cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4391
Views
2
Helpful
8
Replies

Anyconnect posture issue

afahmy
Cisco Employee
Cisco Employee

Hi all, customer is trying to use Anyconnect posture module for posture. ISE 2.3 in use. Anyconnect package and compliance module uploaded on ISE (client provisoining steps are all done the same way done in lab successfully before many many times!),..so what happens is Authentication succeeds and end user is able to access client provisioning portal (via static FQDN) but the client is not actually downloaded and instead user is given compliant status right away once they hit the start button !!!

if try to download AC manually it won't see ISE server although redirect rules are in place on switch and are working on other PCs where NAC agent is installed (note this is a fresh PC with no NAC agent installed before Anyconnect). Configured call home list on ISE but of course Anyconnect is not able to download the configuration from ISE because it can't see it. The DACL is currently permit any any. So it can't be the reason communication is failing.

has anybody seen this before? Is there a way to install ISEPostureCFG.xml on the PC with the manual install of Anyconnect ?

1 Accepted Solution

Accepted Solutions

Yes. Exactly. It just give me internet access without installing the client.

I have to delete the client provisioning rules and reconfigure that rule.

And it works like magic.

Regards,

Sai

View solution in original post

8 Replies 8

afahmy
Cisco Employee
Cisco Employee

Thanks but I don’t know how that helps ?

I have a specific issue I’m trying to solve

Sent from my iPhone

afahmy
Cisco Employee
Cisco Employee

Thank Danny, you’re focusing only on the last part of the question.

My main question is whether someone has experienced this behavior before where the end user gets to the client provisioning portal, hits start but the AC package doesn’t download and they are instead provided compliant status immediately without installing the client.

ldanny
Cisco Employee
Cisco Employee

Will do some research and follow up..

danielsai
Level 1
Level 1

Hi Afahmy,

I have faced that issue a few weeks ago in my lab environment. I was testing to migrate NAC to Anyconnect.

Following are some issue that i've encounter,

  • Client provisioning rules from the ISE for NAC and Anyconnect could not co-exist in recent patches.(If we configure both under same condition, the rules were stop working. I've tested it
  • Client provisioning rules or Posture check rules are not working after we edited the rule. (We delete existing rule and create new rules again).

You can pre install anyconnect software in your machine and AC will download your AC configuration and compliance module once you connect to network or you could do a manually provisioning.

Hope you could get something from this.

Regards,

Daniel Sai

Sami

Did it give you compliant WITHOUT installing the client ?

Thanks

Ahmed

Sent from my iPhone

Yes. Exactly. It just give me internet access without installing the client.

I have to delete the client provisioning rules and reconfigure that rule.

And it works like magic.

Regards,

Sai