03-25-2015 04:21 AM - edited 03-10-2019 10:35 PM
Hi All,
I have configured ISE (1.2) to check Antivirus Installation on endpoints and it is working flawlessly.
Now, the client wants,
1) If Antivirus is not updated on endpoint for more than 5 days; it should be considered as "non-compliant" and as a remediation action; updates should be downloaded automatically.
--> I configured AV Remediation action.
Now, the problem is when endpoint gets categorized as non-compliant, ideally AV updates should get downloaded on endpoint as a remediation action. But AV updates are not getting downloaded.
Please help me in solving this problem..
Thanks in advance,
Aditya
03-27-2015 02:19 AM
You can create an antivirus remediation, which updates clients with up-to-date file definitions for compliance after remediation.
The AV Remediations page displays all the antivirus remediations along with their name and description and their modes of remediation.
Step 1 Choose Policy > Policy Elements > Results > Posture.
Step 2 Click Remediation Actions.
Step 5 Modify the values in the New AV Remediation page.
The following table describes the fields in the AV Remediation page. The navigation path is Policy > Policy Elements > Results > Posture > Remediation Actions > AV Remediation.
04-01-2015 12:44 AM
Hi mohanak,
Thank you for reply.
I configured the remediation action in ISE.
When the endpoint is categorized as non-complaint; as a remediation action antivirus should be automatically updated (updates should be fetched from internet automatically)
But at present antivirus is not getting updated, and as soon as remediation timer expires, endpoint's network access gets blocked and it remains in non-compliant state.
Do we need to open any specific ip/url (eg.http://symantic.com/update) in the ACL on wlc in order to allow updates from internet ?
Regards,
Aditya
06-23-2015 04:58 PM
Yes. You should put on your remediation ACL the IP/Port of antivirus server.
It will allow the antivirus client to access and to download the update.
Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide