08-30-2026 03:31 AM
Hello Team,
need some inputs of experts, in our organization few emp are getting network access blocked status on secure client (highlighted in yellow) and after some time it get auto resolved, and after some time like 30 to 40mnt it gets blocked again automatic.
I am not seeing any such error in ISE radius logs, need your suggestion what to check.
we are using secure client with posture for wired users and VPN users. attached screenshot for reference.
08-30-2026 09:43 AM
- @Cisco ISE Bigner You have no screenshot attached , please try again
M.
08-30-2026 09:49 AM
hello @Mark Elsen,
attached screenshot and issue we are seeing only for user connecting from office.
08-30-2026 10:13 AM
- @Cisco ISE Bigner Ref : https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture.html
You will need to look into : https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture.html#toc-hId-2003437760
and https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture.html#toc-hId-195983297
M.
08-31-2026 04:52 AM
The text in your AnyConnect / Secure Client module indicates that you are using (intentionally or not) the "Trusted Network Policy" (https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/Cisco-Secure-Client-5/admin/guide/b-cisco-secure-client-admin-guide-5-1/m_configure_vpn_access-noth.html#id_100236)
You can create a DART (Diagnostics And Reporting Tool) bundle for an affected client and share it with Cisco TAC for resolution. They should be able to point out the issue for you. It's difficult to do so in a public forum as the DART bundle will include sensitive information about your network settings.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide