<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Anomalous Endpoint Detection and Enforcement Licenses in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406160#M567440</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the deal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want enable&amp;nbsp;Anomalous Endpoint Detection and Enforcement Features of ISE server. Do we need to have Plus licenses to enable mentioned features? I think for Anomalous endpoint enforcement we would need Plus licenses, because we would need to configure an authorization policy for that, but am not really sure and I didn't find any information on the community or elsewhere about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advanced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Reynaldo Lopez&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 16:35:38 GMT</pubDate>
    <dc:creator>reynaldolopeza</dc:creator>
    <dc:date>2021-05-20T16:35:38Z</dc:date>
    <item>
      <title>ISE Anomalous Endpoint Detection and Enforcement Licenses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406160#M567440</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the deal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want enable&amp;nbsp;Anomalous Endpoint Detection and Enforcement Features of ISE server. Do we need to have Plus licenses to enable mentioned features? I think for Anomalous endpoint enforcement we would need Plus licenses, because we would need to configure an authorization policy for that, but am not really sure and I didn't find any information on the community or elsewhere about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advanced.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Reynaldo Lopez&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 16:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406160#M567440</guid>
      <dc:creator>reynaldolopeza</dc:creator>
      <dc:date>2021-05-20T16:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Anomalous Endpoint Detection and Enforcement Licenses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406173#M567443</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Do we need to have Plus licenses to enable mentioned features?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Yes since you would be utilizing profiling data to make an authorization policy decision. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example authz condition:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;EndPoints·AnomalousBehaviour EQUALS True&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Not sure of your ISE version, but strongly suggest referencing&amp;nbsp;the following for additional resources:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1312452864" target="_blank"&gt;ISE Profiling Design Guide - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/workflow/html/b_license_2_7.html" target="_blank"&gt;Cisco ISE 2.7 Admin Guide: Licensing - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/migration-guide-c07-744240.html" target="_blank"&gt;Products - ISE 3.0 License Migration Guide - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 16:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406173#M567443</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-05-20T16:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Anomalous Endpoint Detection and Enforcement Licenses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406265#M567448</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your quick reply and additional resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So just to be sure, ISE license count would increase every time an endpoint hits the &lt;SPAN&gt;authz&amp;nbsp;&lt;/SPAN&gt;Policy "&lt;SPAN&gt;EndPoints·AnomalousBehaviour EQUALS True"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have Base licenses for 2500 endpoints, but if above behaviour is true, we could be fine with just 100 Plus license for anomalous behaviour Endpoints?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reynaldo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reynaldo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 19:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406265#M567448</guid>
      <dc:creator>reynaldolopeza</dc:creator>
      <dc:date>2021-05-20T19:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Anomalous Endpoint Detection and Enforcement Licenses</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406541#M567459</link>
      <description>&lt;P&gt;So just to be sure, ISE license count would increase every time an endpoint hits the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;authz&amp;nbsp;&lt;/SPAN&gt;Policy "&lt;SPAN&gt;EndPoints·AnomalousBehaviour EQUALS True"?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Yes.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have Base licenses for 2500 endpoints, but if above behaviour is true, we could be fine with just 100 Plus license for anomalous behaviour Endpoints?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Depends on your requirements.&amp;nbsp; Technically when a plus license feature is consumed it is a 1:1 ratio and will consume base+plus licenses.&amp;nbsp; In live logs under license types you see the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="content_table" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="69%"&gt;Base and Plus license consumed&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;To reiterate:&amp;nbsp;&lt;SPAN&gt;One Plus feature license is required for each endpoint that is actively authenticated to the network and where profiling data is used to make an Authorization Policy decision.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 11:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-anomalous-endpoint-detection-and-enforcement-licenses/m-p/4406541#M567459</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-05-21T11:34:29Z</dc:date>
    </item>
  </channel>
</rss>

