11-28-2019 08:44 AM
Hi all,
We are using ISE 2.4. Switch C2960 and PSNs are in node group.
Posture Assessment with AnyConnect (AC) is deploying and having following error:
At 28/11/2019, 17h14’
One PC win 7 has problem that posture status is NotApplicable.
Looking the history of AC in this machine + DART file, we note:
At 08h00’ authC và AuthZ OK by Machine authentication (with empty field of posture status) and then user authentication with posture status=compliant.
History shows that AC posture module running well.
At 12h01 (4 hours later) Machine authentication passed but posture status = NotApplicable (NA)
Looking at history of AnyConnect, we have just report of posture only at 8h00. No more activity of posture noted in the log.
On the DART of this PC, we note that:
At 17h30 : we did shut/no shut the interface connected to this PC on Switch.
AuthC by user and posture status=Compliant.
History of AC on PC noted posture module of AC running and report Posture compliant.
By looking at this situation, we remark that:
Question: why active session gone after 4 hours from ISE?
Thanks for your advice,
Minh
Solved! Go to Solution.
12-02-2019 11:27 AM
Suggest opening a TAC SR, but few things to note:
- Is RADIUS accounting configured on the NAD for at least every 2 days?
- Or is there reauth timer < 60 min configured on the NAD?
Either of above should keep the session tracked from the ISE side.
12-02-2019 11:27 AM
Suggest opening a TAC SR, but few things to note:
- Is RADIUS accounting configured on the NAD for at least every 2 days?
- Or is there reauth timer < 60 min configured on the NAD?
Either of above should keep the session tracked from the ISE side.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide