cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1226
Views
5
Helpful
2
Replies

ISE Posture Auto-Remediation

Rob4
Cisco Employee
Cisco Employee

Quick Question about Posture Auto-Remediation for AM Definition updates - will the auto-remediation occur during the unknown posture status or non-compliant?? In my testing it appears to "update" during the posturing process and happens during the unknown status. Is this expected? 

 

 

Thanks

1 Accepted Solution

Accepted Solutions

Colby LeMaire
VIP Alumni
VIP Alumni

Yes, that is how it works.  You would need to ensure that you allow the connectivity in your redirect ACL and any other ACL's that are applied while in the Posture Unknown state.  Non-compliant is for those devices that are given time to remediate but are not able to within the time allowed by the policy.  For example, a case where the AM updates don't work due to connectivity issue or something else.  Then that device would be considered non-compliant.

View solution in original post

2 Replies 2

Colby LeMaire
VIP Alumni
VIP Alumni

Yes, that is how it works.  You would need to ensure that you allow the connectivity in your redirect ACL and any other ACL's that are applied while in the Posture Unknown state.  Non-compliant is for those devices that are given time to remediate but are not able to within the time allowed by the policy.  For example, a case where the AM updates don't work due to connectivity issue or something else.  Then that device would be considered non-compliant.

Thanks so much, that makes sense.