07-10-2018 04:20 AM
Hi,
I am working on demo for ISE/firepower integration through PxGrid. Rely to firepower correlation function, when firepower detected a predefined intrusion event, then told ISE to quarantine the endpoint. I can create another correlation policy on firepower to tell ISE unquarantine the endpoint.
My question is that is it possible to unquarantine this endpoint on ISE manually?
Solved! Go to Solution.
07-10-2018 06:40 AM
Yes, you can go to Operations > Adaptive Network Control > Endpoint Assignment. There may or may not be MAC addresses in this list. Click the EPS unquarantine button and enter the MAC Address of the quarantined endpoint and click the Unquarantine button.
This will manually unquarantine the endpoint.
07-10-2018 06:40 AM
Yes, you can go to Operations > Adaptive Network Control > Endpoint Assignment. There may or may not be MAC addresses in this list. Click the EPS unquarantine button and enter the MAC Address of the quarantined endpoint and click the Unquarantine button.
This will manually unquarantine the endpoint.
07-10-2018 10:18 AM
Please see the discussion on a similar topic
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide