cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2231
Views
0
Helpful
2
Replies

Posture before logon

ankaushi
Cisco Employee
Cisco Employee

Hi Team,


Is there anything on the ISE\Anyconnect posture roadmap to allow for posture before logon  ?

The customers use case is to fully block machines from joining their network if they don’t have AV or up to date windows patches to stop the spread of viruses.  This isn’t possible at the present because the Anyconnect GUI only starts after the user logs on so drive mapping fails.

This is not a BYOD or guest scenario but more about corporate machines where if they are taken off site to other premises and get infected with malware that disables the AV they shouldn’t be allowed back onto the corporate network.


Regards,

Anshul

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

We don’t discuss roadmap in the public forum.

What you’re asking for is likely not possible because all of the services AV etc run in user space. You wouldn’t be able to check if they are running before logon.

However you can severely limit your pre-health network with SGT, tag, acl controls to isolate machines before the check runs. With SGT you can even limit lateral movement between machines. Once the check is complete you give them full access by updating the controls.

View solution in original post

2 Replies 2

howon
Cisco Employee
Cisco Employee

Hi, Anshul. I believe what you are looking for is Stealth mode (Clientless) AnyConnect with ISE which was introduced with ISE 2.2 & AnyConnect 4.4. You can find more about this feature here: Cisco Identity Services Engine Administrator Guide, Release 2.2 - Configure Client Posture Policies [Cisco Identity Ser…

Jason Kunst
Cisco Employee
Cisco Employee

We don’t discuss roadmap in the public forum.

What you’re asking for is likely not possible because all of the services AV etc run in user space. You wouldn’t be able to check if they are running before logon.

However you can severely limit your pre-health network with SGT, tag, acl controls to isolate machines before the check runs. With SGT you can even limit lateral movement between machines. Once the check is complete you give them full access by updating the controls.