cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
524
Views
1
Helpful
2
Replies

Cisco ISE Clientless Posture with VPN users

rafliraditya
Level 1
Level 1

Hello,

Is it possible to do clientless posture on vpn users using anyconnect? the set up is like this :

Cisco ISE > Cisco ASA > VPN Users

Do we have any articles/guide regarding this usecase?

Thank you

 

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

I haven't tested it, but it should be possible since the Posture flow is triggered by the Authorization Policy. The ASA would perform the Authentication then send the request for Authorization to ISE.

I'm not aware of a single document with the full solution, but you should be able to cobble it together with pieces from a couple of different guides.

ISE authorization policy for ASA VPN user certificates 

How To: Agentless Posture Configuration, validation & Troubleshooting 

View solution in original post

2 Replies 2

Greg Gibbs
Cisco Employee
Cisco Employee

I haven't tested it, but it should be possible since the Posture flow is triggered by the Authorization Policy. The ASA would perform the Authentication then send the request for Authorization to ISE.

I'm not aware of a single document with the full solution, but you should be able to cobble it together with pieces from a couple of different guides.

ISE authorization policy for ASA VPN user certificates 

How To: Agentless Posture Configuration, validation & Troubleshooting 

Why not do full AnyConnect client posture though?  The clients already have AnyConnect installed?  Why not push out the ISE Posture module?