<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Patch ISE condition in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/4693979#M577397</link>
    <description>&lt;P&gt;You can get the updated link, for the last Compliance Module, here: &lt;A href="https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 17:40:03 GMT</pubDate>
    <dc:creator>Mauritz</dc:creator>
    <dc:date>2022-09-26T17:40:03Z</dc:date>
    <item>
      <title>Patch ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494121#M509789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;I’m reaching out in need of some support with an issue I am facing with a customer ISE project.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Customer has Landesk Version 10 Security Patch Manager by which they push Windows Security Patches to all endpoints. They have two requirements.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1" style="color: #000000; font-family: -webkit-standard;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt;"&gt;Run a posture check for Landesk App installation and running services.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt;"&gt;Check for Latest critical patches installation and remediate if not installed. (Under Conditons\Patch Management Conditions\Vendor=Landesk\Up to Date\Critical Patches.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 11pt; font-family: Calibri, sans-serif;"&gt;I have created policies for Rule 1 and 2. Rule 1 works well and detects the running application. Rule 2 testing was done on 2 machines.&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt;"&gt;First machine with latest patches installed and the posture status was compliant.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11pt;"&gt;Second Machine was without the latest patches (uninstalled 5 recent security patches, Control Panel/View Installed Updates).&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Issue: For the second machine, even though the patches weren’t latest, the status became back as compliant. I checked the reports on ISE and saw that ISE was passing the critical patches condition for Landesk successfully. Didn’t get any more details. How is Anyconnect checking the installation of critical patches through Landesk. Is it integrated with the Landesk Client on PC and checks with the server for comparison?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Please provide any inputs on how to mitigate this issue. Also the best way to check if latest patches are installed.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 08:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494121#M509789</guid>
      <dc:creator>srikkulk</dc:creator>
      <dc:date>2018-05-21T08:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Patch ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494122#M509791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/ac_compliance_module/Cisco_AnyConnect_ISE_Posture_Win_Support_Charts_for_Compliance_Module_4_2_1538_0.html"&gt;Cisco AnyConnect ISE Posture Windows Support Charts for Compliance Module v4.2.1538.0&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; shows that LANDESK Software, Inc.'s Security and Patch Manager 9.x required CM 4.2.1331.0 minimal and has support for&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Activate GUI Remediation&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Up-to-date Check&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Application Running Check&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Application Kill&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes, the remediation is generally done through the patch management client. Thus, please also check the logs on the LANDESK side. If you need further details, please get a copy of the DART file and submit it to Cisco TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 04:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494122#M509791</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-22T04:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Patch ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494123#M509793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I'm using CM 3.6.x which is recently updated than 4.x and support Landesk version 10. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But im still getting posture status as compliant even when patches are missing. Any idea why that is happening?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 05:32:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/3494123#M509793</guid>
      <dc:creator>srikkulk</dc:creator>
      <dc:date>2018-05-22T05:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Patch ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/4015172#M509794</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/ac_compliance_module/Cisco_AnyConnect_ISE_Posture_Win_Support_Charts_for_Compliance_Module_4_2_1538_0.html" rel="nofollow noopener noreferrer" target="_blank"&gt;Cisco AnyConnect ISE Posture Windows Support Charts for Compliance Module v4.2.1538.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link broken...too bad Cisco removes the older Compliance Module support charts from the portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 10:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/4015172#M509794</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2020-01-21T10:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Patch ISE condition</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/4693979#M577397</link>
      <description>&lt;P&gt;You can get the updated link, for the last Compliance Module, here: &lt;A href="https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/security/identity-services-engine/products-device-support-tables-list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 17:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-condition/m-p/4693979#M577397</guid>
      <dc:creator>Mauritz</dc:creator>
      <dc:date>2022-09-26T17:40:03Z</dc:date>
    </item>
  </channel>
</rss>

