cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
5225
Views
5
Helpful
7
Replies

Anyconnect ISE Posture

aravikumar
Level 1
Level 1

When the endpoint configured for EAP-TLS machine authentication using machine certificate connects to network. Posture becomes compliant but the posture is happening repetitively. It always shows the following dialog box. Tried reinstalling the AC on the endpoint. The same is successful for wireless but failing for wired. Please help.

 

 

1 Accepted Solution

Accepted Solutions

* is ok. I think then that your issue is your cert being used for ISE that is being presented. Is your server name identified at the bottom of the chain and in the common name? I think the ISE hostname needs to be reflected there. If using a wildcard cert you should be able to configure the psn hostnames as SAN.

View solution in original post

7 Replies 7

Mike.Cifelli
VIP Alumni
VIP Alumni
Please ensure that your host/s you are seeing the issue on have the cert chain being presented in the trusted stores. Then attempt to replicate the issue again.

Hi Mike 

 

Thanks for the reply, The Certificate chain is there on the host and the trusted store in ISE. But the issue still persists.

 

Thanks,

 

Aravind.

After multiple attempts it says posture failed due to server issues

Please double check your profile configuration in ISE. Under the posture protocol 'server name rules' does that match the cert name being presented? What do you have configured there?

Policy->Policy elements->Results->Client Provisioning->Resources-><your profile>

I have it configured as "*". I have attached the screenshot, should I have the ISE PSNs listed there?

* is ok. I think then that your issue is your cert being used for ISE that is being presented. Is your server name identified at the bottom of the chain and in the common name? I think the ISE hostname needs to be reflected there. If using a wildcard cert you should be able to configure the psn hostnames as SAN.

Mike.Cifelli is correct on this. Note that an ISE node may use different server certificates for admin and for portals. If you are not using FQDN with the port number configure for the client provisioning portal in the Call Home List (available in ISE 2.2+), the posture might use the cert for "admin".

If you need further help to troubleshoot this, please engage Cisco TAC.