cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1399
Views
10
Helpful
4
Replies

Apex license requirement for TC-NAC / CTA with Stealthwatch

taasai
Cisco Employee
Cisco Employee

I'm prospecting a customer who is interested in ANC on the ISE and the Stealthwatch. Stealthwatch now brings a CTA account and the customer is also considering TC-NAC to integrate with the CTA account. So let me ask some questions.
*Are the configuration task and the license requirements as same as the document about WSA/CTA ISE integration?

https://community.cisco.com/t5/security-documents/how-to-integrate-cognitive-threat-analysis-cta-and-cisco-ise/ta-p/3639706
*What license should the customer purchase? The document says "ISE requires an APEX license for the ability to subscribe to CTA cloud” I assume they will have to purchase only one Apex license. They will buy Base and Plus license as well which means they can are eligible to use ANC. They only need TC-NAC, they won't use MDM nor Posture.
*If the assumption above is right, how many Apex license shoud they purchase? Is the L-ISE-APX-[x]Y-S1 minimum for this scenario? Or do they have to buy Apex as same amount as their Base and Plus?

2 Accepted Solutions

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee
See page 6 table 5 of the ordering guide.

An Apex license is consumed when an endpoint uses or triggers threat based information or action as part of the authorization policy

So basically if you have 100 active endpoints at any given time that are hitting a TC-NAC rule then you would need to purchase same around


https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf

View solution in original post

Hi Tatsuya,

 

Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.

 

Hope this helps.

-Hari

View solution in original post

4 Replies 4

Jason Kunst
Cisco Employee
Cisco Employee
See page 6 table 5 of the ordering guide.

An Apex license is consumed when an endpoint uses or triggers threat based information or action as part of the authorization policy

So basically if you have 100 active endpoints at any given time that are hitting a TC-NAC rule then you would need to purchase same around


https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/guide_c07-656177.pdf

Thanks Jason,

How about just subscribing CTA feed via STIX/TAXII case? No quarantine rules needed. 

Hi Tatsuya,

 

Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.

 

Hope this helps.

-Hari

Thanks Hari,
So the minimum order-able amout of license is 100, they need to purchase the L-ISE-APX-[x]Y-S1 right(if they don't need to use it in the authorization policies)?