<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 1.3 posture - specific MS KB in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424510#M524707</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Krishnan.&lt;/P&gt;&lt;P&gt;It is not completely answering my question:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If we have the KB number i.e. &lt;SPAN style="color: #000000; font-family: CourierNewPSMT; font-size: 17.3333px;"&gt;KB4015217&lt;/SPAN&gt;, how could we generate the compound condition to check this? The KB checks I have seen all include a pre and suffix, which I don't know how it is generated i.e. &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;pc_W7_64_KB3080446&lt;/SPAN&gt;&lt;STRONG style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;_MS15-109&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;I understand you can create different requirements for different operating systems, but we would need to create different requirements for Win10 v1607, Win10 v1511 and Win10 initial version.&lt;BR /&gt;This does not seem to be separated out on the list of operating systems on ISE.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 May 2017 08:24:16 GMT</pubDate>
    <dc:creator>gtilburg</dc:creator>
    <dc:date>2017-05-24T08:24:16Z</dc:date>
    <item>
      <title>ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424508#M524700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our customer wants to protect against WannaCry using posture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can we check the presence of specific Microsoft KBs using ISE posture with ISE 1.3?&lt;BR /&gt;The predefined posture conditions (i.e. pr_Win7_64_Hotfixes) contain a number of combined KB checks, but we would like to make a new condition that only lists the WannaCry specific ones. If we have the KB number, how can we generate the condition? We are unclear on how the last bit (i.e. pc_W7_64_KB3080446&lt;STRONG&gt;_MS15-109&lt;/STRONG&gt;) is generated.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How would it be possible to have different checks for different Win 10 versions?&lt;BR /&gt;Windows 10 has different versions with different KBs to protect against WannaCry (see list below). What would be the way to check the correct KBs for a specific Win10 version?&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 13.0pt; font-family: CourierNewPS-BoldMT;"&gt;Win 10 initial versione July 2015&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;May 9, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4019474&lt;/SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;April 11, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4015221&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 22, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4016637&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 14, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4012606&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 13.0pt; font-family: CourierNewPS-BoldMT;"&gt;Win 10 v1511&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;May 9, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4019473&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;April 11, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4015219&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 22, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4016636&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 14, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4013198&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;STRONG style="font-size: 13.0pt; font-family: CourierNewPS-BoldMT;"&gt;Win 10 v1607&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;May 9, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4019472&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;April 11, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4015217&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 22, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4016635&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 22, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4015438&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;March 14, 2017&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KB4013429&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;Many thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 13.0pt; font-family: CourierNewPSMT; color: black;"&gt;Gert&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 13:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424508#M524700</guid>
      <dc:creator>gtilburg</dc:creator>
      <dc:date>2017-05-23T13:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424509#M524705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Gert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please create custom compound conditions for the KB and added it to the requirements. Add requirements to posture policy. Create different requirements for different operating systems in your case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a documentation that describes that&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116143-config-cise-posture-00.html#anc17" title="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116143-config-cise-posture-00.html#anc17"&gt;Posture Services on the Cisco ISE Configuration Guide - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2017 01:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424509#M524705</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-05-24T01:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424510#M524707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Krishnan.&lt;/P&gt;&lt;P&gt;It is not completely answering my question:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If we have the KB number i.e. &lt;SPAN style="color: #000000; font-family: CourierNewPSMT; font-size: 17.3333px;"&gt;KB4015217&lt;/SPAN&gt;, how could we generate the compound condition to check this? The KB checks I have seen all include a pre and suffix, which I don't know how it is generated i.e. &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;pc_W7_64_KB3080446&lt;/SPAN&gt;&lt;STRONG style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;_MS15-109&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;I understand you can create different requirements for different operating systems, but we would need to create different requirements for Win10 v1607, Win10 v1511 and Win10 initial version.&lt;BR /&gt;This does not seem to be separated out on the list of operating systems on ISE.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2017 08:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424510#M524707</guid>
      <dc:creator>gtilburg</dc:creator>
      <dc:date>2017-05-24T08:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424511#M524709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;OL&gt;&lt;LI&gt;The components in a compound condition are individual posture conditions in one or more categories. In another word, they need defined as individual posture conditions for file checks, etc.&lt;UL&gt;&lt;LI&gt;&lt;IMG alt="Screen Shot 2017-05-28 at 10.43.24 AM.png" class="image-1 jive-image" height="161" src="/legacyfs/online/fusion/107904_Screen Shot 2017-05-28 at 10.43.24 AM.png" style="height: 160.57039711191337px; width: 126px;" width="126" /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;If you really need differentiated posture requirements based on different Win10 releases, please bring the use cases with our product management team.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 May 2017 17:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424511#M524709</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-28T17:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424512#M524711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hsing-Tsu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Not all the individual KBs exist on the ISE predefined conditions. i.e. we would need to check KB4015221, KB4016637, KB4012606,… which are not predefined.&lt;/P&gt;&lt;P&gt;Is there a way to create these individual KB conditions manually?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, any other recommendation to only allow WannaCry-protected hosts on the network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 07:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424512#M524711</guid>
      <dc:creator>gtilburg</dc:creator>
      <dc:date>2017-05-29T07:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.3 posture - specific MS KB</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424513#M524714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The three KB articles are corresponding to OS Build numbers for Windows 10 which initially released in July 2015:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;KB4015221 = OS Build 10240.17354&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;KB4016637 = OS Build 10240.17320&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;KB4012606 = OS Build 10240.17319&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P&gt;Thus, you may create them as registry checks on&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By updating to a later OS build is possibly also addressed the SMB vulnerabilities, but they are not specific to that issue. The KBs added for CSCve42752 are specific to SMB and our engineering team updated it mid last week. That should cover it for all Windows client versions supported by ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 21:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-posture-specific-ms-kb/m-p/3424513#M524714</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-29T21:19:27Z</dc:date>
    </item>
  </channel>
</rss>

