05-31-2023 01:30 AM
Hello,
Is it possible to do clientless posture on vpn users using anyconnect? the set up is like this :
Cisco ISE > Cisco ASA > VPN Users
Do we have any articles/guide regarding this usecase?
Thank you
Solved! Go to Solution.
05-31-2023 03:39 PM
I haven't tested it, but it should be possible since the Posture flow is triggered by the Authorization Policy. The ASA would perform the Authentication then send the request for Authorization to ISE.
I'm not aware of a single document with the full solution, but you should be able to cobble it together with pieces from a couple of different guides.
ISE authorization policy for ASA VPN user certificates
How To: Agentless Posture Configuration, validation & Troubleshooting
05-31-2023 03:39 PM
I haven't tested it, but it should be possible since the Posture flow is triggered by the Authorization Policy. The ASA would perform the Authentication then send the request for Authorization to ISE.
I'm not aware of a single document with the full solution, but you should be able to cobble it together with pieces from a couple of different guides.
ISE authorization policy for ASA VPN user certificates
How To: Agentless Posture Configuration, validation & Troubleshooting
06-02-2023 10:20 AM
Why not do full AnyConnect client posture though? The clients already have AnyConnect installed? Why not push out the ISE Posture module?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide