cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2498
Views
0
Helpful
3
Replies

TCP UDP 8905 8909 with AnyConnect Posture Agent

trevorjenix
Level 1
Level 1

Documentation and books refer to allowing TCP/UDP ports 8905 and 8909 to the ISE servers in the AGENT-REDIRECT ACLs to make sure NAC agent can be prvisioned, be controlled by ISE and allow keepalive traffic. My question is if this all applies only to the NAC agent or if it applies to the AnyConnect Posture module as well, I couldn't have seemed to find this information anywhere. Are 8905 and 8909 ports still used in with:

- AnyConnect provisioning ?

- NSP provisioning ?

- AnyConnect posture module communication and keep alives ?

If not using NAC agent, would it be enough to only include port 8443 to ISE PSN(s) IPs?

1 Accepted Solution

Accepted Solutions

Some documents show 8909 isn’t used in ise 2.0+

View solution in original post

3 Replies 3

Venkatesh Attuluri
Cisco Employee
Cisco Employee

you will be still needing 8905 8909 with anyconnect

Thank you!

Some documents show 8909 isn’t used in ise 2.0+