ISE Posture for non-agent device problem

I have a couple of questions:
- They said it the documents: "these (non-agent) devices assume the Default Posture Status settings". I wonder how ISE determines that a device is a non-agent device, or to put it another way, when is the Default Posture Status settings applied to a device? Is it after some period of time not receiving anything from the agent? If yes, can and where do I change that time in ISE?
- I tested this with my lab and saw that: after the user successfully login with his account, and the Authorization profile with Client provisioning is applied to that session, the user goes to a web page and gets redirect to the CPP page. Now if he just sits there and doesn't install the NAC agent, I noticed that after about 40s, the session is automatically restarted to a new one, with a different session ID, but the same username. The new session gets to the point where the same redirect Authorization profile is applied and the whole process cycles over and over. Things I observed each time the session restarts:
+ The user doesn't even have to enter the credentials again. The 802.1x login doesn't popup 
+ The Default Posture status (I set it to Noncompliant) is applied to the session right before it restarts. I can see an event on ISE indicating that. The event also shows the Acct-Terminate-Cause as "Admin Reset"
+ If at any point, the user installs a NAC agent then he can break the cycle (e.g becomes compliant) and carry on with other Authorization profiles
So my question is: is that expected behavior of ISE? Although it seems no harm except new sessions are created continously
Or have I configured something wrong?

Anybody?

Similar Messages

  • Is vshare for non-jailbroken device safe?

    hey guys,i was planning to download vshare for non jailbroken device but im scared that it might brake my iphone 5s...Is it safe guys?thanks

    The only safe apps are the ones from the App Store.

  • Using 24 ports on 5548 for non fabric devices with 24 FEX's attached.

    If you have 24 Nexus 2248 fabric extenders dual-homed to two Nexus 5548 switches using one 10Gig port from each 2248, can the remaining 24 ports on each 5548 be used for non fabric devices? (Ex. Blade server chassis with integrated switches)

    Yes, you can use the remaining 24 ports for whatever you want to connect.  It could connect to IBM chassis, other routers, switches, etc...
    HTH

  • "save for web and devices" problem

    Hello
    I am running photoshop cs4 on windows vista
    When I click on file>save for web and devices, a message appears saying "the operation cold not be completed"
    This happens for small files and large files
    Can anyone tell me how to overcome this problem please?
    Thanks
    Reg

    Hi again, rego.
    I did a bit of searching and someone had a similar problem as you where simply deleting the pref file via key command didn't work. A user suggested to first zip the Save for Web preferences and then delete the preferences. I am not sure what zipping the file does but basically they are suggesting delete the preferences manually.
    So try zipping the save for web preferences file and then delete it. After this is done, restart Photoshop and see if it helps. To find where the Save for Web preferences are, refer to this page:
    http://kb2.adobe.com/cps/405/kb405012.html
    EDIT: I am not sure if I was clear about the process suggested in the other post. For clarification, the suggestion is to zip the Save for Web preferences file and then delete the zipped file of the Save for Web preferences.

  • CS5 Save for Web and Devices problem

    I recently installed CS5 and now I cannot save for Web and Devices.  A pop up error window appears saying "A write permissions error has occurred".  Any suggestions to make it possible to save for Web and Devices would be appreciated.
    Also, when I exit Photoshop CS5, yet another pop up window appears and reads, "Could not save Preferences because the file is locked or you do not have the necessary access privileges.  Use the 'Get Info' command in the Finder to unlock the file or change permissions on the file or enclosing folders'.  Again, any suggestions as to what this message is about and how to make PS close as it did with CS4 would be appreciated!
    Thanks,
    E

    Try this first:
    Applications > Utilities > Disk Utility > Macintosh HD > Repair Disk Permissions
    Also make sure your not saving to a removable hard drive that is NTFS. If you can drag files into the drive its the right type of drive to use and there shouldn't be a problem.
    Apart from that all i can say is to restart your Mac and make sure all the adobe updaters are up to date
    Hope that helps
    James

  • Do I need to upgrade my CC Account to create a folio app for non-iPad devices?

    Hello,
    I have never created a DPS app, but have been researching this for the last 4 weeks.  From what I understand, I can create a DPS app for iPad using a single edition or a multifolio app.  If I want to create a DPS app for any other device, I would need to create a multifolio app.  I have only a Creative Cloud account, but I believe that I will need a Professional or Enterprise account to create multifolio apps.  Is there another way that I could create apps for Android, iPhone, etc devices without having to upgrated my account?
    Thank you.

    Your research and understanding is correct. If you want to use DPS to target anything other than an iPad you need Professional or Enterprise edition.
    Neil

  • Exporting animation using Save for Web and Devices problem

    The animation plays as it should when the "Play" button is pressed at the bottom of the "Save for Web and Devices" Menu , but when I Preview it the individual frames don't disappear once they've shown , so you can see them all at the end of the animation . This is also how they save as a .gif ( although using the "Save as html" option reverts to looking as it should , each frame appearing and disappearing in turn) How do I save as gif without this happening?Many thanks for any help

    Thanks!  It was under the object - slice.  You've saved my sanity

  • AIR SDK 17 - mailto subject line error for non English devices

    Hi,
    Is there a problem with language localization in AIR SDK 17 for iOS?
    The following code works for an iOS 8 device with the language set to English but if you set it to any other language the subject line is missing!
    var mailme:URLRequest = new URLRequest("mailto:[email protected]?subject=CONTACT");
    navigateToURL(mailme, "_self");   
    Is there a fix for this?

    Hi,
    Is there a problem with language localization in AIR SDK 17 for iOS?
    The following code works for an iOS 8 device with the language set to English but if you set it to any other language the subject line is missing!
    var mailme:URLRequest = new URLRequest("mailto:[email protected]?subject=CONTACT");
    navigateToURL(mailme, "_self");   
    Is there a fix for this?

  • ISE Not Profiling Non-Domain Devices

    I am having an issue where ISE is not profiling devices that do not belong to our domain. Machines with computer accounts in our domain get profiled with no issue. It does not matter if it is an apple device, windows device, or android device. The user can successfully get a prompt for their username and password, however they will get an error stating 'Incorrect Username or Password'. If I drill into the failed attempt, they get a 15039 Authorization Failed and it assigns DenyAccess to them. If I find the device by MAC address in the profiled endpoints, it remains UNKNOWN. If I manually assign a profile, then it lets the device on and successfully identifies the user. I need to be able to allow users to use their devices to gain access to the network.
    SYSTEM INFO
    ISE Ver: 1.1.4.218
    Stand Alone Mode
    Profiling Setup
    DHCP - Interface ALL - Port 67
    HTTP - Interface All
    Radius
    DNS - Timeout 2
    Authorization Policies
    Wireless Blacklist Default - if Blacklist and Wireless_802.1X then Blackhole_Wireless_Access
    Profiled Cisco IP Phones - if Cisco-IP-Phone then Cisco_IP_Phones
    OnlyMachineAuth if AD1:ExternalGroups EQUALS EDUORG/Users/Domain Computers then PermitAccess
    Guest if WLC_Web_Authentication then Guest_Profile
    Employee if (Apple-iPad OR Workstation OR Android) AND (Wireless_802.1X AND AD1:ExternalGroups EQUALS EDUORG/User Accounts/All Employees AND AD1:ExternalGroups NOT_EQUALS EDUORG/Students/All Students ) then Employee_Profile
    Student if (Apple-iPad OR Workstation OR Android) AND (Wireless_802.1X AND AD1:ExternalGroups EQUALS EDUORG/Students/All Students AND AD1:ExternalGroups NOT_EQUALS EDUORG/User Accounts/All Employees ) then Student_Profile
    Default if no matches, then DenyAccess
    Any help would be greatly appreciated
    Thanks,
    Kevin

    Sorry for not explaining further. The guest network works flawlessly. Employees and students are the ones having the issues. They connect to the employee and student networks. The guest network is soley for guests. Employees and students still connect to their respective networks.
    Employees, for example would connect to the 'employees' network. They are unable to connect with their personal device. With their district issued laptop they can get on with no issue. Their district issued laptop is a windows machine which is joined to the domain. However, if a district employee decides to bring their ipad, they will still connect to the employees network. This is where they get the issue. It will not let them connect. It prompts them for their username and password, but then does not allow them on. The same applies to students.
    I hope this clarifies it a little better
    Sent from Cisco Technical Support Android App

  • Mac OS X Server 10.5 Radius authentication for non airport devices

    We have an Astaro Security Gateway 220 that we are planning to use for VPN and other services, we would like to use our Xserve to do authentication for our VPN like we already do for our other services on the device. To do so requires that we use Radius as the communication protocol between the server and the gateway, it works just fine to test authenticate as long as I don't set a Nas-Identifier for the test but as soon as I do it fails. The Nas-Identifiers are used to determine which services the account has access to and are named logically for that, things like http, pptp, etc. are used. I can't figure out how to get the gateway to be able to authenticate users, I don't need to be able to limit based on user which services they can access, any service that has a restricted set of users other than just valid users will be handled separately outside this system. If anyone can give me any good ideas on how to solve this it would be appreciated, we currently are only looking at radius fore this, while we use airports for our wireless we don't link them into the server currently though there is a slight chance it will happen in the future.
    Thanks,
    Glenn McGurrin

    I found the problem. When turning off ClamAv virus scanning and Spam filtering everything runs fine again. So now we only have to repair those functions...

  • Adobe Reader for non-symbian devices

    Why do I have to have a symbian device to read pdf files? We don't need complex operations on a cell-phone with Adobe, other than reading the e-mail attachment.
    I would pay for a Java version of the Reader to run on my non-symbian phone.

    Thanks George, interesting thought.  I looked on Adobe's site and they "advertise" fillable forms for the iPhone and Android markets, but on the Windows Phone tab, that is mysteriously missing.  lol    Maybe it will come later?   Meanwhile, I'll google to see if there are any PDF viewers that can handle it now.   Thanks for the reply.  :-)

  • Using macbook as a wireless router for non-apple devices

    im trying to use my mac as wireless router for my xbox. i went into share under system preferences, and made a network with a WEP password. I can see the network on my xbox but it requires an IP adress...
    i guess what im really asking is, if the mac can automatically assign IP adresses to devices on the network

    I use my MBP regularly to share internet connection with PCs. Usually the PCs do a 'search' for a network and then 'connect' to the network name set in the Airport options... drop down panel. They get the IP automatically.
    In the system preferences>share> there is a button on the right bottom which says 'airport options..' and in the drop down panel, you set the name or SSID and the WEP key.
    Maybe you should check XBOX settings if the network settings are manual or automatic?
    Hope that helps.

  • Is using vshare for non jailbroken devices safe

    I Thought to use vshare but is it virus free

    TacticalTrollface wrote:
       He can come here whenever he thinks he needs it and he can ask as many questions and make as many objections as he wants, whether or not it's the same user that he replied to. Maybe you shouldn't be here if you want to understand that even you aren't perfect and that he's carefully double checking. And when he hoses his i-device, he'll come back here and I'll be the one who replies it, and you can leave and stop being useless.
    Since you're new here, you get a small amount of grace for not understanding how things work. See all those dots under Kilted Tim's name? That really big number of points? He was awarded those points by fellow users who felt his answers were helpful. So, your assertion that he is "useless" is quite obviously wrong.
    What you don't get a pass for is rudeness. However, I suspect from your username, you have intentions of being disruptive. I hope you prove me wrong and learn to be as helpful and useful as Tim.

  • Import prompt for non existent device

    Every time I launch LR 2.2, if prompts me to import from my iPod Touch, which is not connected to the computer. It displays one blank image. How can I stop this from happening? When I plug in my compact flash card, I do want it to bring up the import dialog, which it does correctly.

    Claude-
    Import the bogus image, then delete it, that is, if you can import it, whatever "it" is.
    I'd like to not have my iPhone come up for prompting, as it does have images on it that I don't care to import.

  • Non-Controllable Device (other than the freezing) problem

    I am using FCP 6.0.2 and 10.5.1. I have had virtually no problems for years, but this one recently appeared. I can capture using any setting except for Non-Controllable device. I have two cameras I use, the Sony HDR-FX1 and a little Panasonic hand held Mini-Dv camera. Both have worked before using the non-controllable device, but now when I choose that setting, it says "No Communication" As soon as I put it in any other setting, it says "VTR OK" and I can capture and use all the controls. Seems like it happened after I installed Leopard.
    I tried looking for something in all the settings and preferences but didn't see anything. I also trashed all the preferences for FCP. Any other ideas before I re-install FCP?

    Try repairing your permissions as well...then be sure to re-boot

Maybe you are looking for

  • Problems with Mavericks, maybe someone's found an answer

    - Count me in on one of the people who had great battery life and now gets LESS THAN TWO HOURS after having changed nothing and having far FAR less than 1000 cycles. - Everything is slower. - Eclipse LOST java 7, how that works I have no idea. I used

  • How to open a file in a new window

    I need to create a link to a file and have that file open in a new window. I do NOT want to have to create a page for each of about 600 files! And yes, it has to live on MobileMe and be created in iWeb, so save the comments about using other tools an

  • Problems with images in ibooks author

    I got a problem about edit images in iBooks author: Here is my problem: I want to make the image zoom into full screen when it was tapped on the iPad. How should I do this? I need your help, please tell me if you got some experience about this. Appre

  • Lumia 710 update to WP 7.8

    Dear Nokia,           I am Wessam Moffed from Egypt. I knew lately that there is an update available for my phone ( nokia lumia 710 ) to the new version of windows phone 7.8 . but my phone doesn't show any signs pf updates and when I connected to zun

  • Microsoft Expression Encoder 4 crashes when clicking Start button to begin live smooth streaming to a publishing point created in Windows Server 2012

    Microsoft Expression Encoder 4 crashes when clicking Start button to begin live smooth streaming to a publishing point created in Windows Server 2012, I've got the following error. Can anyone help me with this? Thanks in advance! Nombre del evento de