<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Patch Management with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493930#M535460</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chyps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please elaborate more on your response - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;ISE 2.2 has additional enhancements in 2.2 for checking SCCM checks with external Windows server.&amp;nbsp; I suggest trying to leverage existing WSUS/SCCM integration, or patch management solution to help automate operation."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jan 2018 13:17:37 GMT</pubDate>
    <dc:creator>Bcssi Network</dc:creator>
    <dc:date>2018-01-24T13:17:37Z</dc:date>
    <item>
      <title>Patch Management with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493928#M535458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across a scenario where patch management for Windows' Machines is getting done through various methods like SCCM, WSUS and sometimes running scripts on end points.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As per my understanding patch management with ISE is performed using AnyConnect integration with ISE, where AnyConnect verifies Critical Patches installation on machine with the help of SCCM Client before giving network access to end point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Customer doesn't want to &lt;SPAN style="font-size: 13.3333px;"&gt;ISE to&lt;/SPAN&gt; rely on SCCM, stating that due to some issues patches can be missing on SCCM client and hence&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;want ISE to &lt;/SPAN&gt;verify&lt;SPAN style="font-size: 10pt;"&gt; presence of patches on end points using some manual configuration of Windows registry or KB values.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Request you to please help me out if you are aware of any such &lt;/SPAN&gt;customisation&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;with&lt;SPAN style="font-size: 10pt;"&gt; ISE for Windows patch validations and suggest if any solution/workaround is &lt;/SPAN&gt;available&lt;SPAN style="font-size: 10pt;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Abhishek&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 09:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493928#M535458</guid>
      <dc:creator>abhvyas</dc:creator>
      <dc:date>2017-08-02T09:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Patch Management with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493929#M535459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a number of custom checks for Windows updates that are pushed as part of the Posture rules updates&amp;nbsp;&amp;nbsp; from Cisco.&amp;nbsp; That said, this is typically a much more management intensive route.&amp;nbsp; ISE 2.2 has additional enhancements in 2.2 for checking SCCM checks with external Windows server.&amp;nbsp; I suggest trying to leverage existing WSUS/SCCM integration, or patch management solution to help automate operation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 14:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493929#M535459</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-02T14:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Patch Management with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493930#M535460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chyps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please elaborate more on your response - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;ISE 2.2 has additional enhancements in 2.2 for checking SCCM checks with external Windows server.&amp;nbsp; I suggest trying to leverage existing WSUS/SCCM integration, or patch management solution to help automate operation."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2018 13:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493930#M535460</guid>
      <dc:creator>Bcssi Network</dc:creator>
      <dc:date>2018-01-24T13:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Patch Management with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493931#M535461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, comment was around enhancements on AC compliance module code to check for all patches instead of just critical patches, recommend using the latest CM module to work with all patch levels &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Imran.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Jan 2018 01:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-management-with-ise/m-p/3493931#M535461</guid>
      <dc:creator>imbashir</dc:creator>
      <dc:date>2018-01-27T01:51:54Z</dc:date>
    </item>
  </channel>
</rss>

