10-23-2024 11:51 AM
Hi All,
I trying to determine if it's possible to take a syslog event into ISE and have a policy action taken on the event. For example, if ISE receives a threat event from a firewall would it be possible to match on that event send a CoA to shut the port or move to an isolated VLAN.
Thanks!
10-23-2024 11:58 AM
For example, if ISE receives a threat event from a firewall would it be possible to match on that event send a CoA to shut the port or move to an isolated VLAN.
its all depends what event lot, if that is part of threat mixing with other product can be possible i guess :
look at the video :
https://www.youtube.com/watch?v=wUwEuB6NlxU
Other option Never explored that , but you can use syslog and API - combination of automation code can make action to trigger (not alone ISE can do this i guess)
10-24-2024 01:38 AM
I personally only deployed the auto-remediation actions between StealthWatch (Secure Network Analytics) and ISE where a suspicious endpoint would have triggered an event and based on that event ISE would have isolated the endpoint from the network. AFAIK this is not possible with the ASAs nor the FTDs.
10-24-2024 05:21 AM
No, ISE cannot receive syslog events like this. There are various other integrations available though via pxGrid with many different products.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide