cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3788
Views
5
Helpful
6
Replies

ISE anyconnect posture for MACOS

Qingguo Zhang
Cisco Employee
Cisco Employee

Sorry for wide distribution.

 

My customer plan to check if MACOS main version 10.x.x is up-to-date in ISE posture policy  with anyconnect installed on client.

 

is it done by Patch Management condition in ISE ?  for examples I can see vendor is Apple and agent is software update 1.x 2.x 3.x . how is it relevant to MACOS main version?

If I using other vendor condition like JAMF ot other tool etc ,  is it possible to check if MACOS is up-to-date ?

 

Which one is mostly used to check MacOS is up-to-date ?

1 Accepted Solution

Accepted Solutions

It seems I didn't understand the initial question.  ISE posture can check to see if patch management software is installed on MAC OS X but unfortunately cannot check to see if it is up to date.  That is a Windows only feature currently.  Are you trying to determine if MAC OS is version 10.X.X instead of 10.X?  If that is the case, you can use a file check condition to check SystemVersion.plist file for the ProductVersion value.  It will tell you whether the OS version is, for example, 10.14 or 10.14.1

 

Regards,

-Tim

View solution in original post

6 Replies 6

Timothy Abbott
Cisco Employee
Cisco Employee

You can use either ISE posture or MDM to detect that information.  It really is a matter of personal preference.

 

Regards,

-Tim

Thanks Tim for your answer.

 

Just to check if ISE below posture condition is correct to detect MACOS OS info and up-to-date ?  Version 1.x 2.x 3.x is used in different MACOS ?

 

Screen Shot 2018-11-21 at 11.14.57 PM.png

 

 

Yes, each of those are for different versions of MAC OS X.  You will need to select the version appropriate for MAC OS you are using.

 

Regards,

-Tim

When I select up-to-date , all agent software update are  grey and invalid ,   the condition cannot be saved.  

 

is it not supported or some issue ?

It seems I didn't understand the initial question.  ISE posture can check to see if patch management software is installed on MAC OS X but unfortunately cannot check to see if it is up to date.  That is a Windows only feature currently.  Are you trying to determine if MAC OS is version 10.X.X instead of 10.X?  If that is the case, you can use a file check condition to check SystemVersion.plist file for the ProductVersion value.  It will tell you whether the OS version is, for example, 10.14 or 10.14.1

 

Regards,

-Tim

ISE does NOT communicate to Patch Manager directly ,  ISE believe anyconnect to get information from update client.   this is also same for AV/AS check,  is it correct ?