cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2120
Views
0
Helpful
4
Replies

Installing AV on the ISE appliance/VM itself.

wenoonan
Cisco Employee
Cisco Employee

I have a customer that needs to document for compliance, any systems which cannot have AV installed. I'm 99% sure that it is not possible to install 3rd party AV software on an ISE VM or appliance. Does anyone know of any documentation, etc. that affirms this one way or the other? Thanks!

1 Accepted Solution

Accepted Solutions

jj27
Spotlight
Spotlight

This document is a little dated, but it states "Customers do not have direct access to the OS" which would include the ability to install any 3rd party software such as AV.

 

https://community.cisco.com/t5/security-documents/ise-security-best-practices-hardening/ta-p/3640651#toc-hId-1865503479

View solution in original post

4 Replies 4

jj27
Spotlight
Spotlight

This document is a little dated, but it states "Customers do not have direct access to the OS" which would include the ability to install any 3rd party software such as AV.

 

https://community.cisco.com/t5/security-documents/ise-security-best-practices-hardening/ta-p/3640651#toc-hId-1865503479

wenoonan
Cisco Employee
Cisco Employee

Thanks. I think that will do it. Passed it along to my customer, thanks again!

Anurag Sharma
Cisco Employee
Cisco Employee

Hi @wenoonan ,

 

Why do you want to install AV on ISE anyway? 

ISE cannot act as a 'remediation' server.

If you are thinking of making ISE check whether AV is installed or not, please use Posture condition for AV. Work Centers -> Posture -> Policy Elements -> Conditions -> Anti-virus

FYI, Posture requires Apex license and a whole lot of configuration to get it working properly :)

 

Hope that helps!
Please 'RATE' and 'MARK ACCEPTED', if applicable.

Installing AV on the ISE appliance as an AV client, not a server. Same reason you install AMP on your endpoints. To protect the endpoint. In this case the customer has a [antiquated] requirement to run AV software on all operating systems. The sole exception requires a document from the vendor stating to the effect of "you can't install 3rd party software, including AV software, on the appliance". Hopefully that clarifies the request. Thanks!