03-23-2023 05:35 PM
Hello
we are about to start an ISE posture implementation and I would like to understand automatic remediation of our anti-malware.
In ISE, we just need to set the the remediation action and that is it? How will the client know how to download and install the anti-malware?
Thank you
Marcos
Solved! Go to Solution.
03-24-2023 03:18 PM
hello @mnkojima , the remediation on ISE when it comes to anti-malware can be done automatic or manual es the following image shows
The way it works , if you choose automatic this is going to be using the OPSWAT framework that the module ISE posture module uses when performing posture specifically a library named OESIS , through this framework OPSWAT is going to upgrade automatically the anti-malware , if you chose to remediate manually the user will need to know how to perform the upgrade of the anti-malware that is contained in his machine, regardless of the method that you select , during the remediation stage you need to provide to this machine access to specific servers/connections to do such upgrades that are required in order to become compliant , please refer to https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#concept_1B18C2D8101A41B7AD95EA59F4D8D8F7 where is described this .
Let me know if that helped you .
03-24-2023 03:18 PM
hello @mnkojima , the remediation on ISE when it comes to anti-malware can be done automatic or manual es the following image shows
The way it works , if you choose automatic this is going to be using the OPSWAT framework that the module ISE posture module uses when performing posture specifically a library named OESIS , through this framework OPSWAT is going to upgrade automatically the anti-malware , if you chose to remediate manually the user will need to know how to perform the upgrade of the anti-malware that is contained in his machine, regardless of the method that you select , during the remediation stage you need to provide to this machine access to specific servers/connections to do such upgrades that are required in order to become compliant , please refer to https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#concept_1B18C2D8101A41B7AD95EA59F4D8D8F7 where is described this .
Let me know if that helped you .
03-25-2023 04:39 PM
Thank you very much Rodrigo
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: