cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
3760
Views
21
Helpful
2
Replies

Bypassing AnyConnect scan (AnyConnect 4.8)

Hi,

 

I have laptops connecting to the network via Wired and Wireless. I also have desktop connecting via Wired only.

 

About 50% of the time when the laptop boots up onto the Wired network, it gets the message "Bypassing AnyConnect scan — Your network is configured to use the Cisco NAC agent"

 

When I get this message, I have configured the option in the profile to scan again. This works and the client scans, becomes compliant and gains access to the network.

 

The laptop checks for Anti-Malware and also Windows patches. The Anti-Malware check against Compliance of 4.X or later. We are using 4.3.1453.6145 for the compliance module.

 

About 5% of the time, this occurs on the desktops, they check for the same Anti-Malware and also Windows patches.

 

Device

Wireless/Wired

AnyConnect Version

Compliance Module

Policy

AnyConnectConfig

 

 

Laptop

Wireless

4.8.03036

4.3.1453.6145

Use existing policy

PTSB AnyConnect Config

 

 

Laptop

Wired

4.8.03036

4.3.1453.6145

New policy that looks at AD group for Laptops

Wired-Laptops

 

 

Desktop

Wired

4.10.02086

4.3.2336.6145

New policy that looks at AD group for Laptops

Wired-Desktops

 

 

 

Both wired for desktop and laptop going to different AnyConnectConfigs which highlight the AC version and compliance module. All other settings are the same.

 

I have removed all 3.X conditions from ISE. I have removed all unused requirements that come built-in with ISE. I have removed  all unused built-in CPPs in ISE. I now have only the base install and there is no NAC Agent resources, conditions, policies or remediations in ISE.

 

Any ideas.

 

2 Replies 2

Hi @Anthony O'Reilly ,

 generate a DART Bundle on both cases (with and without the issue) and compare both results (check the Cisco AnyConnect ISE Posture Event Viewer).

 

Hope this helps !!!

Mike.Cifelli
VIP Alumni
VIP Alumni

Definitely agree with @Marcelo Morais with the DART idea.  You should see what the module is doing via those logs.  

 

Some other items for consideration:

About 50% of the time when the laptop boots up onto the Wired network, it gets the message "Bypassing AnyConnect scan — Your network is configured to use the Cisco NAC agent"

-This typically means the clients are not matching ISE posture policies.  Is it possible that there is a discrepancy with your posture matching conditions at startup.  Can you share your conditions?  Have you attempted to test another version of AnyConnect on the troubled clients? AnyConnect 4.8.03036 is very old.