cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
371
Views
0
Helpful
2
Replies

Anomalous Behaviour and Dual Boot machines

Hi there,

 

 

I would like to use the Anomalous Behaviour with automatic enforcement, but would like to allow changes from Windows to Linux and Linux to Windows. 

From the documentation it seems that this change will trigger "anomalous behaviour".

Is there a way to circumvent this issue (ex: only use main classes like Workstation to Printer, and allow changes inside the same class)?

 

Thanks

 

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

It will depend on whether the Linux will send DHCP Vendor Class ID. AFAIK, most Linux doesn't send Vendor Class ID so the endpoint will be profiled as WIndows and not trigger the ABD.

View solution in original post

2 Replies 2

anthonylofreso
Level 4
Level 4

Hmm, I am also curious about this. I've seen very little documentation regarding Anomalous Behavior and the ability to write good policy.

howon
Cisco Employee
Cisco Employee

It will depend on whether the Linux will send DHCP Vendor Class ID. AFAIK, most Linux doesn't send Vendor Class ID so the endpoint will be profiled as WIndows and not trigger the ABD.