cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1330
Views
0
Helpful
1
Replies

How AnyConnect UUID is made

jpoh
Cisco Employee
Cisco Employee

Hi Team,

customer is interested on posture lease feature where they can posture user once per day instead of every login. Saw below statement in tech zone.

"

  • To avoid re-posture at each session id change posture lease can be used. In this scenario information about posture status is stored in the endpoint attributes which stays on ISE even if session ID gets changed.

"

Is the end point attributes refer to AnyConnect UUID? If yes, how we do form this UUID? Can this UUID easily con by others to fool ISE? Customer is using master image for all new laptop. Does this mean all laptop will have same UUID for AC?

 

Appreciate and hope to get advise on UUID area. The InfoSec team of this customer don;t approve posture lease of 1 day as they think AC UUID can be con by others. Will be good if we have links or document that explain how we generate the UUID during installation.

 

Regards &

Have a nice day

1 Reply 1

hslai
Cisco Employee
Cisco Employee

See UDID Integration

The endpoint attribute is PostureExpiry. IIRC, ISE uses UDID to query the endpoint for that attribute and verify whether it expires.