03-27-2021 10:30 PM
Dear community,
I've set the posture lease to 2 days in ISE and it's working as expected in Wireless but whenever the client connects to the wired network it always goes through the posture check.
For additional info, the authentication request always goes to the same PSN node and in the Endpoint Attributes in ISE shows posture expiry time is 2 days for the endpoint.
Kindly advise if some one had similar issue and resolved. Thanks
Arun
03-30-2021 10:05 AM
What version of ISE are you running? How are your global ISE Posture settings configured? What do you have configured for: Cache Last Known Posture Compliant Status
-Is it possible that the wired mac is not present in the ISE DB so ISE thinks the client is new when using wired therefore triggering posture assessment?
-Is it possible that your cache is expiring triggering wired transitions to require posturing?
-What additional tests and info can you share?
03-31-2021 04:47 AM
Hi Mike,
Tried deleting the Endpoint from ISE and tested reconnecting multiple time but each time ISE shows device is successfully postured with complaint status, ISE keeps updating the posture expiry value with the new time (before expiring the posture lease).
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: