03-23-2023 05:35 PM
Hello
we are about to start an ISE posture implementation and I would like to understand automatic remediation of our anti-malware.
In ISE, we just need to set the the remediation action and that is it? How will the client know how to download and install the anti-malware?
Thank you
Marcos
Solved! Go to Solution.
03-24-2023 03:18 PM
hello @mnkojima , the remediation on ISE when it comes to anti-malware can be done automatic or manual es the following image shows
The way it works , if you choose automatic this is going to be using the OPSWAT framework that the module ISE posture module uses when performing posture specifically a library named OESIS , through this framework OPSWAT is going to upgrade automatically the anti-malware , if you chose to remediate manually the user will need to know how to perform the upgrade of the anti-malware that is contained in his machine, regardless of the method that you select , during the remediation stage you need to provide to this machine access to specific servers/connections to do such upgrades that are required in order to become compliant , please refer to https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#concept_1B18C2D8101A41B7AD95EA59F4D8D8F7 where is described this .
Let me know if that helped you .
03-24-2023 03:18 PM
hello @mnkojima , the remediation on ISE when it comes to anti-malware can be done automatic or manual es the following image shows
The way it works , if you choose automatic this is going to be using the OPSWAT framework that the module ISE posture module uses when performing posture specifically a library named OESIS , through this framework OPSWAT is going to upgrade automatically the anti-malware , if you chose to remediate manually the user will need to know how to perform the upgrade of the anti-malware that is contained in his machine, regardless of the method that you select , during the remediation stage you need to provide to this machine access to specific servers/connections to do such upgrades that are required in order to become compliant , please refer to https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_compliance.html#concept_1B18C2D8101A41B7AD95EA59F4D8D8F7 where is described this .
Let me know if that helped you .
03-25-2023 04:39 PM
Thank you very much Rodrigo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide