02-13-2019 10:04 AM
We are running ISE 2.2 with patch 6 currently.
I am wondering how to remove the posture status of an endpoint, so I can test changes to posture policy. The clients in question are Mac OSX both High Sierra and Mojave. Specifically, I am trying to test client provisioning to push new versions of AnyConnect, but they aren't installing since the device is coming in with a successful posture check, and the posture lease hasn't expired.
I tried to remove the endpoint from ISE, which I would have assumed would reset this, but I think ISE might be getting confused, as these MACs are the newer touchbar types, and the device endpoint ID in the logs is using the MAC address for the touchbar rather than the NIC and they are all the same, so I have multiple entries with the same EndpointID, but different usernames, and they are all different devices. There is also a device entry under the actual MAC address, which is the one I removed, but it is still registing with a successful posture check, despite the posture module not being installed on the endpoint.
Solved! Go to Solution.
02-13-2019 02:13 PM
02-13-2019 12:52 PM
Are your Posture leases set to 1 day? You can set them I believe between 1 to 365 days, or you can set the posture lease to perform posture assessment every time you connect to your network, which from my experience works great. Administration->System->Settings->Posture->General Settings
You can also setup reassessments based on local layer 2 ISE endpoint identity groups. Create a new group and add your MAC. This may help with your MAC issue. The reassessment can be setup in the same location where you configure your leases.
HTH!
02-13-2019 12:55 PM
Unfortunately, I can't change the lease timer as this is a production system.
I'm not sure I fully follow what you mean about the separate endpoint groups to run reassement against. I would be interested in hearing more about that.
02-13-2019 02:13 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide