03-02-2018 08:57 AM
Hi all
In case redirection is not possible and there is no desire to use the static client provisioning URL, if one wants to create that file manually to insert it in the directory C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile\ISE Profile
However, there is a field <PublicKey> in the file that contains the public key.. i assume this is the public key of the ISE certificate? so should be obtaibale and copied to this file , correct?
please confirm and let me know if this can be one of the methods to configure AC and tell it how to contact ISE without redirection
Thanks,
Ahmed.
Solved! Go to Solution.
03-02-2018 08:03 PM
Hello,
The public key in the ISEPostureCFG.xml file is from the ISE node. It's not actually a mandatory component of the file. If you wish to create the ISEPostureCFG.xml manually, you can install the windows anyconnect profile editor suite which contains an app called "ISE posture profile editor".
If you want to do posture without redirection, you'll need to have ISE 2.2 or later and configure the call home list.
03-02-2018 08:03 PM
Hello,
The public key in the ISEPostureCFG.xml file is from the ISE node. It's not actually a mandatory component of the file. If you wish to create the ISEPostureCFG.xml manually, you can install the windows anyconnect profile editor suite which contains an app called "ISE posture profile editor".
If you want to do posture without redirection, you'll need to have ISE 2.2 or later and configure the call home list.
10-12-2020 01:49 PM
Ahmed,
Were you able to install the posture module profile manually in that folder on a computer and it worked without requiring the client to be redirected to the client provisioning portal? I have yet to hear of anyone doing this and I have a client that also wants to distribute the software and profile to his computers without using ISE. It doesn't seem like there is any official documentation on this method.
Thanks!
Mark
10-12-2020 02:33 PM
The posture module actually requires two things for it to function properly. There is the posture module for AnyConnect, and there are the compliance definitions. Both the posture module and the compliance definitions must be installed to sidestep the provisioning portal redirect req (assuming you're on ISE 2.2+ and set the call home list). In total you need 3 items:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide