cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
806
Views
0
Helpful
2
Replies

ISE v2.4 - Posture policy query

jbnair
Level 1
Level 1

Hi

Good day!

I am setting up a new ISE posture policy and the following conditions must be met.

 

1. If Windows updates are non-compliant, need a grace period of 3 weeks.

2. If AV services are not running, network access must be blocked immediately.

 

Can we run both of the above policies together in one posture policy?

 

BR

Jay

1 Accepted Solution

Accepted Solutions

Hi,

1.If Windows updates are non-compliant, need a grace period of 3 weeks.- Grace period is available for whole compliance status(for all checks), if the machine was complaint in previous posture check.

 Cache Last Known Posture Compliant Status
 
Hours

 

Instead of this, you can create a PRA condition with grace period of maximum 60 mins & call this patch condition as PRA : reassessment

2. If AV services are not running, network access must be blocked immediately.-Yes it is possible, you can create this as separate policy & call the PRA as initial.

 

Both the policies should be different.

 

For more info on Posture reassessment please check here

 

-Aravind

-Aravind

View solution in original post

2 Replies 2

Hi,

1.If Windows updates are non-compliant, need a grace period of 3 weeks.- Grace period is available for whole compliance status(for all checks), if the machine was complaint in previous posture check.

 Cache Last Known Posture Compliant Status
 
Hours

 

Instead of this, you can create a PRA condition with grace period of maximum 60 mins & call this patch condition as PRA : reassessment

2. If AV services are not running, network access must be blocked immediately.-Yes it is possible, you can create this as separate policy & call the PRA as initial.

 

Both the policies should be different.

 

For more info on Posture reassessment please check here

 

-Aravind

-Aravind

Thanks Aravind. I will be working as per this plan further and update.

 

BR

Jay

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: