<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Posture is a service in Cisco in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599574#M75907</link>
    <description>&lt;P&gt;Posture is a service in Cisco Identity Services Engine (Cisco ISE) that allows you to check the state, also known as posture, of all the endpoints that are connecting to a network for compliance with corporate security policies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010111.html&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2014 14:02:55 GMT</pubDate>
    <dc:creator>Venkatesh Attuluri</dc:creator>
    <dc:date>2014-12-19T14:02:55Z</dc:date>
    <item>
      <title>Controlling Network Access</title>
      <link>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599572#M75898</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The basic idea of what I am wanting to do is control access to networks based on computers having up to date Antivirus installed on a computer.&amp;nbsp; If the computer does not, it is denied access or put off for remediation.&amp;nbsp; I am in a Windows AD environment with two RADIUS servers at a central location.&amp;nbsp; Each one of my remote sites has a Cisco 2901,2911, or a 2951 with the ipbase, securityk9, datak9, and uck9 licensed router as the edge device.&amp;nbsp; I would like to somehow use the Cisco routers to use NAC to evaluate the computers and make the decision for network access.&amp;nbsp; I only use 1 brand of AV software so the setup should hopefully be simple.&amp;nbsp; Can someone give me some pointers on the best way to do this using NAC, RADIUS, NPS, or some combination to do this.&amp;nbsp; I am not opposed to buying a Cisco device to put at my headquarters for this function.&amp;nbsp; I would really like to not buy a device for all of my locations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599572#M75898</guid>
      <dc:creator>David Lee</dc:creator>
      <dc:date>2019-03-11T05:12:47Z</dc:date>
    </item>
    <item>
      <title>Hi David, it sounds like you</title>
      <link>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599573#M75903</link>
      <description>&lt;P&gt;Hi David, it sounds like you are trying to perform "Posture Assessment" The legacy Cisco product that can do this is Cisco NAC. The newer and definitely recommended solution/product would be Cisco ISE. With ISE you can accomplish everything that you have listed above. You need to make sure that you are running on supported hardware/software:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/compatibility/ise_sdt.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/compatibility/ise_sdt.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The most important feature that you will need is CoA (Change of Authorization). This feature will allow you to place the ISE nodes centrally and not having to run them inline.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more information on ISE check out its main page and/or contact your local Cisco partner:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html"&gt;http://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 04:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599573#M75903</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-25T04:01:12Z</dc:date>
    </item>
    <item>
      <title>Posture is a service in Cisco</title>
      <link>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599574#M75907</link>
      <description>&lt;P&gt;Posture is a service in Cisco Identity Services Engine (Cisco ISE) that allows you to check the state, also known as posture, of all the endpoints that are connecting to a network for compliance with corporate security policies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010111.html&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 14:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/controlling-network-access/m-p/2599574#M75907</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2014-12-19T14:02:55Z</dc:date>
    </item>
  </channel>
</rss>

