10-12-2012 03:54 AM - edited 03-10-2019 07:40 PM
Dears,
i have Cisco ISE 1.1.1 with patch installed, i am having a problem with downloading the CIsco NAC agent.
when i click on Install Agent, it is giving the attached message. and sometimes activex failed retrying with applet.
The Web agent is running fine, if i install the NAC agent manualy on my laptop, it is working fine, i have tried 3 laptops with different browser with sames problem.
BR,
10-12-2012 08:47 AM
Hi,
In your client provisioning policy, try selecting another version of the nac agent and see if that fixes your issue, also try to download the offline agent from cisco.com and upload that agent into the ISE resources section and see if that fixes the issue.
Thanks,
Tarik Admani
*Please rate helpful posts*
10-12-2012 12:25 PM
I am also having the same issue. I have modified my dACL to make it work I am just missing something in my Posture remediation ACL.
-CC
10-13-2012 06:37 AM
Dears,
Actually i tried many NAC agent version, same problem. The offline agent is used to download it directly on the workstation without downloading it from the ISE right?
Christopher, can you please share your DACL, i used the one from the ISE Posture guide.
BR,
10-15-2012 04:19 AM
I am going to try and work on narrowing down what it is actually accessing. I also used the gold lab material and it does not work with the downloadable ACL provided. I simply did a PERMTI IP ANY ANY at the end of my dACL and it downloaded the client without issues from my Policy server.
Something is missing.
-CC
10-16-2012 06:18 AM
Here is the downloadable ACL for posture I used to get it to work. It needs TCP 8909 to the Posturing nodes.
permit tcp any any eq www
permit tcp any any eq 443
permit tcp any host
permit tcp any host
permit tcp any host
permit tcp any host
permit tcp any host
permit tcp any host
permit udp any any eq domain
permit udp any host
permit udp any host
permit udp any host
permit udp any host
permit icmp any any
Original LAB ACL
permit udp any any eq domain
permit icmp any any
permit tcp any host 10.1.100.21 eq 8443
permit tcp any any eq 80
permit tcp any any eq 443
permit tcp any host 10.1.100.21 eq 8905
permit udp any host 10.1.100.21 eq 8905
permit udp any host 10.1.100.21 eq 8906
07-15-2013 02:07 AM
Ensure that a client provisioning policy exists in Cisco ISE. If yes, verify the
policy identity group, conditions, and type of agent(s) defined in the policy.
(Also ensure whether or not there is any agent profile configured under Policy >
Policy Elements > Results > Client Provisioning > Resources > Add > ISE
Posture Agent Profile, even a profile with all default values.)
• Try reauthenticating the client machine by bouncing the port on the access
switch.
Remember that the client provisioning agent installer download requires the following:
• The user must allow the ActiveX installer in the browser session the first time an agent is installed
on the client machine. (The client provisioning download page prompts for this.)
• The client machine must have Internet access.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide