<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic First and foremost, which in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-posture-capabilities-limit/m-p/3091844#M25680</link>
    <description>&lt;P&gt;First and foremost, which version and Patch level of ISE do you have installed?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. give access using policy based on time (working hours limited access and after working hours internet only access)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;- Yes. &amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Before You Begin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;To perform the following task, you must be a Super Admin or Policy Admin.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 1 Choose Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Time and Date &amp;gt; Add.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 2 Enter appropriate values in the fields.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;• In the Standard Settings area, specify the time and date to provide access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;• In the Exceptions area, specify the time and date range to limit access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 3 Click Submit&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;2. will non complaint devices return to the production VALN after remediation when the reason for that made it non complaint disappear?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Yes, After Remediation, Posture Check is run again and upon success, placement in the correct VLAN will happen&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. can the solution be full Automated: fix devices that are not compliant automatically for example :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;device without McAfee, will ISE install McAfee&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Device with McAfee but not updated, will ise auto update&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;automatically insall updated for not updated windows devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Automatic Remediation can be configured&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. can we build new roles based on our OS and antivirus?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Integrate and communicate with McAfee to isolate detected device?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- ISE Can detect the installation of and definition dates for AV&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6. If ISE system down. What will happen in our network? (for example connected devices and new devices)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- If the Whole (HA) ISE System is down, logged in users will continute to be authorized, whereas new users would not be able to authenticate onto the network. &amp;nbsp;This can be mitigated through the use of specific switchport configurations, for example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;authentication event server dead action reinitialize vlan 50&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; authentication event server dead action authorize voice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;7. can the ISE Integrate with Juniper and PaloAlto global protect?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- This integration does not exist today, however, Cisco has opened up the ISE APIs and pxGrid connectivity to the Security Community as a whole. &amp;nbsp;If the companies referenced want the integration, all they need to do is to build it into their products.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8. can ISE Integrate with next generation Firewall PaloAlto?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Check this link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;9. Ability to stopping USB port on device?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- v2.1 allows persistent check for USB Mass Storage devices and can force non-compliance when a storage device (USB Flash Drive, External Hard Drive, etc.) is attached.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jul 2017 14:05:25 GMT</pubDate>
    <dc:creator>Charlie Moreton</dc:creator>
    <dc:date>2017-07-23T14:05:25Z</dc:date>
    <item>
      <title>ISE Posture capabilities limit</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-capabilities-limit/m-p/3091843#M25677</link>
      <description>&lt;P&gt;we have ISE distributed demployment and we use ISE for wired and wireless access through the do1x and easy connect methods.&lt;BR /&gt;my manager wants to utilize the ISE posture capabilities in our environment. we need to check on how to do the below tasks with ISE posture, keeping in mind that we intend to use the NAC agent (also if the anyconnect is needed in any of the below situations please advice):&lt;/P&gt;
&lt;P&gt;1. give access using policy based on time (working hours limited access and after working hours internet only access)?&lt;BR /&gt;2. will non complaint devices return to the production VALN after remediation when the reason for that made it non complaint disappear? &lt;BR /&gt;3. can the solution be full Automated: fix devices that are not compliant automatically for example : &lt;BR /&gt; device without McAfee, will ISE install McAfee &lt;BR /&gt; Device with McAfee but not updated, will ise auto update&lt;BR /&gt; automatically insall updated for not updated windows devices&lt;BR /&gt;4. can we build new roles based on our OS and antivirus?&lt;BR /&gt;5. Integrate and communicate with McAfee to isolate detected device?&lt;BR /&gt;6. If ISE system down. What will happen in our network? (for example connected devices and new devices)&lt;BR /&gt;7. can the ISE Integrate with Juniper and PaloAlto global protect?&lt;BR /&gt;8. can ISE Integrate with next generation Firewall PaloAlto?&lt;BR /&gt;9. Ability to stopping USB port on device?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-capabilities-limit/m-p/3091843#M25677</guid>
      <dc:creator>Amr Mohammed Mashaal</dc:creator>
      <dc:date>2019-03-11T07:52:47Z</dc:date>
    </item>
    <item>
      <title>First and foremost, which</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-posture-capabilities-limit/m-p/3091844#M25680</link>
      <description>&lt;P&gt;First and foremost, which version and Patch level of ISE do you have installed?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. give access using policy based on time (working hours limited access and after working hours internet only access)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;- Yes. &amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Before You Begin&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;To perform the following task, you must be a Super Admin or Policy Admin.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 1 Choose Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Time and Date &amp;gt; Add.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 2 Enter appropriate values in the fields.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;• In the Standard Settings area, specify the time and date to provide access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;• In the Exceptions area, specify the time and date range to limit access.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Step 3 Click Submit&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;2. will non complaint devices return to the production VALN after remediation when the reason for that made it non complaint disappear?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Yes, After Remediation, Posture Check is run again and upon success, placement in the correct VLAN will happen&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. can the solution be full Automated: fix devices that are not compliant automatically for example :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;device without McAfee, will ISE install McAfee&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Device with McAfee but not updated, will ise auto update&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;automatically insall updated for not updated windows devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Automatic Remediation can be configured&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. can we build new roles based on our OS and antivirus?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Integrate and communicate with McAfee to isolate detected device?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- ISE Can detect the installation of and definition dates for AV&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6. If ISE system down. What will happen in our network? (for example connected devices and new devices)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- If the Whole (HA) ISE System is down, logged in users will continute to be authorized, whereas new users would not be able to authenticate onto the network. &amp;nbsp;This can be mitigated through the use of specific switchport configurations, for example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;authentication event server dead action reinitialize vlan 50&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; authentication event server dead action authorize voice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;7. can the ISE Integrate with Juniper and PaloAlto global protect?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- This integration does not exist today, however, Cisco has opened up the ISE APIs and pxGrid connectivity to the Security Community as a whole. &amp;nbsp;If the companies referenced want the integration, all they need to do is to build it into their products.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8. can ISE Integrate with next generation Firewall PaloAlto?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- Check this link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/Integrating-Cisco-ISE-Guest-Authentication-with-PAN-OS/ta-p/98295&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;9. Ability to stopping USB port on device?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;SPAN&gt;- v2.1 allows persistent check for USB Mass Storage devices and can force non-compliance when a storage device (USB Flash Drive, External Hard Drive, etc.) is attached.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jul 2017 14:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-posture-capabilities-limit/m-p/3091844#M25680</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-07-23T14:05:25Z</dc:date>
    </item>
  </channel>
</rss>

