02-06-2025 04:16 AM
how to integrate cisco ISE with BigFix Patch management server.
the goal is when a windows endpoint connects to ISE, ISE shd check bigfix patch server whether the endpoint is latest updated.
If updated ISE posture permits the endpoint to network.
02-06-2025 09:20 AM
I don't believe what you are looking for is supported. I think ISE External DataSource condition would only work with AD with some specific attributes as per the following link. However, why not to do the check directly on the endpoints rather than on the BigFix server?
02-06-2025 09:24 PM - edited 02-06-2025 09:24 PM
How to check whether specific KB are installed in endpoints? other than PS scripts?
02-10-2025 02:09 AM - edited 02-10-2025 02:10 AM
If you change the vendor name to Microsoft in the "Patch Management" screenshot you shared you would then be able to set up Windows updates checks. The condition you shared in the screenshot is more related to BigFix client itself, not to Windows updates. The Check type is the definition of what check you want to do for that condition, for instance if you do "Installation" the check will look at if the client is installed, "Enabled" would check if the software you are checking is not disabled on the client, and "Up to Date" will look at the latest version of the client based on the gathered details by ISE of that software. I think the check types might change based on the condition you create.
Regarding the "Check Patches Installed", that is the severity level you want to check for those patches. By selecting "Improtant & Critical" you are saying I only care about looking if the important and critical patches are installed which is the common way to do it.
02-06-2025 09:57 PM - edited 02-06-2025 09:58 PM
a screenshot attached. What does this patch management condition do?
02-06-2025 11:34 PM
@manvik that patch management condition checks to see if the BigFix Client version 10.x or 11.x is installed, up to date and checks to see if Important & Critical patches are installed.
02-07-2025 02:34 AM
what is that "Check Type" and "Check Patches installed"?
Is it windows patches? what is happening while checking those.
02-18-2025 01:51 AM
what is " Important & Critical patches are installed" mean. Is it looking for window patch
02-19-2025 02:14 AM
If that is part of Microsoft as a vendor and Windows OS then yes. However, if the vendor is something else with a specific software then that will be related to that software of that vendor.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide