10-09-2018 03:08 PM
I'm prospecting a customer who is interested in ANC on the ISE and the Stealthwatch. Stealthwatch now brings a CTA account and the customer is also considering TC-NAC to integrate with the CTA account. So let me ask some questions.
*Are the configuration task and the license requirements as same as the document about WSA/CTA ISE integration?
https://community.cisco.com/t5/security-documents/how-to-integrate-cognitive-threat-analysis-cta-and-cisco-ise/ta-p/3639706
*What license should the customer purchase? The document says "ISE requires an APEX license for the ability to subscribe to CTA cloud” I assume they will have to purchase only one Apex license. They will buy Base and Plus license as well which means they can are eligible to use ANC. They only need TC-NAC, they won't use MDM nor Posture.
*If the assumption above is right, how many Apex license shoud they purchase? Is the L-ISE-APX-[x]Y-S1 minimum for this scenario? Or do they have to buy Apex as same amount as their Base and Plus?
Solved! Go to Solution.
10-09-2018 03:43 PM
10-09-2018 07:27 PM
Hi Tatsuya,
Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.
Hope this helps.
-Hari
10-09-2018 03:43 PM
10-09-2018 05:26 PM
Thanks Jason,
How about just subscribing CTA feed via STIX/TAXII case? No quarantine rules needed.
10-09-2018 07:27 PM
Hi Tatsuya,
Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.
Hope this helps.
-Hari
10-11-2018 03:00 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide