<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Aaron. I was looking in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806377#M56444</link>
    <description>&lt;P&gt;Thanks Aaron. I was looking at the posture conditions in ISE but wasn't able find any that says if service pack is equal to something. Do you have any idea about it? Its one of the requirement as per attached diagram.&lt;/P&gt;</description>
    <pubDate>Sun, 06 Dec 2015 16:37:10 GMT</pubDate>
    <dc:creator>sqambera</dc:creator>
    <dc:date>2015-12-06T16:37:10Z</dc:date>
    <item>
      <title>ISE Rules</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806375#M56440</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Could anyone please look at the attached requirement diagram. The Cisco ISE needs to be configured accordingly. Do I have to create Authorization rules for achieving these results? I am wondering that under Authorization conditions in ISE where could I find things like (I am trying to figure out) "windows service pack equal 1", "operating system equals windows 7", etc.&lt;/P&gt;
&lt;P&gt;Or is it somewhere else that I need to look for configuring these requirements? Does this needs to be done under Posture rules?&lt;/P&gt;
&lt;P&gt;Thanks in advance for all your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Qamber&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806375#M56440</guid>
      <dc:creator>sqambera</dc:creator>
      <dc:date>2019-03-11T06:17:47Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806376#M56443</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Not exactly. Not all the requirements you ask and the flow you want to get will be done only with Authorization rules.&lt;/P&gt;
&lt;P&gt;You'll need to use authentication and authorization rules, plus provisioning and posture rules and checks.&lt;/P&gt;
&lt;P&gt;Your flow is something similar to what I desgined in my company, the only thing you don't have in yours is the BYOD side.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2015 08:24:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806376#M56443</guid>
      <dc:creator>Aaron Castro Sanchez</dc:creator>
      <dc:date>2015-12-05T08:24:21Z</dc:date>
    </item>
    <item>
      <title>Thanks Aaron. I was looking</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806377#M56444</link>
      <description>&lt;P&gt;Thanks Aaron. I was looking at the posture conditions in ISE but wasn't able find any that says if service pack is equal to something. Do you have any idea about it? Its one of the requirement as per attached diagram.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2015 16:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806377#M56444</guid>
      <dc:creator>sqambera</dc:creator>
      <dc:date>2015-12-06T16:37:10Z</dc:date>
    </item>
    <item>
      <title>You have to create a posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806378#M56446</link>
      <description>&lt;P&gt;You have to create a posture result condition that would be something like:&lt;/P&gt;
&lt;P&gt;If OS equals "any" met if "posture condition" else "remediation action".&lt;/P&gt;
&lt;P&gt;Most&amp;nbsp;OS should be already there.&lt;/P&gt;
&lt;P&gt;Posture conditions come pre loaded,&amp;nbsp;so you only have to select i.e. pc_W7_SP1_int.&lt;/P&gt;
&lt;P&gt;Same for remediation, many come created, or you can create new ones as well.&lt;/P&gt;
&lt;P&gt;Once you have the posture requirements rules, then you can create the policy so if an identity group matches the OS then the requirement will be the one you created as a rule.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2015 17:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806378#M56446</guid>
      <dc:creator>Aaron Castro Sanchez</dc:creator>
      <dc:date>2015-12-06T17:29:15Z</dc:date>
    </item>
    <item>
      <title>Thanks Aaron for helping out.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806379#M56447</link>
      <description>&lt;P&gt;Thanks Aaron for helping out.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 04:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806379#M56447</guid>
      <dc:creator>sqambera</dc:creator>
      <dc:date>2015-12-09T04:09:35Z</dc:date>
    </item>
    <item>
      <title>Hi Community,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806380#M56448</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;could you help me configure posture to check for operating system version? I want to allow access only for Windows 7 and Windows 10. Other Windows version should be rejected.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 11:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-rules/m-p/2806380#M56448</guid>
      <dc:creator>Bob Goal</dc:creator>
      <dc:date>2016-11-23T11:41:08Z</dc:date>
    </item>
  </channel>
</rss>

