cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
14045
Views
7
Helpful
3
Replies

Anyconnect Posture ISEPostureCFG.xml file

afahmy
Cisco Employee
Cisco Employee

Hi all

In case redirection is not possible and there is no desire to use the static client provisioning URL, if one wants to create that file manually to insert it in the directory C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile\ISE Profile


However, there  is a field <PublicKey> in the file that contains the public key.. i assume this is the public key of the ISE certificate? so should be obtaibale and copied to this file , correct?

please confirm and let me know if this can be one of the methods to configure AC and tell it how to contact ISE without redirection

Thanks,

Ahmed.

1 Accepted Solution

Accepted Solutions

Hello,

The public key in the ISEPostureCFG.xml file is from the ISE node.  It's not actually a mandatory component of the file.  If you wish to create the ISEPostureCFG.xml manually, you can install the windows anyconnect profile editor suite which contains an app called "ISE posture profile editor".

If you want to do posture without redirection, you'll need to have ISE 2.2 or later and configure the call home list.

View solution in original post

3 Replies 3

Hello,

The public key in the ISEPostureCFG.xml file is from the ISE node.  It's not actually a mandatory component of the file.  If you wish to create the ISEPostureCFG.xml manually, you can install the windows anyconnect profile editor suite which contains an app called "ISE posture profile editor".

If you want to do posture without redirection, you'll need to have ISE 2.2 or later and configure the call home list.

Mark DeLong
Level 4
Level 4

Ahmed,

 

Were you able to install the posture module profile manually in that folder on a computer and it worked without requiring the client to be redirected to the client provisioning portal? I have yet to hear of anyone doing this and I have a client that also wants to distribute the software and profile to his computers without using ISE. It doesn't seem like there is any official documentation on this method.

 

Thanks!

Mark

The posture module actually requires two things for it to function properly.  There is the posture module for AnyConnect, and there are the compliance definitions.  Both the posture module and the compliance definitions must be installed to sidestep the provisioning portal redirect req (assuming you're on ISE 2.2+ and set the call home list).  In total  you need 3 items:

  1. ISEPostureCFG w/ call home list
  2. Posture module
  3. Compliance definitions