08-24-2021 11:06 PM - edited 08-24-2021 11:08 PM
Hi
We have Cisco AnyConnect VPN solution with posture check on ISE. For this posture compliance module is pushed via client provisioning portal from ISE. Now we are planning to upgrade Cisco AnyConnect VPN + posture client. But when we push new AnyConnect client and compliance module via SCCM, and try to connect with new version of clients, still old modules getting downloaded and ultimately failing.
Can someone recommend how we should upgrade Cisco AnyConnect secure mobility client with posture check.
Solved! Go to Solution.
08-24-2021 11:40 PM
You should modify your Posture AnyConnect configuration file, and to enable deferral. This means that ISE will not push updates, for as long as you are on minimum defined versions (your current versions):
This means that if your AnyConnect is at minimum v.4.10.01075, and/or your compliance module is it at minimum version v4.3.1770.6145, ISE won't force update. These versions should be your current ones, while new versions should be defined in configuration file.
BR,
Milos
08-24-2021 11:40 PM
You should modify your Posture AnyConnect configuration file, and to enable deferral. This means that ISE will not push updates, for as long as you are on minimum defined versions (your current versions):
This means that if your AnyConnect is at minimum v.4.10.01075, and/or your compliance module is it at minimum version v4.3.1770.6145, ISE won't force update. These versions should be your current ones, while new versions should be defined in configuration file.
BR,
Milos
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide