06-03-2020 08:10 AM
Hello everyone,
Can someone shed some light in this question?
If I have a projetct that is going to have AMP for Endopoins and AnyConnect posture with ISE, should I consider using AMP Enabler Module?
Do they complement each other or they perform the same tasks?
Best Regards in advance.
Solved! Go to Solution.
06-04-2020 08:40 PM
Each of the products/technologies you mentioned has a distinct purpose and they are complimentary to each other.
Here's a breakdown:
06-03-2020 08:56 AM
06-03-2020 09:23 AM
AMP Enabler in the AnyConnect module helps you to install AMP for Endpoints. Here is an article that can provide some more detailed information.
https://www.cisco.com/c/en/us/support/docs/security/advanced-malware-protection-endpoints/200284-Installation-and-Configuration-of-AMP-Mo.html
Thanks,
Matt
06-03-2020 10:10 AM
Thanks for the documment,
So, as far as I understood, the AMP Enabler Module is just a method for deploying AMP for Endpoint, there are no differences in functionality, the only difference is the deploying method right?
If I have a project that encompasses AMP for Endpoints, AnyConnect (Just for Posture with ISE) and Umbrella, could I assume that the wisest choice of engagement in the beginning is to deploy AnyConnect with all the modules that are going to be used?
I am having these doubts, what would be the best choice of use/deployment of all these technology put together like, Cisco ISE, Cisco AMP for Endpoints, Cisco Umbrella/SIG, Cisco StealthWatch, Cisco AnyConnect (Just Posture).
Thanks in advance
06-04-2020 08:40 PM
Each of the products/technologies you mentioned has a distinct purpose and they are complimentary to each other.
Here's a breakdown:
06-09-2020 03:10 AM
If you're considering AMP and AnyConnect for Posture on the same Machine, how are you deploying the AnyConnect Agent?
If you are you are using something like SCCM, you can use this same process to deploy AMP4E also. In this case, you wouldn't need AnyConnect AMP Enabler.
The AMP Enabler for AnyConnect is a process which can be used with ISE to deploy AMP4E once the machine is in the wild and you may not have a tool like SCCM to deploy.
Simplified process:
For instance, a remote worker connects to the office via AnyConnect VPN to an ASA
When the user connects, the ASA pushes the AMP Enabler module to the End user and silently installs
The AMP Enabler module then connects to AMP4E Console and downloads the AMP Connector
AMP Connector installs and registers to the AMP Console.
06-09-2020 05:46 AM
@Darren Lynn thanks for the answer.
This thread is getting even more dense, and as the project flows, new doubts begin to surface.
In every documentation of AMP Enabler deployment that I read, I realized that everyone is commenting the use of ASA or Firepower to push the connector, however, althought almost all of my customer appliances are Cisco, their firewall is not, so the new question that arises is:
Is there an obligation to use Cisco Firewall to deploy the AMP Enabler?
Once again, thanks in advance.
06-09-2020 06:27 AM
06-09-2020 06:57 AM
I see less than 5% of my clients using AMP enabler.
Most use either SCCM, GPO software install or manual install.
06-09-2020 04:48 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: