cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
783
Views
1
Helpful
9
Replies

New Provisioning policies with no download from ISE

TVmaster
Level 1
Level 1

Hi fellows 

we have a situation in my end of suport ISE 2.7 . we are in a migration from 2.7 to 3.2 , but our provisioning policies are old in 2.7 , and complicance module and anyconnect versions are also...

i would like to migrate to 3.2 without having to force a download this new compliance module and new anyconnect version to the machines , because we will have a lot of work with windows GPO ,that block instalations and updates from certain softwares.. and we would like to do this manualy inside our organization...

is it possible to configure provisioning policies with new packages in my new ISE , without force our user to download this new recourses? without "defer" option , because is prompted to the user...

i tried to do this , and when a user tries do posture , client tries to downlod "compliance module" and "anyconnect new version" and because we have a GPO , a error occur in anyconnect because this update is blocked.

i remember in older ISE versions , a option called "is upgrade mandatory?", but in new versions .. i cant found this option.

9 Replies 9

I didn't come across this specific scenario but how about if you import the old packages into ISE 3.2 and reference them in the posture assessment and client provisioning policies?

Aref .. this old packages are not  available anymore in download section in Cisco

What is your upgrade strategy for ISE? They are included in the ISE configuration database.

Is the plan eventually for a migration to 3.3?  

You should not upgrade with EOL compliance module or AnyConnect versions as those may not have been validated on more modern versions of windows.  I would do the upgrade to Secure Client with your package management utility first. 

https://www.cisco.com/c/en/us/products/collateral/security/anyconnect-secure-mobility-client/anyconnect-secure-mobility-client-v4x-eol.html

Ahollifield , yes yes , is the plan , but not for now.. and we would like to avoid some problems in this moment

 

 

Problems like what? I would just upgrade ISE in place then or use backup/restore method. Then ASAP start the upgrades for Secure Client using your package management utility.

we have old and new machines in the envi...

is it not possible to disable  this automatic update by provisioning policies from ise? 

Not for the compliance module no.  I'm not sure what you are asking though?  What do you mean?

I think @TVmaster is after disabling the upgrade/update prompt of AnyConnect/Secure Client posture module on the endpoints. Not sure but I think if you disable the client provisioning portal that might be the fix?