<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AntiMalware  - Definition checks - Posure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4399820#M567203</link>
    <description>&lt;P&gt;Yes your assumptions are correct, but with Windows Defender the risk of the definitions being older than five days is very low since Microsoft updates on a 2 hour schedule. I still prefer to use 5 days from the last known definition date because of this though, not every AV/AM is as frequent as Microsoft.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 May 2021 06:11:09 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2021-05-09T06:11:09Z</dc:date>
    <item>
      <title>AntiMalware  - Definition checks - Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4399818#M567202</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We're running ISE 2.6 with Patch 8 installed. AnyConnect is 4.8 and the Compliance Module is 4.3.X. I've been asked to configure a New AV Posture policy Definition check for Windows Defender.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name: AV_Def_5days&lt;/P&gt;&lt;P&gt;Compliance Module: 4.X or later&lt;/P&gt;&lt;P&gt;Operating System: Windows All&lt;/P&gt;&lt;P&gt;Vendor: Microsoft Corporation&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Check Type: Definition&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Allow Virus Definition to be 5 days older than the Current system date&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. With the above config, I assume users should be having the Definition file date which are no longer older than the current system date (running on users PC). Is that correct?&lt;/P&gt;&lt;P&gt;2. What if the vendor isn't updating their AV database every 5 days once? Will the ISE mark them as non-compliant?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 09 May 2021 08:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4399818#M567202</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-05-09T08:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: AntiMalware  - Definition checks - Posure</title>
      <link>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4399820#M567203</link>
      <description>&lt;P&gt;Yes your assumptions are correct, but with Windows Defender the risk of the definitions being older than five days is very low since Microsoft updates on a 2 hour schedule. I still prefer to use 5 days from the last known definition date because of this though, not every AV/AM is as frequent as Microsoft.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 May 2021 06:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4399820#M567203</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-05-09T06:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: AntiMalware  - Definition checks - Posure</title>
      <link>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4400015#M567207</link>
      <description>&lt;P&gt;Thanks Damien.&lt;/P&gt;&lt;P&gt;We're also looking for the other option "Latest file date" which I guess implies, the virus definition files installed on the machine are no more 5 days older than the versions that ISE knows about. Is it correct?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 01:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/antimalware-definition-checks-posture/m-p/4400015#M567207</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-05-10T01:31:59Z</dc:date>
    </item>
  </channel>
</rss>

