cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Choose one of the topics below for ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.

198
Views
1
Helpful
2
Replies
Highlighted
Beginner

Passive-ressessment issue

Hi,

Tried to implement 1 day Posture lease time with 4 hours PrA.

If I switch on Reassessment Enforcement, and re-connect  a Compliant machine again to net,

it is force a posture check every time.

At ISE posture logs I see a Compliant entry ("Bypass posture since the endpoint is compliant" ),

but immediately afterwards I see a

PRA INFO: PRA is starting

and after this the client preforms a complete re-check.

Why?

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: Passive-ressessment issue

What you are seeing is expected. Since the initial posture is by-passed due to posture lease, the user will get compliant access right away and then PrA will kick off in place of the initial assessment to start off the timer.

Screen Shot 2017-10-21 at 4.56.39 PM.pngScreen Shot 2017-10-21 at 5.22.52 PM.png

2 REPLIES
Cisco Employee

Re: Passive-ressessment issue

Hi.

Please make sure the you have a authz policy with condition that includes session: Agent-request-type = Periodic reassessment.

Periodic reassessment requires machine to be compliant and also choose the appropriate option when configuring Periodic reassessment

from Administration>System>Setting>Posture>Reassessment, choose the enforcement type continue.

Thanks

Krishnan

Cisco Employee

Re: Passive-ressessment issue

What you are seeing is expected. Since the initial posture is by-passed due to posture lease, the user will get compliant access right away and then PrA will kick off in place of the initial assessment to start off the timer.

Screen Shot 2017-10-21 at 4.56.39 PM.pngScreen Shot 2017-10-21 at 5.22.52 PM.png

CreatePlease to create content
Ask the Expert- Webex Hybrid Services Solutions