cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
874
Views
0
Helpful
6
Replies

Anyconnect and temproal agent

Qingguo Zhang
Cisco Employee
Cisco Employee

Is it possible to setup up posture for both anyconnect and temporal agent ?  Not sure CPP can be applicable both.

2 Accepted Solutions

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee

Not both at the same time on the same machine but you can configure CPP for AnyConnect and Temporal agent separately. Especially, with 2.4 you can choose which policies apply to which Agent in the posture policies.Screen Shot 2018-12-19 at 5.23.26 PM.png

View solution in original post

You will need another condition to differentiate the two as both could be applicable.  You can only use one or the other but not both at the same time.  For example, you could use temporal for Windows 7 and AnyConnect for Windows 10.  You could also use AD groups to differentiate as well.

 

Regards,

-Tim

View solution in original post

6 Replies 6

Jason Kunst
Cisco Employee
Cisco Employee
Please explain in more detail your use case

Use case is that for the users with anyconnect installed will do posture directly, for users w/o anyconnect will do temporal agent.

 
Understand Different client provisioning policy can have different conditions,  for existing anyconnect posture user do they still use client provisioning policy to update profile ?
 
We can’t differentiate user other than the condition of anyconnect installed.

Surendra
Cisco Employee
Cisco Employee

Not both at the same time on the same machine but you can configure CPP for AnyConnect and Temporal agent separately. Especially, with 2.4 you can choose which policies apply to which Agent in the posture policies.Screen Shot 2018-12-19 at 5.23.26 PM.png

Screen Shot 2018-12-19 at 10.54.53 PM.png

 

 

can I use the first policy for user who have already installed anyconnect and posture module ,  2nd policy for user w/o anyconnect will go to temporal agent ?

 

 

You will need another condition to differentiate the two as both could be applicable.  You can only use one or the other but not both at the same time.  For example, you could use temporal for Windows 7 and AnyConnect for Windows 10.  You could also use AD groups to differentiate as well.

 

Regards,

-Tim

Surendra and Tim are correct. ISE Client Provisioning Policy is using first match.