We are using Cisco ISE for device profiling (corporate machines, printers, phones, video conferencing units). I would like to know if there is a mechanism for ISE to generate and send an alert if a device is moved to Quarantine?
Go to Solution.
A new feature in ISE 3.1 allows you to create alarms when a particular Authorization Profile is applied to a session. See the Release Notes for more information.
With ISE versions prior to 3.1, you would need to leverage an external syslog/SIEM solution (like Splunk) that could generate an alarm based on values in the Authentication syslog events.
View solution in original post
Thanks Greg. This helps
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: