04-14-2020 08:50 AM
Hi
We are currently working on setting up the posture for a certain subset of our users. Now I have defined a policy to get my test user out of the loop, authenticate and authorize it. My coworker has been doing the tests with the test user's creds. However we now see that posture is checked every time he logs in, regardless of the conditions or whether he uses the test user or his own creds. Is that to be expected? Can't we hide it if it's not in use?
We are thinking of distributing the any connect bundle with the posture module---but are concerned that it's not such a good idea after all because the posture itself is meant to be used by only a subset of our users...
Thanks
Mae
04-14-2020 09:15 AM
04-14-2020 10:18 AM
Thank you Mike for your prompt reply.
I tried in my conditions to specify a user group not to check. Same ASA.
We do have the message that the posture is not needed on the wireless network (we are posturing on VPN anyways).
However when we try to log in, it still checks it.
I'd really like for it not to posture AT ALL if it's not the right group.
04-14-2020 10:37 AM - edited 04-14-2020 10:38 AM
Can you share your CP Policy and conditions in detail? And any additional host information that may better assist with troubleshooting.
04-14-2020 12:59 PM
Hi
Not sure of the details you're really interested in.
My posture config is just a test. It's enabled only if someone show up with the username XXXX.
Else you are in the old policy we had before we even had posture. So no posture checks are enabled.
04-14-2020 01:03 PM
BTW it's posturing but not enforcing.
Through my tests today I was able to confirm that.
The concern is that the users may complain and it may generate unnecessary tickets.
04-14-2020 01:30 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide