08-11-2020 07:01 AM
Hi Guys,
I am deploying a new network and I am implementing posture assessment over wired, wireless and VPN.
I would like to achieve this: when a user is compliance, the user can connect to any other corp network without performing another posture scan.
I have configured ISE to perform posture assessment once every day, but I still get scanned everytime I connect.
If I disable redirection and removed the discovery host and just use call home list, I don't get scanned everytime but on ISE my posture status is still unknown.
can you please assist?
Regards,
Albert
08-11-2020 07:50 AM
Sounds like an issue with your authorization policy. When you are being scanned every time you connect, verify which authorization policy rule you are hitting. Your rules should be something like below and the order matters:
Posture Status = Compliant -> Full Access/No Redirect
Posture Status != Compliant -> Limited Access/Posture Redirect
Sounds like you are not hitting your compliant rule to give full access.
08-11-2020 08:00 AM
08-11-2020 08:11 AM
Can you send a screenshot of your compliant and unknown posture rules? You have to look at why you are not hitting the compliant rule.
08-11-2020 08:22 AM - edited 08-11-2020 08:29 AM
08-11-2020 10:13 AM
On your most recent successful authentication in Live Logs, open up the details and scroll down on the left side. Do you see the proper EAP-Chaining result of Machine passed and User passed? Do you also see Posture Status of Compliant?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide