cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

181
Views
0
Helpful
1
Replies
Highlighted
Cisco Employee

posture during PSN failover

PSN's are load balanced behind an F5.  When a PSN failover occur's the new PSN initiates new authentication session and a new redirect ACL is sent to the switch.  However, the endpoint posture module never initiates new posture assessment.  The endpoint still shows it self as compliant, but redirect ACL on the switch blocks traffic.

How do you get the posture reassess the endpoint in this scenario?

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Beginner

Make sure all PSNs in LB cluster are part of some node group. There is a designated "master" that will initiate CoA in event that another PSN in node group had a session in URL-redirect pending state. This should ensure that new session established using new redirect ACL appropriate to current PSN.  

View solution in original post

1 REPLY 1
Highlighted
Beginner

Make sure all PSNs in LB cluster are part of some node group. There is a designated "master" that will initiate CoA in event that another PSN in node group had a session in URL-redirect pending state. This should ensure that new session established using new redirect ACL appropriate to current PSN.  

View solution in original post

Content for Community-Ad