AnyConnect ISE posture module discovery host and call home list AnyConnect launches and the ISE posture module starts running In order to discover if posture assessment is required, the posture module initiates 4 probes to detect the client provisioning portal The four probes are: HTTP GET auth discovery to the default gateway IP; HTTP GET auth discovery to enroll cisco com
Cisco ISE POSTURE user cant connect I checked the DART logs and could see the discovery probes to be failing Hence the issue: Time out for Ng-Discovery target enroll cisco com with path auth ng-discovery debug unable to send request: 12002 Status of Ng-Discovery target enroll cisco com with path auth ng-discovery is 6 <Not Reachable >
Troubleshoot ISE Session Management and Posture - Cisco Discovery Process does not Start on a New Authentication Attempt The ISE posture module is designed to monitor a limited amount of events on the endpoint to trigger a discovery process Events which trigger discovery: Initial ISE posture module installation User login Power events Interface status change OS resume after sleep
ISE Posture Troubleshooting - Apronets Probe 3 – HTTP GET auth discovery to discovery host Discovery host value is returned from ISE during installation in AC posture profile Expected result for the probe is redirect-url Your AC posture profile lives here C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\ISE Posture\ISEPosture xml
Compare ISE Posture Redirection Flow to ISE Posture . . . - Cisco Step 20 At this stage, Anyconnect ISE Posture Module initiates policy server detection This is accomplished with a series of probes that are sent at the same time by the Anyconnect ISE Posture module Probe 1 - HTTP get auth discovery to default gateway IP Consider that MAC OS devices do not have a default gateway on the VPN adapter
ISE posture with distributed deployment - Cisco Community The best way to do this is get posture discovery working correctly In this way, it doesn't matter if you have 2 PSNs or 20 I don't use the posture discovery host I like posture discovery to work with a fresh install of the posture module no customization required The two methods that are easy to intercept are: Port 80 to the default gateway