03-17-2021 05:59 AM
Hi Everyone,
We have deployed the redirection less posture checking in which we were manually installed the any connect agent(ver4.8) and compliance module (ver4.3) in the endpoints. We had configured all required configuration on switches and ISE.
But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.
As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.
Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?
Regards,
Ishwar
Solved! Go to Solution.
03-17-2021 06:31 AM
Hi @IshwarBamane2910 ,
please take a look at the following to better understand your issue:
ISE 2.6 ACL Redirection-less Posture
ISE Posture Style Comparison for Pre and Post 2.2
Hope this helps !!!
03-17-2021 07:05 AM - edited 03-17-2021 07:07 AM
But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.
-This is normal behavior because the clients are missing the appropriate xml files that aide in how the module will work in regard to reaching out to ISE.
As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.
Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?
-This is because the redirection aides the client session in reaching the portal via url-redirect configured in your authz profile that is assigned to the session. Once the client reaches the portal (via redirect help) you have an assigned AnyConnect Config result that has the AnyConnect Posture profile assigned with it. At this point that profile is pushed to clients, which can be found here: C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture
The name of the profile I am referring to is: ISEPostureCFG.xml
IMO one option would be to configure clients pre-deployment with the respective XML file via SCCM or imaging process.
I would recommend taking a peek at the 'Compliance & Posture' section here: Cisco ISE & NAC Resources - Cisco Community
HTH!
03-17-2021 06:31 AM
Hi @IshwarBamane2910 ,
please take a look at the following to better understand your issue:
ISE 2.6 ACL Redirection-less Posture
ISE Posture Style Comparison for Pre and Post 2.2
Hope this helps !!!
03-17-2021 07:05 AM - edited 03-17-2021 07:07 AM
But even after doing this, AnyConnect agent from fresh/new endpoints (having no previous records with ISE) showing no policy server detected error.
-This is normal behavior because the clients are missing the appropriate xml files that aide in how the module will work in regard to reaching out to ISE.
As soon as we start the redirection in authorization profile issue get resolved and agent started to scan and showed compliant status.
Can we know, Why in redirection less deployment we required URL redirection for onboarding the new/fresh endpoints ?
-This is because the redirection aides the client session in reaching the portal via url-redirect configured in your authz profile that is assigned to the session. Once the client reaches the portal (via redirect help) you have an assigned AnyConnect Config result that has the AnyConnect Posture profile assigned with it. At this point that profile is pushed to clients, which can be found here: C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture
The name of the profile I am referring to is: ISEPostureCFG.xml
IMO one option would be to configure clients pre-deployment with the respective XML file via SCCM or imaging process.
I would recommend taking a peek at the 'Compliance & Posture' section here: Cisco ISE & NAC Resources - Cisco Community
HTH!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide