07-18-2017 04:44 AM
Hi Team,
We are in the process of deploying the ISE at customer site and need few pointers and help on below requirements:
Appreciate any quick help on this.
Thanks & Regards,
Yogesh Madhekar
Solved! Go to Solution.
07-18-2017 07:28 AM
1. Depends on environment. If you have wsus then consider using it.
2. Changing VLANs is not the preferred method for isolating users based on posture. Consider dacls first.
3. The available guide should serve as a great starting point. Not much has changed in the configuration of posture between ISE 2.1 and 2.2. The presentation says it's from 2.1.
George
Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.
07-18-2017 07:28 AM
1. Depends on environment. If you have wsus then consider using it.
2. Changing VLANs is not the preferred method for isolating users based on posture. Consider dacls first.
3. The available guide should serve as a great starting point. Not much has changed in the configuration of posture between ISE 2.1 and 2.2. The presentation says it's from 2.1.
George
Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.
07-18-2017 11:30 AM
Just to add to George's response:
1) You can use systems manager of any sort to deploy AnyConnect and the profiles for posture or other modules. For devices that are unmanaged (like BYOD assets) ISE authorization policy can be defined to provision the agent through ISE on-boarding flow.
2) Yes changing the VLANs is a bad idea, dACLs keeps it seamless. However, with posture, you have one of the 3 compliance states: Compliant, Non-complaint and Uknown. So if either AV or DLP is missing, then the endpoint would still be deemed non-compliant, you can't have a partially complaint status for posture.
3) Yes, there isn't much change for 2.x for WSUS. Also MS has moved from from WSUS to SCCM now.
Cheers!
-Hari
07-19-2017 01:45 AM
Hi Hari,
Thanks for the quick response.
Can you please provide details of how Dacl's will be useful for the compliant state based on different checks?
Also do we have any document giving best practices for implementing ISE in enterprises that can be shared with the customer?
Thanks in advance for any help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide