This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
I'm prospecting a customer who is interested in ANC on the ISE and the Stealthwatch. Stealthwatch now brings a CTA account and the customer is also considering TC-NAC to integrate with the CTA account. So let me ask some questions.
*Are the configuration task and the license requirements as same as the document about WSA/CTA ISE integration?
https://community.cisco.com/t5/security-documents/how-to-integrate-cognitive-threat-analysis-cta-and-cisco-ise/ta-p/3639706
*What license should the customer purchase? The document says "ISE requires an APEX license for the ability to subscribe to CTA cloud” I assume they will have to purchase only one Apex license. They will buy Base and Plus license as well which means they can are eligible to use ANC. They only need TC-NAC, they won't use MDM nor Posture.
*If the assumption above is right, how many Apex license shoud they purchase? Is the L-ISE-APX-[x]Y-S1 minimum for this scenario? Or do they have to buy Apex as same amount as their Base and Plus?
Solved! Go to Solution.
Hi Tatsuya,
Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.
Hope this helps.
-Hari
Thanks Jason,
How about just subscribing CTA feed via STIX/TAXII case? No quarantine rules needed.
Hi Tatsuya,
Your customer will need at least one Apex license to enable TC NAC service and connect to the CTA feed. As Jason mentioned, additional Apex licenses will be consumed when the CTA attributes are used in the authorization policies.
Hope this helps.
-Hari