08-11-2017 08:57 AM
Dear experts,
Please help on below two questions.
1. How anyconnect posture module to decide the checking order of rules I configure in posture rules on ISE. The actual checking order is not the same with what I configure. In my testing, windows server update services is always the first one to be checked. Because WSUS remediation always spends more time downloading and installing patches and cause remediation time expired. So other rules are not even checked.
2. I use the default remediation timer--4 minutes in my lab. But time of WSUS remediation which is one of three posture rules is longer than 4 minutes. So is there other specific timer for each remediation?
ISE Version: 2.2.0.470
Anyconnect Version: 4.4.02034
Compliance Module: 4.2.1134.0
Solved! Go to Solution.
08-11-2017 06:55 PM
On 1, two possibilities:


On 2, there is no remediation timer for individual remediation so please set a longer timer for overall remediations.
08-11-2017 06:55 PM
On 1, two possibilities:


On 2, there is no remediation timer for individual remediation so please set a longer timer for overall remediations.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide