cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

12706
Views
5
Helpful
2
Replies
Andrew Mathu
Beginner

Cisco ISE Posture: Failed to Perfom the required client update checks. Contact your System Administrator.

Hello All,

 

We are running ISE version 2.3 with patch 3. We have installed the following Anyconnect and Compliance Modules:

anyconnect-win-4.5.03040-core-vpn-predeploy-k9

anyconnect-win-4.5.03040-iseposture-predeploy-k9

anyconnect-win-3.6.11682.2-isecompliance-predeploy-k9

 

Some users upon connecting are getting error below in the compliance module:

"Failed to perform required client update checks. Contact your system administrator."

In the AnyConnect icon the error is displayed as "Failed to launch downloader."

 

We mostly have Windows 10 Pro devices (laptops and workstations).

What could be causing the error?

1 ACCEPTED SOLUTION

Accepted Solutions
Rob Ingram
VIP Mentor

Hi,

My first thought is the AnyConnect client is attempting to upgrade or install a module. Unless the user is an administrator they would not be able to install the client.

Have you pre-deployed all modules, including the compliance module?

You can use the bypass downloader, this is configured in the AnyConnectLocalPolicy.xml file, use the AnyConnect Profile Editor - VPN Local Policy to modify this value, or edit the xml file direct.

In ISE you have the option to require a minimum version, make sure this is not set.

HTH

View solution in original post

2 REPLIES 2
Rob Ingram
VIP Mentor

Hi,

My first thought is the AnyConnect client is attempting to upgrade or install a module. Unless the user is an administrator they would not be able to install the client.

Have you pre-deployed all modules, including the compliance module?

You can use the bypass downloader, this is configured in the AnyConnectLocalPolicy.xml file, use the AnyConnect Profile Editor - VPN Local Policy to modify this value, or edit the xml file direct.

In ISE you have the option to require a minimum version, make sure this is not set.

HTH

View solution in original post

I ran into this issue today.  I have seen a lot of posts on the community, but none that helped me.  My solution was simple.  The version of AnyConnect on the firewall must be the same version of AnyConnect specified in the ISE configuration.  In my case, I am pushing the AnyConnect ISE Posture module from the firewall.

Content for Community-Ad