01-21-2021 02:32 PM - edited 01-21-2021 02:37 PM
Hello, guys.
Does anyone know should the ISE Posture module trigger non-compliant state if:
- connect via VPN with the ISE Posture module
- there are no last Windows updates installed
- the posture requirement has a condition: pr_WSUSRule
- the posture requirement has a remediation action: Message Text Only
- the final posture state is compliant
Since the last patches are not installed, the expected move is to change the posture status to non-compliant.
It doesn't happen.
I confirm that if this is a remediation from "Windows Server Update Services Remediations" section, the ISE Posture module trigger windows to install missing patches followed by compliant state.
01-22-2021 05:56 AM
Is it possible the CoA is failing when session is moving from unknown to noncompliant? Are you able to share your ISE authz policies? Do you have separate flows for unknown, compliant, & non-compliant? What is your AC posture scan summary depicting on a test client, is it for sure missing patches & failing the specific check?
01-22-2021 07:23 AM
Hi @fedor.solovev ,
beyond what @Mike.Cifelli said.
Please double check the Mandatory x Audit info on the Result Summary (Work Center > Posture > Troubleshoot) > Requirements column of the pr_WSUSRule condition.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide