<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Posture: Download AND Execute a program? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583436#M528257</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have long since known that we can offer both a file download as a remediation as well as the execution of signed code. Is there any way to actually run a signed executable that has been downloaded as part of a posture validation remediation flow on Windows? OS X? Getting an answer for Windows is a priority right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would be on latest ISE/Posture Module and I spoke about it with &lt;A href="https://community.cisco.com//u1/157264"&gt;vsantuka&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Jul 2017 04:48:44 GMT</pubDate>
    <dc:creator>ruhearn</dc:creator>
    <dc:date>2017-07-25T04:48:44Z</dc:date>
    <item>
      <title>Posture: Download AND Execute a program?</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583436#M528257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have long since known that we can offer both a file download as a remediation as well as the execution of signed code. Is there any way to actually run a signed executable that has been downloaded as part of a posture validation remediation flow on Windows? OS X? Getting an answer for Windows is a priority right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would be on latest ISE/Posture Module and I spoke about it with &lt;A href="https://community.cisco.com//u1/157264"&gt;vsantuka&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 04:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583436#M528257</guid>
      <dc:creator>ruhearn</dc:creator>
      <dc:date>2017-07-25T04:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Posture: Download AND Execute a program?</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583437#M528258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Theoretically, yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are two ways to accomplish this, first is to run the installer from the download server.&amp;nbsp; Create an Application Condition at &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Application Condition&lt;/STRONG&gt;.&amp;nbsp; This is where you choose the Application you would like to ensure is installed.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall1.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109728_AppInstall1.PNG" style="height: 573px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Create the Remediation Action that takes place if the Application is not installed at &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Launch Program Remediation&lt;/STRONG&gt;.&amp;nbsp; Point this to the installer source on your download server.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall2.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/109729_AppInstall2.PNG" style="height: 576px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Create the Posture Requirement at &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Requirements&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall3.PNG" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/109730_AppInstall3.PNG" style="height: 19px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Add the rule to your Posture Policy at &lt;STRONG&gt;Policy &amp;gt; Posture&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall4.PNG" class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/109731_AppInstall4.PNG" style="height: 14px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other option is the two step option that you mentioned.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a File Condition at &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; File Condition&lt;/STRONG&gt; to check if the installer file exists.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall5.PNG" class="jive-image image-5" src="https://community.cisco.com/legacyfs/online/fusion/109732_AppInstall5.PNG" style="height: 550px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then go to &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Application Condition&lt;/STRONG&gt; and create the check for the installation of the application.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 13.3333px;"&gt;&lt;IMG alt="AppInstall1.PNG" class="jive-image image-6" src="https://community.cisco.com/legacyfs/online/fusion/109733_AppInstall1.PNG" style="height: 573px; width: 620px;" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From here, we will create both Remediation Actions.&amp;nbsp; Go to &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; File Remediations &lt;/STRONG&gt;and upload the file to be downloaded to your client.&amp;nbsp; This file will reside on ISE.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall6.PNG" class="jive-image image-7" src="https://community.cisco.com/legacyfs/online/fusion/109734_AppInstall6.PNG" style="height: 380px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next, go to &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Launch Program Remediations &lt;/STRONG&gt;and reference the local installer for your application.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall8.PNG" class="jive-image image-8" src="https://community.cisco.com/legacyfs/online/fusion/109735_AppInstall8.PNG" style="height: 377px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create your Requirements at &lt;STRONG style="font-size: 13.3333px;"&gt;Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Requirements&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 13.3333px;"&gt;&lt;IMG alt="AppInstall9.PNG" class="jive-image image-9" src="https://community.cisco.com/legacyfs/online/fusion/109736_AppInstall9.PNG" style="height: 28px; width: 620px;" /&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Add to your Posture Policy.&amp;nbsp; Remember, the rules are run from the top down, so you want to check if the downloaded file exists prior to checking if the application is installed.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="AppInstall10.PNG" class="image-10 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109737_AppInstall10.PNG" style="height: 30px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, having said all that, I did not go into detail as to the permissions/ACLs/access you will need to accomplish these tasks.&amp;nbsp; One of the biggest things to remember is that the client MUST have permissions to install applications or this will not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 12:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583437#M528258</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-07-25T12:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Posture: Download AND Execute a program?</title>
      <link>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583438#M528259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Charles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the thorough reply, I suppose the bit I did miss out on here is that the clients, like many in an enterprise environment, do not have much if any access to run installers that are downloaded. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Russ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 13:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/posture-download-and-execute-a-program/m-p/3583438#M528259</guid>
      <dc:creator>ruhearn</dc:creator>
      <dc:date>2017-07-25T13:34:12Z</dc:date>
    </item>
  </channel>
</rss>

