cached information from the previous session, but tbh I don't think you should change turn off that. How did you configure the NIC for dot1x? and how ISE policies are configured? are you doing dot1x for both machine and users?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 18:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5256224#M594741</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-02-03T18:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Closed Mode and Posture Check</title>
      <link>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5257085#M594767</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;I did some digging, and it turns out that simply enabling "stateless authentication resume" causes this issue.&lt;BR /&gt;It's quite strange and have simply removed this option.&lt;BR /&gt;&lt;BR /&gt;(ISE issues TLS client a session ticket that can be presented to any PSN to shortcut reauth process)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 05 Feb 2025 11:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/closed-mode-and-posture-check/m-p/5257085#M594767</guid>
      <dc:creator>David-IT</dc:creator>
      <dc:date>2025-02-05T11:14:33Z</dc:date>
    </item>
  </channel>
</rss>

