<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enforcing OS version using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4406462#M567453</link>
    <description>&lt;P&gt;Thanks much again Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I guess it would work only with Windows machine, not for any other OS e.g. MAC and generally enterprise will have various Client OSs to look at.&lt;/P&gt;</description>
    <pubDate>Fri, 21 May 2021 08:03:35 GMT</pubDate>
    <dc:creator>VipulAgr</dc:creator>
    <dc:date>2021-05-21T08:03:35Z</dc:date>
    <item>
      <title>Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404490#M567344</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there is anyway to verify minimum OS version in ISE policy set , e.g. allowing only&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Windows10 1903 (build 18362) or higher&lt;/LI&gt;&lt;LI&gt;Mac OS - 10.14 or higher&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404490#M567344</guid>
      <dc:creator>VipulAgr</dc:creator>
      <dc:date>2021-05-18T08:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404511#M567346</link>
      <description>&lt;P&gt;is this BYOD or pre-deployed equiment ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE with Posture check do this for you.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404511#M567346</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-05-18T08:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404552#M567352</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1129800"&gt;@VipulAgr&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;at &lt;STRONG&gt;Policy &amp;gt; Profiling &amp;gt; Profiling Policies&lt;/STRONG&gt;, create the following &lt;STRONG&gt;Profiler Policy&lt;/STRONG&gt; (for ex.)&lt;/P&gt;&lt;PRE&gt;Name: Build18362&lt;BR /&gt;Parent Policy: Windows10-Workstation&lt;BR /&gt;Condition: ACIDEX_device-platform-version CONTAINS 10.0.18362&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="BUILD 18362.png" style="width: 660px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120624i00530D0B9E07DCA2/image-dimensions/660x396?v=v2" width="660" height="396" role="button" title="BUILD 18362.png" alt="BUILD 18362.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;Logical Profiles&lt;/STRONG&gt;, create the following &lt;STRONG&gt;Logical Profile&lt;/STRONG&gt; (for ex.)&lt;/P&gt;&lt;PRE&gt;Name: Windows10-Builds&lt;BR /&gt;Assigned Policies: Build18362&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="BUILD 18362.png" style="width: 677px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120626i1AD528FD6D05C662/image-dimensions/677x285?v=v2" width="677" height="285" role="button" title="BUILD 18362.png" alt="BUILD 18362.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;Policy &amp;gt; Policy Set&lt;/STRONG&gt; you are able to create an &lt;STRONG&gt;Authorization Policy&lt;/STRONG&gt; like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="BUILD 18362.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120627i28696392C22F3616/image-size/large?v=v2&amp;amp;px=999" role="button" title="BUILD 18362.png" alt="BUILD 18362.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 10:55:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404552#M567352</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-05-18T10:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404585#M567353</link>
      <description>&lt;P&gt;Thanks Marcelo, That's really helpful. I was hoping to have a straight forward profile which allows OS versions higher than specific, but looks like I need to create multiple logical profiles for each version which I need to allow. But that works.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:14:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4404585#M567353</guid>
      <dc:creator>VipulAgr</dc:creator>
      <dc:date>2021-05-18T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405630#M567397</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;Surprisingly, this &lt;STRONG&gt;cannot&lt;/STRONG&gt; be enforced in a posture policy .&lt;/STRIKE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 11:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405630#M567397</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2021-05-20T11:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405882#M567425</link>
      <description>&lt;P&gt;Yeah True, very surprising when Posture policies are so feature rich but doesn't support this basic requirement.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 08:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405882#M567425</guid>
      <dc:creator>VipulAgr</dc:creator>
      <dc:date>2021-05-20T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405971#M567429</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285490"&gt;@Peter Koltl&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1129800"&gt;@VipulAgr&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;to "enforce" in a &lt;STRONG&gt;Posture Policy&lt;/STRONG&gt;, try this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;In &lt;STRONG&gt;Work Centers &amp;gt; Posture &amp;gt; Policy Elements &amp;gt; Conditions &amp;gt; Registry&lt;/STRONG&gt;:&lt;/P&gt;&lt;PRE&gt;Regitry Root Key: HKLM&lt;BR /&gt;Sub Key:&amp;nbsp;SOFTWARE\Microsoft\Windows NT\CurrentVersion&lt;BR /&gt;Value Name: ProductName&lt;BR /&gt;Value Data: 10&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="COMMUNITY.png" style="width: 685px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120818i04F9E3AC0BC5B16F/image-dimensions/685x285?v=v2" width="685" height="285" role="button" title="COMMUNITY.png" alt="COMMUNITY.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Regitry Root Key: HKLM&lt;BR /&gt;Sub Key:&amp;nbsp;SOFTWARE\Microsoft\Windows NT\CurrentVersion&lt;BR /&gt;Value Name: CurrentBuild&lt;BR /&gt;Value Data: 18362&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="COMMUNITY.png" style="width: 688px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120819iFC27863475BC119B/image-dimensions/688x295?v=v2" width="688" height="295" role="button" title="COMMUNITY.png" alt="COMMUNITY.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;In &lt;STRONG&gt;Work Centers &amp;gt; Posture &amp;gt; Policy Elements &amp;gt; Requirements&lt;/STRONG&gt;, create the following:&lt;/P&gt;&lt;PRE&gt;Name: Req-Check-WindowsOSVersion&lt;BR /&gt;Operating System: Windows All&lt;BR /&gt;Compliance Module: 4.x or later&lt;BR /&gt;Posture: AnyConnect | Check-WindowsOSVersion | Message Text Only&lt;BR /&gt;&lt;BR /&gt;Name: Req-Check-WindowsOS_Build&lt;BR /&gt;Operating System: Windows All&lt;BR /&gt;Compliance Module: 4.x or later&lt;BR /&gt;Posture: AnyConnect | Check-WindowsOS_Build | Message Text Only&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="COMMUNITY.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120820i983C3F83F7CB8784/image-size/large?v=v2&amp;amp;px=999" role="button" title="COMMUNITY.png" alt="COMMUNITY.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In &lt;STRONG&gt;Work Centers &amp;gt; Posture &amp;gt; Posture Policy&lt;/STRONG&gt;:&lt;/P&gt;&lt;PRE&gt;Rule Name: SO-Mandatory&lt;BR /&gt;Identity Groups: Any&lt;BR /&gt;Operating Systems: Windows All&lt;BR /&gt;Compliance Module: 4.x or later&lt;BR /&gt;Posture Type: Any Connect&lt;BR /&gt;Other Conditions: &amp;lt;choose your condition&amp;gt;&lt;BR /&gt;Requirements: &lt;STRONG&gt;Mandatory&lt;/STRONG&gt; - Check-WindowsOSVersion &lt;U&gt;and&lt;/U&gt; &lt;STRONG&gt;Mandatory&lt;/STRONG&gt; - Check-WindowsOS_Build&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="COMMUNITY02.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120821i49270BBD908F43D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="COMMUNITY02.png" alt="COMMUNITY02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 11:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4405971#M567429</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-05-20T11:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing OS version using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4406462#M567453</link>
      <description>&lt;P&gt;Thanks much again Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I guess it would work only with Windows machine, not for any other OS e.g. MAC and generally enterprise will have various Client OSs to look at.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 08:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enforcing-os-version-using-ise/m-p/4406462#M567453</guid>
      <dc:creator>VipulAgr</dc:creator>
      <dc:date>2021-05-21T08:03:35Z</dc:date>
    </item>
  </channel>
</rss>

