<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi DennisI got a similar in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629511#M73908</link>
    <description>&lt;P&gt;Hi &lt;SPAN class="fullname" itemprop="author"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/dennisnieuwenhuyzen" title="View user profile."&gt;Dennis&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I got a similar scenario. Were you able to find a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;G&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2015 06:01:13 GMT</pubDate>
    <dc:creator>Gaj Ana</dc:creator>
    <dc:date>2015-10-08T06:01:13Z</dc:date>
    <item>
      <title>Cisco ISE (1.3) Posture without Client Provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629510#M73907</link>
      <description>&lt;P&gt;Hello readers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to set up Cisco ISE with posture &lt;B&gt;without&amp;nbsp;&lt;/B&gt;Client Provisioning?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customer deploys the NAC Agent via MS SCCM. We prefer a access accept + DACL during the pending state instead of redirecting to client provisioning. But the NAC Agent will only communicate when we redirect to client provisioning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629510#M73907</guid>
      <dc:creator>dennisnieuwenhuyzen</dc:creator>
      <dc:date>2019-03-11T05:34:30Z</dc:date>
    </item>
    <item>
      <title>Hi DennisI got a similar</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629511#M73908</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="fullname" itemprop="author"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/dennisnieuwenhuyzen" title="View user profile."&gt;Dennis&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I got a similar scenario. Were you able to find a solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 06:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629511#M73908</guid>
      <dc:creator>Gaj Ana</dc:creator>
      <dc:date>2015-10-08T06:01:13Z</dc:date>
    </item>
    <item>
      <title>The NAC agent needs to be</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629512#M73909</link>
      <description>&lt;P&gt;The NAC agent needs to be redirected to find the PSN node that is servicing the session that was created when the switch/wlc tried to authenticate the user/machine, this is why you can't hardcode an ise server into the nac agent. However if you configure a discovery host in your nac client, then that is the only ip address you need to create a redirect for in your acl, everything else can be allowed. So just pick an unused ip address thats routeable, and use that as discovery host, then make sure that you redirect to provisioning when the agent makes it's http request on port 80 to that ip.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 17:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629512#M73909</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-10-08T17:00:39Z</dc:date>
    </item>
    <item>
      <title>Hi JanThanks for the feedback</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629513#M73910</link>
      <description>&lt;P&gt;Hi Jan&lt;/P&gt;&lt;P&gt;Thanks for the feedback.&lt;/P&gt;&lt;P&gt;If we don't use the discovery host and in the case of pre-deployed agent just wondering how does the agent will try to discover a PSN . Assuming there can be more than one PSN's in a distributed setup and since the browser method is not used no session is created initially and agent is unaware which PSN to connect to?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;G&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 23:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629513#M73910</guid>
      <dc:creator>Gaj Ana</dc:creator>
      <dc:date>2015-10-08T23:28:12Z</dc:date>
    </item>
    <item>
      <title>The Agent will run through</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629514#M73911</link>
      <description>&lt;P&gt;The Agent will run through different probes to detect the redirect with the session in the url, to find the psn. If there is no redirect, it will never find the psn, this is required to make it work. This is a good guide for technical info on the swiss protocol : http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/118724-technote-ise-00.html#anc2&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 23:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629514#M73911</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-10-08T23:36:27Z</dc:date>
    </item>
    <item>
      <title>I indeed solved it without</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629515#M73912</link>
      <description>&lt;P&gt;I indeed solved it without hardcoding the ISE server in the NAC-agent. The problem we had was that when not using GigE0 Cisco ISE returned a IP-adres of the interface instead of a hostname. We resolved this using the ip host command on the PSN cli.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/cli_ref_guide/ise_cli/ise_cli_app_a.html#pgfId-2567879&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 05:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629515#M73912</guid>
      <dc:creator>dennisnieuwenhuyzen</dc:creator>
      <dc:date>2015-10-09T05:22:48Z</dc:date>
    </item>
    <item>
      <title>Thanks Dennis</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629516#M73913</link>
      <description>&lt;P&gt;Thanks Dennis&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 12:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629516#M73913</guid>
      <dc:creator>Gaj Ana</dc:creator>
      <dc:date>2015-10-09T12:10:36Z</dc:date>
    </item>
    <item>
      <title>Thanks Jan</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629517#M73915</link>
      <description>&lt;P&gt;Thanks Jan&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 12:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-posture-without-client-provisioning/m-p/2629517#M73915</guid>
      <dc:creator>Gaj Ana</dc:creator>
      <dc:date>2015-10-09T12:11:34Z</dc:date>
    </item>
  </channel>
</rss>

