03-24-2020 09:21 AM
We are in the process of deploying ISE 2.6 Patch 3 and are using Cisco AnyConnect Network Access Manager for EAP Chaining. We have ran into a a situation where whenever no user is logged into the machine it becomes unreachable (no ping, VNC, etc.). I have attached screenshots of our NAM configuration from the AnyConnect Profile Editor. Are there additional settings in ISE that could be causing this behavior? We currently have a rule in our Policy in ISE that is Temp Roll Out rule that basically allows anything that is profiled as a Workstation, etc. to connect. I have a TAC case open as well but they aren't being very responsive.
Solved! Go to Solution.
03-24-2020 11:26 AM
Thank you so much! The issue was the DACL which I didn't event think that I had applied anywhere but clearly I had somehow managed to do just that. I really appreciate it and I have made adjustments to the DACL and now I am able to connect to the machine as expected when no user is logged in.
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide