11-29-2017 11:27 AM
ISE version 2.2
Stealthwatch version 6.9
Endpoint is quarantined and hits the right policy on the ISE. Endpoint status on ISE now shows quarantine.
Endpoint is then unquarantined using Stealthwatch.
On the ISE, EP still remains with status Quarantine. We can see in the reports that ISE receives the unquarantine action from SW, but no COA happens.
On the ISE you have to manually click the Unquarantine button for the EP to be unquarantined or delete the EP and have the endpoint authenticate again.
Is this expected? I read from some discussions that ISE will not do the unquarantine automatically, does that still hold true?
Any information is appreciated.
Solved! Go to Solution.
11-30-2017 08:23 AM
This seems like a bug to me. From what i understand you can call the quarantine and unquaratine action from stealth watch without issues, added SME jeppich to keep me honest
11-30-2017 08:23 AM
This seems like a bug to me. From what i understand you can call the quarantine and unquaratine action from stealth watch without issues, added SME jeppich to keep me honest
11-30-2017 03:16 PM
Hey Malavika,
As Jason noted in his email, the endpoint should have been unquarantined in ISE as well.
Are you sending any failure messages in ISE?
Let me know your availability for next week and i will setup a webex.
Thanks,
John
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide