Phase 5: Posture & Provisioning
Posture assessment ensures that devices connecting to your network meet your organization's security requirements (e.g., updated antivirus, enabled firewall, OS patches) before they are granted full access.
Workflow A: Redirection-Based Posture
This is the most common method for unmanaged or BYOD devices. It uses the network device (switch or WLC) to intercept HTTP traffic and redirect the user to an ISE web page.
The Process
- Initial Connection: The device connects and is placed in a "Limited Access" state via an Authorization Profile.
- Redirection: When the user tries to browse the web, the switch redirects them to the ISE Client Provisioning page.
- Agent Download/Execution: The user is prompted to download and run the AnyConnect (or Cisco Secure Client) posture module.
- Assessment: The agent checks the device against your defined posture policies.
- Compliance/Non-Compliance:
- Compliant: The agent notifies ISE, and ISE sends a CoA (Change of Authorization) to the switch to move the user to the "Full Access" VLAN.
- Non-Compliant: The user is redirected to a remediation page to fix the issues.
Configuration Highlights
- ✔ URL Redirection: Configuring the switch/WLC with the ISE redirection URL.
- ✔ Redirect ACLs: Defining which traffic should be intercepted.
- ✔ Client Provisioning Policy: Setting up the ISE policy that dictates what is presented to the user during redirection.
Workflow B: Redirectionless Posture
For managed corporate devices, redirection can be intrusive. Redirectionless posture relies on the device already having the posture agent installed and communicating with ISE via standard protocols.
The Process
- Agent Communication: The pre-installed agent automatically reaches out to ISE via RADIUS or HTTPS as soon as the device connects.
- Silent Assessment: The assessment happens in the background without the user seeing a web redirect.
- Seamless Transition: Once the device is deemed compliant, ISE triggers a CoA to grant full access.
Requirements
- Pre-deployed Agent: The posture agent must be deployed via MDM (Mobile Device Management) or Group Policy (GPO).
- Known Identity: The device must be able to identify itself to ISE reliably (e.g., via machine certificates) so the agent can associate the posture status with the correct endpoint.
- Network Reachability: The device must have a clear path to communicate with ISE without needing a web redirect to "get started."