cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
293
Views
1
Helpful
1
Replies

Cisco ISE 3.2 and Cisco Secure Client with ISE Posture Issues

Frank Durham
Level 1
Level 1

Hi Community..

I have seem to run into a problem testing out ISE Posture via Cisco FTD and Secure Client.   I have followed a few videos on line for reference and read this article from Cisco; 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215236-ise-posture-over-anyconnect-remote-acces.html

I believe I have everything properly, but when I initiate a connection on the Secure Client; I get the dreaded "The IPsec VPN connection was terminated due to an authentication failure or timeout".  What is strange is authentication is not the issue for these reasons.

  • If i remove the posture configs from the Policy set and do a simple secure client connection using the same username/password, I am able to connect
  • When the posture configs are enabled in the policy sets; and I do live logs or reporting, I can see my username for Authorize-Only, the correct policy set was chosen, redirect ACL applied along with downloadable ACL and the posture status says "pending"  but no connection on the secure client

TAC is puzzled and still waiting for response.  Wanted to ask the community if anyone has seen or experienced this behavior.

Thanks

Frank

1 Reply 1

start with anyconnect 

Screenshot (294).png

share screen shot 

MHM