cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
720
Views
0
Helpful
1
Replies

Cisco ISE Posture

bwongtho
Cisco Employee
Cisco Employee

We are preparing of a posture PoV.  I wanted to validate that we'd be able to accomplish the following requirements.

 

Here are the minimum requirements for posture:

 

  1. Solution must be capable of device fingerprinting, looking at a combination of MAC, running services, and network behavior.
  2. Solution must track the device, ensuring it stays on the VLAN it was placed on.
  3. If the device is owned by our enterprise, the solution should verify that the normal support solutions (LandDesk, Trend) are in place and running
  4. Granular access to IoT devices (apple tv, chromecast or sonos) on large single broadcast subnets eg we have a sonos speaker in a /22 space, how can we make the device visible to IP addresses / hosts X,Y, Z only.
  5. Outside vendor access – ease of connecting to network after security posturing.  Agent / agentless; what does installing AnyConnect on the end device look like and how easy is it to manage. The process of a device being untrusted after posturing (put in a segregation VLAN) vs a trusted device.

  6. Device discovery – What information is discovered about hosts on a subnet and how easy is it to create specific policy enforcement for a discovered device eg blood gas machine on the 7th floor only needs access to server XYZ

     

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

If you're Cisco staff you can get this sort of thing addressed more comprehensively using internal resources.

 

That said, everything you mentioned is in the scope of what ISE can do when combined with access devices supporting Trustsec SGTs. The SGT bit will be especially useful for item #4. The Anyconnect bit depends on the OS. AnyConnect NAM is only supported on Windows OS.

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

If you're Cisco staff you can get this sort of thing addressed more comprehensively using internal resources.

 

That said, everything you mentioned is in the scope of what ISE can do when combined with access devices supporting Trustsec SGTs. The SGT bit will be especially useful for item #4. The Anyconnect bit depends on the OS. AnyConnect NAM is only supported on Windows OS.