02-27-2023 01:22 PM
We are running ISE 3.1 patch 4 and rolling out wired connections with posture checking. the issue we are seeing is with computers on 24x7 , we are a manufacturing plant. With the lease setting at 24 hrs, and the the posture recheck at 12 hours, the computers will scan for posture automatically once at the end of 12 hours, but when the lease expires a user must login and select re-scan to get the device online. Has anyone had devices that have to stay on 24x7 for up to months on ISE? What did you do about the lease and rescan for posture?
02-27-2023 02:45 PM
if that causing the issue, if the industrial device is trusted, I will create a different profile and disable posture checks.
02-27-2023 02:54 PM
02-27-2023 04:01 PM
so all windows PC are the industrial requirements? what windows XP / 7 / 10 or 21H2 ?
02-28-2023 06:03 AM
Nothing older than 10, most should be 21H2.
02-28-2023 06:39 AM
Are you doing the posture assessment via AnyConnect? and are you referring to the lease in the reassessment page or the general posture assessment settings?
02-28-2023 06:42 AM
02-28-2023 11:05 AM - edited 02-28-2023 11:05 AM
I have not tested, will a radius reauth of the port trigger a rescan? We only use AnyConnect for wireless and they tend to bounce on/off all day so never had an issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide