12-22-2012 10:28 PM - edited 03-12-2019 05:41 PM
Hi..
We are deploying ISE 1.1.1 for an enterprise customer. Having some doubts about postering. Customer wants to check windows update as part of posture check. What I understood, ise supports only wsus. There is a predefined rule pr_WSUSRule,which can't be edited and don't know how it works. customer is using SCCM to periodically deploy windows patches. Don't know whether pr_WSUSRule is applicable in this scenario. How to go ahead in our case.
Thanks and waiting for your valuable input....
12-24-2012 12:13 AM
Hi,
I have had this scenario on a few of my ISE deployments and I have made a check so that sms service on the clients are enabled on the workstations before they are granted access to the network. I also run an audit requirement for win 7 32 bit updates (for example) so their administrators can perform checks to see if the sccm patches are being recognized. If the check fails then I have the agent turn it on.
Keep in mind when you deploy ISE you have provide customers a policy and in this case we are using as an enforcement and audit tool over their current sccm architecture.
Sent from Cisco Technical Support Android App
07-10-2013 02:18 AM
Hi Tarik
can you explain how you did that ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide