01-17-2021 01:35 AM
Hi,
The cisco ISE 2.7 is integrated to amp for endpoints. I would like to block endpoints that are compromised. I can see compromised endpoints in ISE with severity level as painful. Is there anyway to block these endpoints in ISE?
Thanks,
Solved! Go to Solution.
01-18-2021 05:10 AM
Yes. The feature is known as Threat-Centric NAC or TC-NAC. It requires Apex licensing but is otherwise relatively easy to setup. Please see the following section of the admin guide:
There are some other resources in the following as well:
https://www.youtube.com/watch?v=VhfAM7KXOl0
01-18-2021 06:03 AM
If you combine Rapid Threat Containment (RTC) with Adaptive Network Control (ANC) it can automatically quarantine the endpoint in ISE upon receipt of an AMP event.
Here's an example:
01-18-2021 12:54 AM
Is there anyway to do automatic quarantine rather than manual in cisco ISE?
Thanks,
01-18-2021 05:10 AM
Yes. The feature is known as Threat-Centric NAC or TC-NAC. It requires Apex licensing but is otherwise relatively easy to setup. Please see the following section of the admin guide:
There are some other resources in the following as well:
https://www.youtube.com/watch?v=VhfAM7KXOl0
01-18-2021 05:32 AM
Thanks for your resources. It does not quarantine any compromised endpoint automatically. It needs to be done manually. Is there anyway to do automatic quarantine with ISE policy?
01-18-2021 06:03 AM
If you combine Rapid Threat Containment (RTC) with Adaptive Network Control (ANC) it can automatically quarantine the endpoint in ISE upon receipt of an AMP event.
Here's an example:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide