06-23-2015 07:57 AM - edited 03-10-2019 10:50 PM
Hello Everyone
Do you guys have a document or an idea on how to begin configuring a policy to assess a host based on its membership? Basically two groups, desktops and notebooks, and both have different requirements to be considered compliant.
Machine and user authentications are working fine, and so is user-based posture. The requirements for desktop and notebooks were created already but I cannot figure out how to tie them to machine OUs. User accounts don't have any machine-related attribute.
Can posture run at the machine level?
Advices, ideas and docs are always welcome.
Running distributed ISE 1.3.
Thanks!
Guido
Solved! Go to Solution.
06-23-2015 10:13 AM
Hi again Guido, what you can do is this:
- Place all laptops in their own security group in AD
- Place all desktops in their own security group in AD
- In ISE, under Policy > Posture: You can create different rules that are matched against the specific AD group membership
As far as documentation here is an older guide written by TAC:
Also, the Cisco Press ISE book is a very good resource:
http://www.ciscopress.com/store/cisco-ise-for-byod-and-secure-unified-access-9780133103656
I hope this helps!
Thank you for rating helpful posts!
06-23-2015 10:13 AM
Hi again Guido, what you can do is this:
- Place all laptops in their own security group in AD
- Place all desktops in their own security group in AD
- In ISE, under Policy > Posture: You can create different rules that are matched against the specific AD group membership
As far as documentation here is an older guide written by TAC:
Also, the Cisco Press ISE book is a very good resource:
http://www.ciscopress.com/store/cisco-ise-for-byod-and-secure-unified-access-9780133103656
I hope this helps!
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide