<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE posture requirement to check if endpoint's USP port is disabled in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352371#M112903</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I wonder if it is possible to set the disabled USP Port in the endpoints as a requirement in ISE Posture ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:09:32 GMT</pubDate>
    <dc:creator>ccie16351</dc:creator>
    <dc:date>2019-03-11T04:09:32Z</dc:date>
    <item>
      <title>ISE posture requirement to check if endpoint's USP port is disabled</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352371#M112903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I wonder if it is possible to set the disabled USP Port in the endpoints as a requirement in ISE Posture ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352371#M112903</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2019-03-11T04:09:32Z</dc:date>
    </item>
    <item>
      <title>ISE posture requirement to check if endpoint's USP port is disab</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352372#M112922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your question pertains to the capability of the ISE disabling the USB port on a PC, then the answer is no.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the NAC agent, however, you can check various programs and may be able to check the condition of USB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would have to create a New Posture Condition and Remediations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The condition that I will use in this example is a Registry Key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor\Start" has a value of 3, the USB is enabled.&amp;nbsp; A value of 4 is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So set a Posture Condition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Click Policy &amp;gt; Policy Elements &amp;gt; Conditions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/7/9/168970-USB_1.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Choose &lt;STRONG&gt;Posture&lt;/STRONG&gt; from the left menu:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/7/9/168974-USB_2.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then choose &lt;STRONG&gt;Registry Condition&lt;/STRONG&gt; from the left menu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click &lt;STRONG&gt;+Add&lt;/STRONG&gt; to add a new Posture Condition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/7/9/168975-USB_End.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you have to create Remediation Actions.&amp;nbsp; Click the &lt;STRONG&gt;Results&lt;/STRONG&gt; button at the top of the left Menu:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/7/9/168976-REMED_1.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Choose &lt;STRONG&gt;Remediation Actions&lt;/STRONG&gt; and choose the Remediation you want to use.&amp;nbsp; I chose &lt;STRONG&gt;Link Remediation&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;+Add&lt;/STRONG&gt; to add a new Link Remediation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/8/9/168980-REMED_2.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then choose &lt;STRONG&gt;Requirements&lt;/STRONG&gt; from the left menu and create a new Remediation Result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/8/9/168981-REMED_3.GIF" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, you can choose different remediations as necessary for your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Dec 2013 16:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352372#M112922</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2013-12-05T16:17:42Z</dc:date>
    </item>
    <item>
      <title>ISE posture requirement to check if endpoint's USP port is disab</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352373#M112932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Charles,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I hasn't tried the solution, yet, but what you have said, with the pictorial detailed steps, I am quite confident, it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very much appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Dec 2013 17:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-requirement-to-check-if-endpoint-s-usp-port-is/m-p/2352373#M112932</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2013-12-05T17:15:02Z</dc:date>
    </item>
  </channel>
</rss>

