cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
 
ISE 2.3 Patch 7 has been posted. This will be the last patch for the ISE 2.3 release!
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

178
Views
10
Helpful
4
Replies
Cisco Employee

Apex license requirement for TC-NAC / CTA with Stealthwatch

I'm prospecting a customer who is interested in ANC on the ISE and the Stealthwatch. Stealthwatch now brings a CTA account and the customer is also considering TC-NAC to integrate with the CTA account. So let me ask some questions.
*Are the configuration task and the license requirements as same as the document about WSA/CTA ISE integration?

https://community.cisco.com/t5/security-documents/how-to-integrate-cognitive-threat-analysis-cta-and-cisco-ise/ta-p/3639706
*What license should the customer purchase? The document says "ISE requires an APEX license for the ability to subscribe to CTA cloud” I assume they will have to purchase only one Apex license. They will buy Base and Plus license as well which means they can are eligible to use ANC. They only need TC-NAC, they won't use MDM nor Posture.
*If the assumption above is right, how many Apex license shoud they purchase? Is the L-ISE-APX-[x]Y-S1 minimum for this scenario? Or do they have to buy Apex as same amount as their Base and Plus?

2 ACCEPTED SOLUTIONS

Accepted Solutions
Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

See page 6 table 5 of the ordering guide.

An Apex license is consumed when an endpoint uses or triggers threat based information or action as part of the authorization policy

So basically if you have 100 active endpoints at any given time that are hitting a TC-NAC rule then you would need to purchase same around


https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf
Highlighted
Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

Hi Tatsuya,

 

Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.

 

Hope this helps.

-Hari

4 REPLIES 4
Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

See page 6 table 5 of the ordering guide.

An Apex license is consumed when an endpoint uses or triggers threat based information or action as part of the authorization policy

So basically if you have 100 active endpoints at any given time that are hitting a TC-NAC rule then you would need to purchase same around


https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf
Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

Thanks Jason,

How about just subscribing CTA feed via STIX/TAXII case? No quarantine rules needed. 

Highlighted
Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

Hi Tatsuya,

 

Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.

 

Hope this helps.

-Hari

Cisco Employee

Re: Apex license requirement for TC-NAC / CTA with Stealthwatch

Thanks Hari,
So the minimum order-able amout of license is 100, they need to purchase the L-ISE-APX-[x]Y-S1 right(if they don't need to use it in the authorization policies)?