02-20-2024 07:19 AM - edited 03-04-2024 12:40 AM
Edit: Thanks for the guiding questions; I realized that I should have provided more context.
I am working at a cybersecurity company, and we want to integrate our product with Cisco ISE using the APIs so we can quarantine endpoints that we determine to be suspicious. Our company as of now doesn’t use Cisco ISE, but many of our customers do.
====================================================================
Original Post
New to ISE here and I currently have 3.2 (no patches applied yet). I was reading through some of these posts (https://community.cisco.com/t5/network-access-control/how-to-block-a-endpoint-pc-in-cisco-ise-system/td-p/2449185 and https://community.cisco.com/t5/network-access-control/ise-1-2-disable-endpoints-with-certain-mac-address/td-p/2520093), and still haven’t exactly figured out the best way to block an endpoint. Have things changed in the 3.2 release?
So far, I have explored several possibilities.
Questions
These are a lot of questions, and thanks so much for offering support!
02-21-2024 06:41 AM
Moved your post to Network Access Control, as its an ISE question, not a Cisco Secure Endpoint question.
02-21-2024 06:48 AM
Please apply the latest 3.2 patch. What exactly do you mean by "block"? Deny network access completely? Apply a dACL? Change the VLAN? Something else? During first authentication or after a successful authentication?
02-22-2024 05:09 AM
Thanks for your response. I just applied 3.2 patch 5, and I am very much a newbie here.
What are the pros and cons of each of those methods? Don’t they roughly do the same thing? For instance, can’t we deny network access by applying a dACL with a deny policy or putting the device in a quarantine VLAN? What licenses do they require? Which ones are easiest with the Cisco API?
02-22-2024 05:18 AM
02-22-2024 07:19 AM - edited 02-22-2024 07:21 AM
I don't have a Cisco Account SE or a Cisco Partner. We want to use the API so we can block malicious devices immediately based on our own algorithms, we haven't been using ISE, and are currently using evaluation mode. What is the best way of getting my questions answered? Thanks!
02-22-2024 07:30 AM
03-04-2024 12:38 AM
Thanks for the guiding questions; I realized that I should have provided more context.
I am working at a cybersecurity company, and we want to integrate our product with Cisco ISE using the APIs so we can quarantine endpoints that we determine to be suspicious. Our company as of now doesn’t use Cisco ISE, but many of our customers do.
Thanks for sharing the link to the API. I still have questions about the higher-level pros/cons as well as the differences between the various ways of blocking an endpoint (ex: complete block, dACL, VLAN, authentication, ANC quarantine, etc.) In addition, I’m not sure exactly how to block an endpoint on the GUI through some of the ways (ex: blocking via identity groups).
03-04-2024 07:59 AM
The right thing for us to do is get you in touch with the proper team at Cisco for inter-product connectivity.
I’ll send you a DM, and get you in touch with the right person.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide