cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
751
Views
20
Helpful
8
Replies

API call for the EPS unquarantine function?

Chess Norris
Level 4
Level 4

Hi,

 

We are using the EPS unquarantine function in ISE 2.4, but it's a manual process where we have to copy/paste the MAC address of the client we want to unquarantine. Is it possible to do unquarantine through an API call instead? If so, are there any documentation that describe this?

 

Thanks

/Jorgen

3 Accepted Solutions

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee
You can use the following APIs :

https://[ISE IP]/admin/API/eps/UnQuarantineByMAC/<endpoint MAC>
https://[ISE IP]/admin/API/eps/UnQuarantineByIP/<endpoint IP>

If you would like to quarantine, you can use the below :

https://[ISE IP]/admin/API/eps/QuarantineByIP/<endpoint IP>
https://[ISE IP]/admin/API/eps/QuarantineByMAC/<endpoint MAC>

They are not documented anywhere because EPS is legacy and i think is used by a very few customers.

View solution in original post

Please request through firepower team

I will check internally

View solution in original post

Hi Jorgen,

 

Firepower 6.1 and above uses pxGrid for ANC 1.0 mitigation actions subscribing to the EndpointProtection Topic, and uses the Session:ESTATUS:Quarantine ISE authz.policy. (legacy EPS)

 

For ANC 2.0 mitigation actions, Firepower would need to subscribe to the AdaptiveNetworkControl Topic, and use the true ANC policies: port_bounce, quarantine, shut_down and associated actions.

 

Do you have customers asking for this? If so, can you unicast me their names.  We would have to route them over the Firepower PM.  As Jason indicates, we will check and get back with you if it's something that we can share.

 

Thanks,

John

jeppich@cisco.com 

View solution in original post

8 Replies 8

Surendra
Cisco Employee
Cisco Employee
You can use the following APIs :

https://[ISE IP]/admin/API/eps/UnQuarantineByMAC/<endpoint MAC>
https://[ISE IP]/admin/API/eps/UnQuarantineByIP/<endpoint IP>

If you would like to quarantine, you can use the below :

https://[ISE IP]/admin/API/eps/QuarantineByIP/<endpoint IP>
https://[ISE IP]/admin/API/eps/QuarantineByMAC/<endpoint MAC>

They are not documented anywhere because EPS is legacy and i think is used by a very few customers.

Thank you for the quick reply,

My understanding  is that Firepower - in it's current version - is not able to use the newer ANC method to do quarantine/unquarantine and we are stuck with using legacy EPS for that. Do you have any insight when or if Firepower will ever support ANC.

 

Thanks

/Jorgen

Please request through firepower team

I will check internally

Hi Jorgen,

 

Firepower 6.1 and above uses pxGrid for ANC 1.0 mitigation actions subscribing to the EndpointProtection Topic, and uses the Session:ESTATUS:Quarantine ISE authz.policy. (legacy EPS)

 

For ANC 2.0 mitigation actions, Firepower would need to subscribe to the AdaptiveNetworkControl Topic, and use the true ANC policies: port_bounce, quarantine, shut_down and associated actions.

 

Do you have customers asking for this? If so, can you unicast me their names.  We would have to route them over the Firepower PM.  As Jason indicates, we will check and get back with you if it's something that we can share.

 

Thanks,

John

jeppich@cisco.com 

Hi John,

 

I sent you an email earlier today with information about the customer. (let me know if you didn't received it).

 

The customer have about 30 000 endpoints and before they go live with Rapid Threat Containment, the customer require a function to unquarantine multiple endpoints. The customer is worried about false positives from Firepower that could potentially put thousands of endpoints in quarantine.

That's why they feel it's very importand to have a fail safe/emergency function that could achieve this. I imagine it would be a lot easier to accomplish this with ANC 2,0 where we would actually see a list of MAC addresses being quarantine and have an option to select all and unqurantine them.   

 

Best regards

/Jorgen 

 

jofr@conscia.com

Hi John,

 

I sent you an email earlier today with information about the customer. (let me know if you didn't received it).

 

The customer have about 30 000 endpoints and before they go live with Rapid Threat Containment, the customer require a function to unquarantine multiple endpoints. The customer is worried about false positives from Firepower that could potentially put thousands of endpoints in quarantine.

That's why they feel it's very importand to have a fail safe/emergency function that could achieve this. I imagine it would be a lot easier to accomplish this with ANC 2,0 where we would actually see a list of MAC addresses being quarantine and have an option to select all and unqurantine them.   

 

Best regards

/Jorgen 

 

jofr@conscia.com

John,

 

I sent you an email earlier today with information about the customer. (let me know if you didn't received it).

 

The customer have about 30 000 endpoints and before they go live with Rapid Threat Containment, the customer require a function to unquarantine multiple endpoints. The customer is worried about false positives from Firepower that could potentially put thousands of endpoints in quarantine.

That's why they feel it's very importand to have a fail safe/emergency function that could achieve this. I imagine it would be a lot easier to accomplish this with ANC 2,0 where we would actually see a list of MAC addresses being quarantine and have an option to select all and unqurantine them.   

 

Best regards

/Jorgen 

 

 

Jorgen Frejso

Senior Network Engineer

Conscia Netsafe

Phone: +46-8-765 53 00

Mobile: +46-72-532 05 29

Email: jofr@conscia.com

Just for closure on this thread, I am corresponding with Jorgen directly.

 

Thanks,

John

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: