cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

537
Views
5
Helpful
2
Replies
kostasthedelegate
Enthusiast

Issue with posturing

Hello, 

 

I have an issue with posturing on ISE 2.6.0.156, patch 5.

 

I have posturing with cisco AnyConnect. 

I have a condition as Mandatory which fails

fw_enabled_v4_fw_ANY_ANY_ANY

 

But from the PC I see that the firewall is enabled. Both on gui and cli.

 

Regards, 

Konstantinos

 

1 ACCEPTED SOLUTION

Accepted Solutions
Panos Bouras
Beginner

Hi Konstantinos,

 

Can you share a bit more about ISE posture module version, which condition you used and what's the firewall installed on the client machine (along with Windows version).

Also, when you say it fails what is displayed on Anyconnect?

Also check the following page for posture compatibility matrix

https://www.cisco.com/c/en/us/td/docs/security/ise/ac_compliance_module/cisco_anyconnect_ise_posture_win_support_charts_for_compliance_module_4_3_1614_6145.html

 

Thank you,Panos.
Please Rate Posts (by clicking on Star) and/or Mark Solutions as Accepted, when applies

View solution in original post

2 REPLIES 2
Panos Bouras
Beginner

Hi Konstantinos,

 

Can you share a bit more about ISE posture module version, which condition you used and what's the firewall installed on the client machine (along with Windows version).

Also, when you say it fails what is displayed on Anyconnect?

Also check the following page for posture compatibility matrix

https://www.cisco.com/c/en/us/td/docs/security/ise/ac_compliance_module/cisco_anyconnect_ise_posture_win_support_charts_for_compliance_module_4_3_1614_6145.html

 

Thank you,Panos.
Please Rate Posts (by clicking on Star) and/or Mark Solutions as Accepted, when applies

View solution in original post

Mike.Cifelli
VIP Advocate

Please share additional information so the forum can better assist.  What is your desire with the posture check? To ensure the firewall service is running?  If so, you could do something like this:

hips_svc.PNG

 

Just make sure you grab the right service name.  This works like a charm for most products I have tested and performed posture against.  HTH!

Content for Community-Ad