cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
418
Views
2
Helpful
3
Replies

Anyconnect Posture Issue

osman869
Level 1
Level 1

Hello,

I have ISE 3.2 Patch 3 and I am doing only posture checks on client machines.

IDEAL SCENARIO (Working with most of the machines)

Step 1- Machine Authenticates = Goes to Limited Access VLAN

Step2- User Logs in = Stays in Limited Access VLAN but AC runs and performs the posture check

Step 3- If PC is complaint = COA and PC will change the VLAN

ISSUE:(Random issue on random machines)

Some machines are stuck in step 2 as they stay in the posture test for some time (even for hours). Sometimes I need to reconnect the Wire or enable disbale the WiFi after step 2 to initiate the connection between client's PC and ISE to perform the compliance.

OBSERVATION:

I am not sure but I doubt that after Step 2 the PC lost (anyconnect) its connectivity to ISE. Its very random issue.

Any clue why this is happening.

 

 

2 Accepted Solutions

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

Much more detail would be needed to provide any meaningful assistance. You would likely be best pulling a DART bundle from one of the problem PCs when it happens an opening a TAC case to investigate.

View solution in original post

3 Replies 3

Greg Gibbs
Cisco Employee
Cisco Employee

Much more detail would be needed to provide any meaningful assistance. You would likely be best pulling a DART bundle from one of the problem PCs when it happens an opening a TAC case to investigate.

Peter Koltl
Level 7
Level 7

Try another Compliance Module version