- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-28-2019 05:17 PM
Dear all,
I'm trying to install AnyConnect NAM and ISE posture, as well configure posture on ISE without Client Provisioning. I also generated profile using Profile Editor for both of NAM and posture module, then paste them to consisten folder AnyConnect NAM and ISE posture in ProgramData/Cisco.
The NAM operated normally, but after authorization complete, Posture module didn't scan the system for compliance, the status is Bypassing AnyConnect scan — Your network is configured to use the Cisco NAC agent.
Could anyone know the issue?
Thank you so much!
Solved! Go to Solution.
- Labels:
-
AnyConnect
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2019 10:23 AM
If any ID Groups & Windows ALL AND <other conditions you wish to match on> THEN result equals AnyConnect Configuration
The AC configuration is also setup under Client Prov resources. This config specifies the AC package version, what compliance module to look for/use, and what ISE posture AC profile to use that I mentioned earlier. Check this out:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116143-config-cise-posture-00.html#anc14
Also, take a peek at labminutes.com/security for free video tutorials. Good luck & HTH!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-29-2019 10:23 AM
If any ID Groups & Windows ALL AND <other conditions you wish to match on> THEN result equals AnyConnect Configuration
The AC configuration is also setup under Client Prov resources. This config specifies the AC package version, what compliance module to look for/use, and what ISE posture AC profile to use that I mentioned earlier. Check this out:
https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116143-config-cise-posture-00.html#anc14
Also, take a peek at labminutes.com/security for free video tutorials. Good luck & HTH!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-30-2019 12:32 AM
Thank so much, Mike!
As you mentioned, I also read w/ carefully the guide from cisco, and figured out that we need to configure client provisioning for AnyConnect profile, and I fixed the issue yesterday.
But, I'm facing the new issue that the anyconnect does not do remediation with the untrust server. My ISE PSN is using self-signed cert, I don't know how to make anyconnect accept untrust server? Could you give me any suggestions?
Btw, thank you for your response, Ot's quite useful to me!
Best regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-30-2019 08:07 AM
Two options here:
1 - get a certificate that is trusted by your end clients. Ensure the chain is in the appropriate stores on your end devices.
2 - Use the ISE posture profile editor to allow end clients to connect to untrusted servers. See here: https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/configure-posture.html
HTH!
