cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1170
Views
5
Helpful
4
Replies

Windows Login issue with ISE posture after User password expires

MALi-786
Level 1
Level 1

I am running posture with AnyConnect 4.7 in my environment but now facing an issue after the user windows password expires.

 

1- User windows password expires

2- User reset at the time of login

3- Got the message for successful password change.

4- Tried to login with a new password but not working.

5- User able to login with old password but posture not working.

 

Any idea how to fix this issue. I tried in posture redirect ACL by allowing any to AD.

2 Accepted Solutions

Accepted Solutions

Did you try opening most everything first, make sure that works and start restricting?

View solution in original post

MALi-786
Level 1
Level 1

It's fixed now. I am was allowing tcp but not udp. After I allowed the required ports for udp it starts working fine.

View solution in original post

4 Replies 4

Mike.Cifelli
VIP Alumni
VIP Alumni
How is your authz policy & redirect acl setup? Sounds like that user is able to get back in via cached creds. What conditions are you utilizing to kick off posture scan?

 

  1. Compliant--> Result--> Permit
  2. Non Compliant --> Deny
  3. Unknown Compliant --> Posture Redirect
    1. AUTH Profile: DACL (Redirection)
    2. Web Redirection -> ACL ->CP Portal

 

Yes, they are using cached credentials due to some issue which I am trying to identify. AD is working fine with ISE and I checked by testing user.

 

 

Did you try opening most everything first, make sure that works and start restricting?

MALi-786
Level 1
Level 1

It's fixed now. I am was allowing tcp but not udp. After I allowed the required ports for udp it starts working fine.