06-26-2023 12:56 AM - edited 06-26-2023 05:39 AM
Hi,
We have configured posturing in our Cisco ISE 3.1 patch 6.
The AnyConnect version for ISE Posturing is 4.10, and the Compliance module is 4.3.35.
The authentication profiles are as follows:
There are 2 Authorization Policies
The requirement is that the endpoint must have any anti-malware software installed and any firewall running.
With these configurations, most agents are able to correctly perform compliance checks on the endpoints. However, we have noticed strange behavior with certain endpoints, specifically gaming laptops, such as Asus Tuf and Lenovo Legion.
The behavior is as follows:
Since this behavior only occurs with specific brands, we are not sure how to approach the issue.
Thank you,
06-26-2023 05:33 AM
Why are you changing VLANs and not using a dACL? Out of date wireless drivers? Are these managed or unmanaged endpoints?
06-26-2023 05:46 AM
Hello Ahollifield. from my understanding we only use DACL with VPN posturing using ASA/Wired posturing using Switches. As this is wireless posturing, we're using WLC ACL. CMIIW.
06-26-2023 05:58 AM
Got it, correct for wireless this would just be named AireSpace ACL for the Posture states. But in your post you state you are changing VLANs between VLAN A and VLAN B?
06-26-2023 06:00 AM
Wait did you edit your post?
Anyways, if this is only impacting certain endpoints, the most likely cause is an endpoint issue.
12-11-2023 06:18 AM - edited 12-11-2023 06:29 AM
Good day!
Have the same problem, but I faced it on ISE 2.7
Some of our corporate laptops first get compliant status and after several seconds stuck in pending. It looks like it depends on the specific laptop model. For example on dell devices compliant check works fine, acer TravelMate P215-53 also works properly, but all our acer aspire A514-55 stuck in pending. Also these Acer A514 laptops generates more logs on ISE then those, which don't have this problem. As far as I understand they regularly reconnect to ISE and it happens really too often, I think it abnormal behavior. (I'va also uploaded screenshot which demonstrates this behavior)
So I tried to install different versions of wlan and other drivers, also switched between different anyconnect version, but nothing helped to solve this problem. Did anyone face such problem? Any ideas what measures can be taken to solve it?
Thanks!
12-11-2023 07:26 AM
What is the wireless NAD? Also I see the name OTP in the authc/authz policy results. Are you using MFA on wireless? Is this SSID mac authenticated? Why not 802.1X?
12-13-2023 06:58 AM
@ahollifield , thanks for your reply
Our wireless network is based on AP Cisco AIR-AP2802I-R-K9 and WLC C9800-L-C-K9.
In our case OTP has nothing in common with MFA, it is just naming of our SSIDs.
Yes, we use 802.1X, EAP-FAST (we check both machine certificate and user credentials, this information was not displayed in the previous screenshot, so I've added a new one)
As for ISE 2.7 so we planned to perform an upgrade, but recently our IT department has bought rather large batch of acer laptops and all of them have the same problem with posture status and frequent reconnections. And that is why we want first to solve this problem, then move to upgrade. Moreover in this topic @rafliraditya has similar problem on ISE 3.1 and it seems to me that the problem is connected with endpoints and not with ISE.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide