<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When the client is in Posture in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026612#M67124</link>
    <description>&lt;P&gt;&lt;SPAN&gt;When the client is in Posture required state, and the client does the discovery for the ISE server, WLC intercepts this request. Which interface in the WLC intercepts it, is it the management interface or the interface specified in the webauth profile. Since the VLAN &amp;nbsp;for the SSID is only L2 &amp;amp; if the webauth interface is trying to intercept the packet my posturing will fail&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2017 10:36:32 GMT</pubDate>
    <dc:creator>nikhilcherian</dc:creator>
    <dc:date>2017-05-19T10:36:32Z</dc:date>
    <item>
      <title>5760 ise posture</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026606#M67118</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does 5760 support ISE posturing, I haven't seen any document regarding this nor any discussion in the support forum&lt;/P&gt;
&lt;P&gt;The ISE compatibility matrix says it is supported, has any one worked on posturing with 5760&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nikhil&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026606#M67118</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2021-07-05T14:03:13Z</dc:date>
    </item>
    <item>
      <title>I am assuming you have 5760</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026607#M67119</link>
      <description>&lt;P&gt;I am assuming you have 5760 as MC and 3850 or 3650 as MA and in this setup you are tying to perform posture check for wireless clients through ISE. It should be supported.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Posture validation is more of an ISE apex feature than wireless itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whats important from wireless perspective is if the Authenticator supports COA, which in this case 5760 does.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;**rate helpful posts**&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 11:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026607#M67119</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-05-18T11:47:53Z</dc:date>
    </item>
    <item>
      <title>Hi , </title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026608#M67120</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the reply,&lt;/P&gt;
&lt;P&gt;I just have 5760 &amp;amp; I am trying to perform posture validation for wireless clients. The posture validation is success through &amp;amp; but doesn't work with 5760. My client is stuck in posture_required state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let &amp;nbsp;me know if you have seen any documentation - design/configuration guide for 5760-ISE integration&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nikhil&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 12:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026608#M67120</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-05-18T12:37:34Z</dc:date>
    </item>
    <item>
      <title>http://www.cisco.com/c/en/us</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026609#M67121</link>
      <description>&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5700-series-wireless-lan-controllers/117717-config-wlc-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;its not specific to posture, but validate your configuration with this, use 1812 and 1813 for auth and Acct port and ensure support for RFP3576 is in enabled state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you post the ISE detailed log screenshot, version etc.&lt;/P&gt;
&lt;P&gt;"The posture validation is success through &amp;amp; but doesn't work with 5760. My client is stuck in posture_required state."&amp;nbsp; - Elaborate this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 12:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026609#M67121</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-05-18T12:55:18Z</dc:date>
    </item>
    <item>
      <title>Thanks for the reply, I can</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026610#M67122</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks for the reply, I can see a MACFILTER in WLAN config, which I feel is not required in the case of dot1x.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I don't have the logs with me, but client status is as below&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;gt;1&amp;gt;My client gets connected, hits the POSTURE-UNKNOWN rule in the ISE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;gt;2&amp;gt;Client status is shown as POSTURE_REQD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;gt;3&amp;gt;The anyconnect shows "WEB-AUTHENTICATION-REQD" &amp;amp; asks to open a browser&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;gt;4&amp;gt; If I open the browser, I get a request to enter the credentials( though I have configure SSO)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Nikhil&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 13:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026610#M67122</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-05-18T13:16:29Z</dc:date>
    </item>
    <item>
      <title>I can also see the below</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026611#M67123</link>
      <description>&lt;P&gt;I can also see the below message in my anyconnect&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bypassing AnyConnect scan—Your network is configured to use the Cisco NAC agent.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This message is mentioned in the anyconnect installation guide, but don't have much further explanation.&lt;/P&gt;
&lt;P&gt;I missed some more things on my network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;When I use the PC for with the wired network, I can see the Posturing is a success.&lt;/P&gt;
&lt;P&gt;&amp;gt;When I use the same PC for the Guest access, in the 5760, it is a success. I use CWA with ISE. I use the same redirect ACL for CWA &amp;amp; posturing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; The only point I am stuck is with the posturing in 5760&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 06:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026611#M67123</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-05-19T06:04:53Z</dc:date>
    </item>
    <item>
      <title>When the client is in Posture</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026612#M67124</link>
      <description>&lt;P&gt;&lt;SPAN&gt;When the client is in Posture required state, and the client does the discovery for the ISE server, WLC intercepts this request. Which interface in the WLC intercepts it, is it the management interface or the interface specified in the webauth profile. Since the VLAN &amp;nbsp;for the SSID is only L2 &amp;amp; if the webauth interface is trying to intercept the packet my posturing will fail&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 10:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026612#M67124</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-05-19T10:36:32Z</dc:date>
    </item>
    <item>
      <title>What's there an address where</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026613#M67128</link>
      <description>&lt;P&gt;What's there an address where I can send you some&amp;nbsp;email ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not I would recommend engage TAC, there a lot of floating information, posture issues are easy to solve but I need to look into you policy, and failure logs on wlc as well as ISE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 13:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026613#M67128</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-05-19T13:07:07Z</dc:date>
    </item>
    <item>
      <title>you can mail me in nikhs@live</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026614#M67129</link>
      <description>&lt;P&gt;you can mail me in nikhs@live.com&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 18:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3026614#M67129</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-05-19T18:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: When the client is in Posture</title>
      <link>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3299088#M67130</link>
      <description>Just in case this is helpful to anyone, I am adding something I found&lt;BR /&gt;1. In my setup, I got the message "Bypassing AnyConnect scan—Your network is configured to use the Cisco NAC agent." because the client wasn't hitting the CP rules&lt;BR /&gt;2. I added one more rule specific to the Wireless controller in the CP, saying if the "RADIUS called station id end with XYZ", this is the use the CP profile, Thanks to my friend who pointed out this to me&lt;BR /&gt;3. With this also, I didn't find my client downloading the Posture rule. &lt;BR /&gt;4. I had to edit the posture rules &amp;amp; add a specific rule to the Posture condition, saying if the "RADIUS called station id end with XYZ" use this Posture condition. This helped me to resolve the issues</description>
      <pubDate>Wed, 20 Dec 2017 04:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5760-ise-posture/m-p/3299088#M67130</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2017-12-20T04:26:18Z</dc:date>
    </item>
  </channel>
</rss>

