cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1948
Views
5
Helpful
2
Replies

Why URL Redirection required for onboarding new endpoints(having no records on ise previously)

Hi Everyone,

 

We have deployed the redirection less posture checking in which we were manually installed  the any connect agent(ver4.8) and compliance module (ver4.3) in the endpoints. We had configured all required configuration on switches and ISE.

But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.

As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.

Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?

 

Regards,

Ishwar

2 Accepted Solutions

Accepted Solutions

Hi @IshwarBamane2910 ,

 please take a look at the following to better understand your issue:

ISE 2.6 ACL Redirection-less Posture

ISE Posture Style Comparison for Pre and Post 2.2

 

Hope this helps !!!

View solution in original post

Mike.Cifelli
VIP Alumni
VIP Alumni

But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.

-This is normal behavior because the clients are missing the appropriate xml files that aide in how the module will work in regard to reaching out to ISE.

As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.

Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?

-This is because the redirection aides the client session in reaching the portal via url-redirect configured in your authz profile that is assigned to the session.  Once the client reaches the portal (via redirect help) you have an assigned AnyConnect Config result that has the AnyConnect Posture profile assigned with it.  At this point that profile is pushed to clients, which can be found here: C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture

The name of the profile I am referring to is: ISEPostureCFG.xml

IMO one option would be to configure clients pre-deployment with the respective XML file via SCCM or imaging process.

I would recommend taking a peek at the 'Compliance & Posture' section here: Cisco ISE & NAC Resources - Cisco Community

HTH!

View solution in original post

2 Replies 2

Hi @IshwarBamane2910 ,

 please take a look at the following to better understand your issue:

ISE 2.6 ACL Redirection-less Posture

ISE Posture Style Comparison for Pre and Post 2.2

 

Hope this helps !!!

Mike.Cifelli
VIP Alumni
VIP Alumni

But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.

-This is normal behavior because the clients are missing the appropriate xml files that aide in how the module will work in regard to reaching out to ISE.

As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.

Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?

-This is because the redirection aides the client session in reaching the portal via url-redirect configured in your authz profile that is assigned to the session.  Once the client reaches the portal (via redirect help) you have an assigned AnyConnect Config result that has the AnyConnect Posture profile assigned with it.  At this point that profile is pushed to clients, which can be found here: C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture

The name of the profile I am referring to is: ISEPostureCFG.xml

IMO one option would be to configure clients pre-deployment with the respective XML file via SCCM or imaging process.

I would recommend taking a peek at the 'Compliance & Posture' section here: Cisco ISE & NAC Resources - Cisco Community

HTH!