<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: POV Threat Centric NAC using Qualys with Cisco Identity Services Engine (ISE). in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pov-threat-centric-nac-using-qualys-with-cisco-identity-services/m-p/3522398#M519714</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of Apple iPhones were scanned by Qualys as shown below so it appears supported. The Qualys console would give info why a scan not happened. Please contact Qualys support team if it not working as expected.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="113458" alt="Screen Shot 2017-11-17 at 5.50.05 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/113458_Screen Shot 2017-11-17 at 5.50.05 PM.png" style="height: 149px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Qualys is a cloud platform. In my experience, the scan needs queued first and then, depending on availability of the platform and the scanner, initiate the scan. After that, ISE checks the results in a configured interval. Thus, it can take as long as 30 minutes or longer at times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The third question is up to the ISE admin team, as to what access to grant before receiving the results on an endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you on your answer on the fourth question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 18 Nov 2017 01:58:25 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-11-18T01:58:25Z</dc:date>
    <item>
      <title>POV Threat Centric NAC using Qualys with Cisco Identity Services Engine (ISE).</title>
      <link>https://community.cisco.com/t5/network-access-control/pov-threat-centric-nac-using-qualys-with-cisco-identity-services/m-p/3522397#M519713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;I am currently working on a POV for Cisco Threat Centric NAC using Qualys with Cisco Identity Services Engine (ISE).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;As you know Qualys integration does not use Cisco platform Exchange Grid (pxGrid) for ISE integration, instead it uses Structured Threat Information Expression (STIX).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;This is where my client stands:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;It is working on laptops &lt;SPAN style="color: #575757; text-decoration: underline;"&gt;but not on smartphones&lt;/SPAN&gt;? &lt;EM&gt;&lt;STRONG&gt;Is this a current limitation of this integration?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;Qualys initial scan takes up to 30 min – Is this what expected? &lt;EM&gt;&lt;STRONG&gt;That seems way too long but might be what to expect, can you confirm?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;This rises question about what to happens to the client during the initial Scan? &lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;Quarantine or Allow? &lt;EM&gt;&lt;STRONG&gt;I would think only a &lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN style="text-indent: 0px; color: #58585b; text-align: left; font-style: normal; font-size: 10pt; font-family: CiscoSans, Arial, sans-serif; font-weight: normal;"&gt;&lt;EM&gt;&lt;STRONG&gt;limited access would be given to the client while waiting for then Qualys Scan report&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;when Qualys scan report comes back? what is next?&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;&lt;STRONG&gt;I would think an ISE COA could then even quarantine the client or provide further network/application access based on CVSS score? Can you confirm?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;P&gt;&lt;EM style="font-family: 'Avenir',sans-serif;"&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Avenir',sans-serif;"&gt;Any guidance or best practices would be appreciated. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Nov 2017 18:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pov-threat-centric-nac-using-qualys-with-cisco-identity-services/m-p/3522397#M519713</guid>
      <dc:creator>Samuel Vuillaume</dc:creator>
      <dc:date>2017-11-17T18:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: POV Threat Centric NAC using Qualys with Cisco Identity Services Engine (ISE).</title>
      <link>https://community.cisco.com/t5/network-access-control/pov-threat-centric-nac-using-qualys-with-cisco-identity-services/m-p/3522398#M519714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of Apple iPhones were scanned by Qualys as shown below so it appears supported. The Qualys console would give info why a scan not happened. Please contact Qualys support team if it not working as expected.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="113458" alt="Screen Shot 2017-11-17 at 5.50.05 PM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/113458_Screen Shot 2017-11-17 at 5.50.05 PM.png" style="height: 149px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Qualys is a cloud platform. In my experience, the scan needs queued first and then, depending on availability of the platform and the scanner, initiate the scan. After that, ISE checks the results in a configured interval. Thus, it can take as long as 30 minutes or longer at times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The third question is up to the ISE admin team, as to what access to grant before receiving the results on an endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you on your answer on the fourth question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Nov 2017 01:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pov-threat-centric-nac-using-qualys-with-cisco-identity-services/m-p/3522398#M519714</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-18T01:58:25Z</dc:date>
    </item>
  </channel>
</rss>

