02-02-2013 11:58 AM - edited 03-10-2019 08:02 PM
I am doing ISE (1.1.1) deployment for client. The customer is using AD logon script do do drive map to a nas server. My posture remediation acl is blocking drive mapping unless I use 'permit ip any any' which is a security hole. My acl should be modified to allow the drive mapping during unknown/posture-remediation interval. Could any one suggest if you have faced similar issue.
03-12-2013 11:23 PM
You need to permit access to your domain controllers during posture remediation and add a delay to your logon script -
http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a70c18.shtml
03-15-2013 05:53 AM
Hi,
I depolyed the same ACL and typically if you allow the ports you will not see the drive mapping issues. Just make sure you are not flipping vlans around or you will run into issue just as this, unless you choose to run login scripts.
Thanks,
Tarik Admani
*Please rate helpful posts*
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide