09-29-2017 10:48 AM
A customer wants to know if they can connect the same computer to perform posture on more than one connection (LAN and wireless at the same time). Typically, I’m asked for the opposite as customers don’t want wireless and LAN to be connected at the same time. In this case, the customer wants both as well as both connections checked with posture. Is this possible? I didn’t think so
Solved! Go to Solution.
09-29-2017 01:38 PM
I believe there’s a problem as AnyConnect will only posture out one interface at a time depending on how the OS is preferring the NICs
If it prefers wired and you plug in, it will posture wired and wireless if not postured will sit in a state of unknown as AnyConnect won’t communicate
If you connect wireless and posture then Connect wired then it will posture again, now both nics should be postured state
If you have PRA enabled then it will fail on wireless since there is no communication
You will want to make sure that your posture lease is enabled so that you only have to posture 1x a day on each connection if preferred
Best scenario is to limit to one interface at a time using AnyConnect NAM (windows only)
Remember licensing is per active connection (Mac address), having 2 nics connected will result in each machine consuming 2 licenses
09-29-2017 01:15 PM
The NIC connections IP’s and MAC’s are different and posture will happen again. This is the normal behavior.
-Krishnan
09-29-2017 01:38 PM
I believe there’s a problem as AnyConnect will only posture out one interface at a time depending on how the OS is preferring the NICs
If it prefers wired and you plug in, it will posture wired and wireless if not postured will sit in a state of unknown as AnyConnect won’t communicate
If you connect wireless and posture then Connect wired then it will posture again, now both nics should be postured state
If you have PRA enabled then it will fail on wireless since there is no communication
You will want to make sure that your posture lease is enabled so that you only have to posture 1x a day on each connection if preferred
Best scenario is to limit to one interface at a time using AnyConnect NAM (windows only)
Remember licensing is per active connection (Mac address), having 2 nics connected will result in each machine consuming 2 licenses
10-02-2017 11:42 AM
I also am validating with our posture SME imbashir
10-02-2017 12:04 PM
In case posture lease is enabled, then ISE can track AC interfaces (using UDID) e.g. moving from Wired to Wireless or vice versa, would not trigger posture
Else, posture would be triggered at each connection time (wired, wireless or VPN)
Thanks
Imran
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide