06-27-2019 11:52 AM - edited 02-21-2020 11:07 AM
I have a question and would like an answer.
I am using ASA5525 - ISE2.6.
I am preparing to use the Posture feature in the ASA - ISE environment.
I want to group VPN users and apply Posture differently.
I think it identity group in the ISE Posture policy menu.
However, why does the "Posture system scan" proceed when the User "ns3793" is the "test" group in the ISE user identity and the identity group specified in the Posture policy is "B_group"?
I am wondering why the Posture System Scan is proceeding when I try to connect Anyconnect though the groups are different.
Solved! Go to Solution.
06-28-2019 09:26 AM
Looks to be defect from your description. Suggest contacting TAC.
Aside from the user group, are there any other attribute you can use? Are the users in different tunnel group? If so you could try custom condition such as 'Cisco-VPN3000:CVPN/ASA/PIX7x-Tunnel-Group-Name(146)'.
06-28-2019 09:26 AM
Looks to be defect from your description. Suggest contacting TAC.
Aside from the user group, are there any other attribute you can use? Are the users in different tunnel group? If so you could try custom condition such as 'Cisco-VPN3000:CVPN/ASA/PIX7x-Tunnel-Group-Name(146)'.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide