<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE EPS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-eps/m-p/3838371#M473866</link>
    <description>&lt;P&gt;Hey Terry,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of Cisco Firepower are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have your pxGrid remediaton instance configured on Firepower, have you setup your quarantine by source ip address &amp;nbsp;remediation policies and assigned them to your Firepower quarantine policies and configured your Firepower quarantine rules?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firepower will trigger an automated mitigation action via pxGrid, you will want to have your Session:EPSStatus:Quarantine ISE authorization policy configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both ISE authz Session:EPSStatus:Quarantine rules and ISE ANC policies (port-shut, port-bounce, quarantine) are Adaptive Network Control (ANC) mitigation actions. &amp;nbsp; &amp;nbsp;Session:EPSStatus:Quarantine is considered ANC 1.0, Firepower subscribes the pxGrid EndpointProtection Service Topic to perform this mitigation action. &amp;nbsp;ISE ANC policies are considered ANC 2.0, pxGrid clients like Stealthwatch 7.0 subscribe to &amp;nbsp;the pxGrid AdaptiveNetworkControl topic to perform these mitigation actions.. &amp;nbsp;Firepower, even though, they also subscribe to the pxGrid AdaptiveNetworkControl, DO NOT use ISE ANC policies, they still use Session:EPSSTATUS:Quarantine policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firepower 6.0 does not support ANC mitigations via pxGrid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have additional questions, please email me directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;
&lt;P&gt;jeppich@cisco.com&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2019 01:06:48 GMT</pubDate>
    <dc:creator>jeppich</dc:creator>
    <dc:date>2019-04-15T01:06:48Z</dc:date>
    <item>
      <title>ISE EPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eps/m-p/3838022#M473864</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently trying to setup RTC between FMC &amp;amp; ISE which looks like it is failing on the ISE side.&lt;/P&gt;&lt;P&gt;To simplify things I'm trying to manually implement device quarantine using 'Session:EPSStatus equals Quarantine' as a condition under global exceptions which is linked to an authorization profile that will place the device into a VLAN - this doesn't work. However, if I use 'Session:ANC equals QUARANTINE' (QUARANTINE being a policy with an ANC action of QUARANTINE) it works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I then test the RTC setup with either the EPS or ANC options (or even both with an OR statement) it doesn't work. On the FMC I can see the triggered event listed under 'Analysis &amp;gt; Correlation Events' and I can see the pxgrid connection under 'System &amp;gt; Syslog'.&lt;/P&gt;&lt;P&gt;On ISE under 'Administration &amp;gt; pxGrid Services &amp;gt; All Clients' I can see the 'iseagent' client online with 'ANC,EPS' listed under 'Client Group(s)'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I'm running ISE version 2.3 - is the 'EPSStatus' condition supported with 2.3?&lt;/P&gt;&lt;P&gt;- My understanding is that FMC - ISE RTC only supports EPS and not ANC - is this correct?&lt;/P&gt;&lt;P&gt;- If both the answers to the above are yes - does anyone have an idea why the manual quarantine option using 'EPSStatus' may not be&amp;nbsp; working?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;T&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 11:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eps/m-p/3838022#M473864</guid>
      <dc:creator>Terry</dc:creator>
      <dc:date>2019-04-13T11:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EPS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eps/m-p/3838371#M473866</link>
      <description>&lt;P&gt;Hey Terry,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of Cisco Firepower are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have your pxGrid remediaton instance configured on Firepower, have you setup your quarantine by source ip address &amp;nbsp;remediation policies and assigned them to your Firepower quarantine policies and configured your Firepower quarantine rules?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firepower will trigger an automated mitigation action via pxGrid, you will want to have your Session:EPSStatus:Quarantine ISE authorization policy configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both ISE authz Session:EPSStatus:Quarantine rules and ISE ANC policies (port-shut, port-bounce, quarantine) are Adaptive Network Control (ANC) mitigation actions. &amp;nbsp; &amp;nbsp;Session:EPSStatus:Quarantine is considered ANC 1.0, Firepower subscribes the pxGrid EndpointProtection Service Topic to perform this mitigation action. &amp;nbsp;ISE ANC policies are considered ANC 2.0, pxGrid clients like Stealthwatch 7.0 subscribe to &amp;nbsp;the pxGrid AdaptiveNetworkControl topic to perform these mitigation actions.. &amp;nbsp;Firepower, even though, they also subscribe to the pxGrid AdaptiveNetworkControl, DO NOT use ISE ANC policies, they still use Session:EPSSTATUS:Quarantine policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firepower 6.0 does not support ANC mitigations via pxGrid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have additional questions, please email me directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;
&lt;P&gt;jeppich@cisco.com&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2019 01:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eps/m-p/3838371#M473866</guid>
      <dc:creator>jeppich</dc:creator>
      <dc:date>2019-04-15T01:06:48Z</dc:date>
    </item>
  </channel>
</rss>

