cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1079
Views
2
Helpful
4
Replies

How to keep endpoint alive after session termination

Jeffrey Jones
Level 5
Level 5

Situation: User logs off system terminating session with ISE, how can an administrator still get to the device for windows updates, etc, or to log in to the system to troubleshoot. VNC is installed on endpoints, but we can not even RDP to the endpoint.

ISE version 2.1 patch 1 and 2, AnyConnect version 4.3 with NAM and ISE Posture, DART also installed.

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

Jeffrey,

I have already responded to your question in other post here: Re: ISE 1.4 API remove stale sessions

You can use Low Impact Mode or return a default MAB-based policy that grants required access.

Craig

View solution in original post

4 Replies 4

Craig Hyps
Level 10
Level 10

Jeffrey,

I have already responded to your question in other post here: Re: ISE 1.4 API remove stale sessions

You can use Low Impact Mode or return a default MAB-based policy that grants required access.

Craig

Charlie Moreton
Cisco Employee
Cisco Employee

This is a good question.  I think that if you have implemented machine authentication (AD Domain Joined Machines), you should be able to do this.

I have an Authorization Compound Condition (Policy > Policy Elements > Conditions > Authorization > Compound Conditions) set up like this:

CompCond.png

Which is used in my Wired Access Policy Set (Policy > Policy Sets)

machine policy.PNG

The permissions (AD-ONLY) given are set at Policy > Policy Elements > Results > Authorization Profiles.  Of course, you'll need a DACL for this, too (Policy > Policy Elements > Results > Downloadable ACLs).

AuthProf.PNG

And that should give you the access you desire.

This works great on Cisco switches, but not on HP ProCurve which this customer has. cant do dacl

Then reference the ACL on the switch:

AuthProACL.PNG