08-27-2018 10:39 AM - edited 03-11-2019 01:48 AM
We are preparing of a posture PoV. I wanted to validate that we'd be able to accomplish the following requirements.
Here are the minimum requirements for posture:
Outside vendor access – ease of connecting to network after security posturing. Agent / agentless; what does installing AnyConnect on the end device look like and how easy is it to manage. The process of a device being untrusted after posturing (put in a segregation VLAN) vs a trusted device.
Device discovery – What information is discovered about hosts on a subnet and how easy is it to create specific policy enforcement for a discovered device eg blood gas machine on the 7th floor only needs access to server XYZ
Solved! Go to Solution.
08-28-2018 03:01 AM
If you're Cisco staff you can get this sort of thing addressed more comprehensively using internal resources.
That said, everything you mentioned is in the scope of what ISE can do when combined with access devices supporting Trustsec SGTs. The SGT bit will be especially useful for item #4. The Anyconnect bit depends on the OS. AnyConnect NAM is only supported on Windows OS.
08-28-2018 03:01 AM
If you're Cisco staff you can get this sort of thing addressed more comprehensively using internal resources.
That said, everything you mentioned is in the scope of what ISE can do when combined with access devices supporting Trustsec SGTs. The SGT bit will be especially useful for item #4. The Anyconnect bit depends on the OS. AnyConnect NAM is only supported on Windows OS.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide