08-14-2020 06:48 PM
I have a scenario where in a corporate user connects to vpn and will go through posture check via ISE. Now if the user machine goes to compliant state, and intentionally disable/uninstall (e.g. windows firewall) can ISE detect this in real time and automatically re-scan? So if it detected that the firewall has been removed or disabled, ISE can issue a CoA push so that it will go to non-compliant state.
I tested this in my home lab and I can't make it work (see attached screenshot). Not sure which settings to tune in ISE. I can't find any documentation if this scenario is supported or not.
Solved! Go to Solution.
08-15-2020 07:00 PM
08-17-2020 07:48 PM
poongarg is correct that your best bet is to use PRA as ISE Posture does not trigger real-time detection of such activities.
08-15-2020 07:00 PM
08-17-2020 07:48 PM
poongarg is correct that your best bet is to use PRA as ISE Posture does not trigger real-time detection of such activities.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide