<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi phosawyer,I have all these in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735518#M57381</link>
    <description>&lt;P&gt;Hi phosawyer,&lt;/P&gt;&lt;P&gt;I have all these working (ISE, AC 4, posture rules for AV and WSUS)...&lt;/P&gt;&lt;P&gt;I'd like just to have a rule that check the OS version.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2015 14:39:41 GMT</pubDate>
    <dc:creator>andre.ortega</dc:creator>
    <dc:date>2015-09-30T14:39:41Z</dc:date>
    <item>
      <title>ISE - Checking Windows version</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735510#M57367</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;I'd like to create an authorization rule on ISE to check the version of OS.&lt;/P&gt;&lt;P&gt;For example, If OS = Windows 8 then Accept_Access.&lt;/P&gt;&lt;P&gt;How could I do that?&lt;/P&gt;&lt;P&gt;I have the option "Endpoints:OperatingSystem equals" but I didn't find any OS to complete the rule.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735510#M57367</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2019-03-11T06:06:01Z</dc:date>
    </item>
    <item>
      <title>You can specify OS versions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735511#M57369</link>
      <description>&lt;P&gt;You can specify OS versions in a posture policy. It gives you options like Windows XP, 7, 8, 8.1 10 etc.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_010111.html#task_19FF1593E194455087D9AB00FB843020"&gt;Reference&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 11:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735511#M57369</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-29T11:15:21Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,I need a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735512#M57372</link>
      <description>&lt;P&gt;Hi Marvin,&lt;BR /&gt;I need a authorization rule based on OS.&lt;BR /&gt;Is it possible? Or how could I create a posture policy to accomplish that?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 18:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735512#M57372</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-09-29T18:17:28Z</dc:date>
    </item>
    <item>
      <title>Andre,Think of the Posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735513#M57374</link>
      <description>&lt;P&gt;Andre,&lt;/P&gt;&lt;P&gt;Think of the Posture policy as a tool to give you more information on which to base your Authorization (AuthZ) policy. The various pieces of ISE build on one another like building blocks to give you the granular context-based AuthZ policy you are talking about.&lt;/P&gt;&lt;P&gt;So create a Posture policy that checks for OS version. The result of that policy is then used in your AuthZ policy to grant access or perform other CoA actions.&lt;/P&gt;&lt;P&gt;This slide&amp;nbsp;from Cisco Live shows what I'm talking about with the pieces working together from AuthC through AuthZ:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_posture.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 20:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735513#M57374</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-09-29T20:48:11Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,Thank you for all</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735514#M57375</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thank you for all the attention on this post and for your contribution on this community.&lt;/P&gt;&lt;P&gt;I am trying to figure out how to create a posture rule to check the OS. I know that is possible to specify the OS version as a conditions, but I don't know what will be the requirement.&lt;/P&gt;&lt;P&gt;For example, I can make a posture rule like:&lt;/P&gt;&lt;P&gt;If &lt;STRONG&gt;Windows 8&lt;/STRONG&gt; then AV should be &lt;STRONG&gt;OfficeScan10&lt;/STRONG&gt; (to be compliant)&lt;/P&gt;&lt;P&gt;Now I need a rule like:&lt;/P&gt;&lt;P&gt;If &lt;STRONG&gt;Windows 8&lt;/STRONG&gt; then ???? (to be compliant)&lt;/P&gt;&lt;P&gt;What is the requirement that I have to configure?&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 12:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735514#M57375</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-09-30T12:54:43Z</dc:date>
    </item>
    <item>
      <title>You need to implement posture</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735515#M57376</link>
      <description>&lt;P&gt;You need to implement posture assessment as Martin says.&lt;/P&gt;&lt;P&gt;This will include either using the NAC client or most probably using the Anyconnect client with the posture module.&lt;/P&gt;&lt;P&gt;Then the module will report to ISE extra required information to be able to do what you want.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 13:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735515#M57376</guid>
      <dc:creator>phosawyer</dc:creator>
      <dc:date>2015-09-30T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Hi phosawyer,could you please</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735516#M57377</link>
      <description>&lt;P&gt;Hi phosawyer,&lt;/P&gt;&lt;P&gt;could you please give me um example of this rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 14:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735516#M57377</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-09-30T14:14:50Z</dc:date>
    </item>
    <item>
      <title>Here is a TAC document on</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735517#M57379</link>
      <description>&lt;P&gt;Here is a TAC document on integrating ISE with anyconnect&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/118714-configure-ise-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/118714-configure-ise-00.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And this is a TAC document on designing posture policy to be able to have remediation, in this case using WSUS to update windows.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119214-configure-ise-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119214-configure-ise-00.html&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 14:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735517#M57379</guid>
      <dc:creator>phosawyer</dc:creator>
      <dc:date>2015-09-30T14:38:09Z</dc:date>
    </item>
    <item>
      <title>Hi phosawyer,I have all these</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735518#M57381</link>
      <description>&lt;P&gt;Hi phosawyer,&lt;/P&gt;&lt;P&gt;I have all these working (ISE, AC 4, posture rules for AV and WSUS)...&lt;/P&gt;&lt;P&gt;I'd like just to have a rule that check the OS version.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 14:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735518#M57381</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-09-30T14:39:41Z</dc:date>
    </item>
    <item>
      <title>Ok I understand now Andre, I</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735519#M57382</link>
      <description>&lt;P&gt;Ok I understand now Andre,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a quick look and there is a&amp;nbsp;&lt;STRONG&gt;Session:Device-OS&lt;/STRONG&gt;&amp;nbsp;condition, which then allows you to select.&lt;/P&gt;&lt;P&gt;However I only am able to select&amp;nbsp;&lt;STRONG&gt;Windows&lt;/STRONG&gt;&amp;nbsp;as opposed to a version of windows. This is odd as in the provisioning rules there are specific versions of windows (vista,7,8) and so would've thought the same would be available for the Policy.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 15:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735519#M57382</guid>
      <dc:creator>phosawyer</dc:creator>
      <dc:date>2015-09-30T15:14:55Z</dc:date>
    </item>
    <item>
      <title>Now you got my point</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735520#M57383</link>
      <description>&lt;P&gt;Now you got my point phosawyer.&lt;/P&gt;&lt;P&gt;Does anyone know&amp;nbsp;how to do that?&lt;/P&gt;&lt;P&gt;I mean, to create a rule that check the Windows version, and If it is Windows 8, then give the access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2015 20:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735520#M57383</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-09-30T20:15:01Z</dc:date>
    </item>
    <item>
      <title>I am posting just to say that</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735521#M57385</link>
      <description>&lt;P&gt;I am posting just to say that I found an option.&lt;/P&gt;&lt;P&gt;On Profiling Policies there are policies for Windows7, Windows8, Windows10,... one way to do what I was asking for is to create a "matching identity group", and then to use this identity group on authz policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/profiling_policies_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/endpoint_identity_groups.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/authz.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 00:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-checking-windows-version/m-p/2735521#M57385</guid>
      <dc:creator>andre.ortega</dc:creator>
      <dc:date>2015-10-01T00:23:05Z</dc:date>
    </item>
  </channel>
</rss>

