<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Posture for non-agent device problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-for-non-agent-device-problem/m-p/2518022#M73553</link>
    <description>&lt;P&gt;I have a couple of questions:&lt;/P&gt;&lt;P&gt;- They said it the documents: "these (non-agent)&amp;nbsp;devices assume the Default Posture Status settings". I wonder how ISE determines that a device is a non-agent device, or to put it another way, when is the Default Posture Status settings applied to a device? Is it after some period of time not receiving anything from the agent? If yes, can and where do I change that time in ISE?&lt;/P&gt;&lt;P&gt;- I tested this with my lab and saw that: after the user successfully login with his account, and the Authorization profile with Client provisioning is applied to that session, the user goes to a web page and gets redirect to the CPP page. Now if he just sits there and doesn't install the NAC agent, I noticed that after about 40s, the session is automatically restarted to a new one, with a different session ID, but&amp;nbsp;the same username. The new session gets to the point where the same redirect Authorization profile is applied and the whole process cycles over and over. Things I observed each time the session restarts:&lt;/P&gt;&lt;P&gt;+&amp;nbsp;The user doesn't even have to enter the credentials again. The 802.1x login doesn't popup&amp;nbsp;&lt;/P&gt;&lt;P&gt;+ The Default Posture status (I set it to Noncompliant) is applied to the session right before it restarts. I can see an event on ISE indicating that. The event also shows the&amp;nbsp;Acct-Terminate-Cause as "Admin Reset"&lt;/P&gt;&lt;P&gt;+ If at any point, the user installs a NAC&amp;nbsp;agent then he can break the cycle (e.g becomes compliant) and carry on with other Authorization profiles&lt;/P&gt;&lt;P&gt;So my question is: is that expected behavior of ISE? Although it seems no harm except new sessions are created continously&lt;/P&gt;&lt;P&gt;Or have I configured something wrong?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:56:20 GMT</pubDate>
    <dc:creator>Tan Do Nhat</dc:creator>
    <dc:date>2019-03-11T04:56:20Z</dc:date>
    <item>
      <title>ISE Posture for non-agent device problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-for-non-agent-device-problem/m-p/2518022#M73553</link>
      <description>&lt;P&gt;I have a couple of questions:&lt;/P&gt;&lt;P&gt;- They said it the documents: "these (non-agent)&amp;nbsp;devices assume the Default Posture Status settings". I wonder how ISE determines that a device is a non-agent device, or to put it another way, when is the Default Posture Status settings applied to a device? Is it after some period of time not receiving anything from the agent? If yes, can and where do I change that time in ISE?&lt;/P&gt;&lt;P&gt;- I tested this with my lab and saw that: after the user successfully login with his account, and the Authorization profile with Client provisioning is applied to that session, the user goes to a web page and gets redirect to the CPP page. Now if he just sits there and doesn't install the NAC agent, I noticed that after about 40s, the session is automatically restarted to a new one, with a different session ID, but&amp;nbsp;the same username. The new session gets to the point where the same redirect Authorization profile is applied and the whole process cycles over and over. Things I observed each time the session restarts:&lt;/P&gt;&lt;P&gt;+&amp;nbsp;The user doesn't even have to enter the credentials again. The 802.1x login doesn't popup&amp;nbsp;&lt;/P&gt;&lt;P&gt;+ The Default Posture status (I set it to Noncompliant) is applied to the session right before it restarts. I can see an event on ISE indicating that. The event also shows the&amp;nbsp;Acct-Terminate-Cause as "Admin Reset"&lt;/P&gt;&lt;P&gt;+ If at any point, the user installs a NAC&amp;nbsp;agent then he can break the cycle (e.g becomes compliant) and carry on with other Authorization profiles&lt;/P&gt;&lt;P&gt;So my question is: is that expected behavior of ISE? Although it seems no harm except new sessions are created continously&lt;/P&gt;&lt;P&gt;Or have I configured something wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-for-non-agent-device-problem/m-p/2518022#M73553</guid>
      <dc:creator>Tan Do Nhat</dc:creator>
      <dc:date>2019-03-11T04:56:20Z</dc:date>
    </item>
    <item>
      <title>Anybody?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-for-non-agent-device-problem/m-p/2518023#M73554</link>
      <description>&lt;P&gt;Anybody?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 08:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-for-non-agent-device-problem/m-p/2518023#M73554</guid>
      <dc:creator>Tan Do Nhat</dc:creator>
      <dc:date>2014-08-18T08:08:17Z</dc:date>
    </item>
  </channel>
</rss>

