cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
429
Views
2
Helpful
3
Replies

Posture and Network acess(ISE)

vilasreddy
Level 1
Level 1

If same set of devices are referenced in a posture policy set and normal wired/wireless   policy sets with different authorization profiles ,to which policy set does it match?

2 Accepted Solutions

Accepted Solutions

@vilasreddy policy set working top to bottom. but you can set action to process with another policy or only process matched policy,

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

View solution in original post

You wouldn't create a separate policy set for posture assessment, instead the posture assessment authorization rules should be created within the existing policy set(s). For instance, say you have two separate policy sets, one for wired and one for wireless. What you would need to do for posture assessment is going inside each of these two policies and add the posture assessment authorization rules for the unknown, non-compliant, and compliant.

View solution in original post

3 Replies 3

@vilasreddy policy set working top to bottom. but you can set action to process with another policy or only process matched policy,

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

For suppose wired/wireless policy sets are above the posture policy set ,and it hits the wired/wireless policy set first ,how will the posture be enforced?

You wouldn't create a separate policy set for posture assessment, instead the posture assessment authorization rules should be created within the existing policy set(s). For instance, say you have two separate policy sets, one for wired and one for wireless. What you would need to do for posture assessment is going inside each of these two policies and add the posture assessment authorization rules for the unknown, non-compliant, and compliant.