Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,
When performing a migration from ACS to ISE, does the password expiry value (x days until expiration) come over from ACS or do these values for internal users (and internal admin users?) come over as well or does the timer/counter reset and...
Hello,
I was reviewing the IBNS 2.0 guide: https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515
which states:
The device-tracking policy is effective only when applying the policy...
Hello,
My customer is running ASA on an FP4140 Appliance and is using ISE for posture assessment. Is there anywhere that has comments on ISE DACL scalability for AnyConnect VPN users? Is this like a switch where there is a limited amount of resourc...
Hello,
We are working on a long-running ISE pilot for a customer using 2.3. Of course, in the customer environment the ISE node cannot access the internet. I tried to look for the temporal agent in the offline policy feed service update but that’s ...
Hello,I presume that AnyConnect's MSI removes old versions. Is there any limitation to this as long as the computer/user/etc. has the right permissions for allow changes at this level?Thanks,Russ
Hey @Nidhi -
I understand that 2.6 + AC 4.7 supports sending the UDID via the posture flow, but is this would only cover customers using ISE posture. In the past, Jamf would get the MAC addresses of whatever NICs (I believe up to two of them) whe...
Hey Hsing,
I have a customer who has contacted me about this, as well (will forward internally) but wanted to see if there was any update if this frustrating issue would be fixed?
Thank you,
Russ
Is this known to work with certificates as the external user database? Is there anything planned to make this work across multiple PSNs using the MnT or some other solution?Thanks!
Hey Charles,Thank you for the thorough reply, I suppose the bit I did miss out on here is that the clients, like many in an enterprise environment, do not have much if any access to run installers that are downloaded. Cheers,Russ