03-15-2013 03:49 AM - edited 03-10-2019 08:12 PM
Here is my scenario.
I have some industrial machines that doesn't support Antivirus and we even put them on the domain, because of the risk of a security breach. But at the same time those machines need to access the NAS to copy some configuration files.
My doubt is how ISE can help me put those machines on the network keeping the other vlans safe from a risk of infection or possible data loss or even inside attacks. Theres any way we can enforce security on those machines, letting them access network but not accessible from others only with ISE? And when i mean enforce im talking not only keeping the vlan unaccessible but some rules to avoid use of firewall in the middle.
We dont have ISE yet but its on the way and im trying to figure how it works.
I would be glad for some help here. Thanks
Solved! Go to Solution.
03-15-2013 05:48 AM
Kaleby,
You can segement these devices based on mac address if you like and dump them on their own vlan and also send a DACL (if wired) so they only have access to specific services. Let me know if that hits your requirement.
Thanks,
Tarik Admani
*Please rate helpful posts*
03-15-2013 05:48 AM
Kaleby,
You can segement these devices based on mac address if you like and dump them on their own vlan and also send a DACL (if wired) so they only have access to specific services. Let me know if that hits your requirement.
Thanks,
Tarik Admani
*Please rate helpful posts*
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide