cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1727
Views
2
Helpful
4
Replies

Manual posture remediation in ISE

mnkojima
Level 1
Level 1

Hello

in Cisco ISE 3.1, I see that there is no automatic remediation for the anti-malware solution I have. Therefore, manual remediation should be configured. 

In that case, what could I configure in ISE to present the user a way to remediate an outdated anti-malware?

Thank you

Marcos

1 Accepted Solution

Accepted Solutions

Rodrigo Diaz
Cisco Employee
Cisco Employee

Hello Marcos , what you need to do is to configure the remediation for anti-malware you are talking to be applied manually as the following example suggests : 

RodrigoDiaz_0-1680055537416.png

Then you need to configure a requirement in the menu Work Centers> Posture > Policy Elements > Requirements from there you  need to configure an anti-malware action for the condition you created to detect that the anti-malware is outdated, click in edit for any requirement and then "insert new requirement" and in remediation action select the example I posted above , for this scenario you configure to show a message to the user no compliant 

RodrigoDiaz_1-1680056170035.png

Lastly you will need to enforce this requirement within a posture policy as the next example shows from Work Centers> Posture> Posture Policy 

RodrigoDiaz_2-1680056398910.png

Please notice here that the remediation configured will trigger in case the user does not met the condition configured for anti-malware , hence the status of the machine will be non- compliant, you need to adjust the non-compliant status to grant the machine the access it requires to become compliant depending upon the anti-malware you are talking , also during the configuration for the remediation message you can customize and instruct the end user in how to update by himself the anti-malware to become compliant , in any case you can find more insight in this guide https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273 . 

Rate and comment if this helped you . 

 

View solution in original post

4 Replies 4

Rodrigo Diaz
Cisco Employee
Cisco Employee

Hello Marcos , what you need to do is to configure the remediation for anti-malware you are talking to be applied manually as the following example suggests : 

RodrigoDiaz_0-1680055537416.png

Then you need to configure a requirement in the menu Work Centers> Posture > Policy Elements > Requirements from there you  need to configure an anti-malware action for the condition you created to detect that the anti-malware is outdated, click in edit for any requirement and then "insert new requirement" and in remediation action select the example I posted above , for this scenario you configure to show a message to the user no compliant 

RodrigoDiaz_1-1680056170035.png

Lastly you will need to enforce this requirement within a posture policy as the next example shows from Work Centers> Posture> Posture Policy 

RodrigoDiaz_2-1680056398910.png

Please notice here that the remediation configured will trigger in case the user does not met the condition configured for anti-malware , hence the status of the machine will be non- compliant, you need to adjust the non-compliant status to grant the machine the access it requires to become compliant depending upon the anti-malware you are talking , also during the configuration for the remediation message you can customize and instruct the end user in how to update by himself the anti-malware to become compliant , in any case you can find more insight in this guide https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273 . 

Rate and comment if this helped you . 

 

Thank you Rodrigo for your reply.

So, I understand that since the endpoint will need a manual remediation, the end users will need to remediate the laptop by themselves (let's say that it is an outdated antivirus).  In that case, the end users do not have admin rights to their laptops and they will have to open a ticket to service desk to update their antivirus. Am I correct?

 

That would depend mostly on the application that is out of date, as per my understanding some of the anti-malware or anti virus upgrade procedures don't need admin privileges to run , in your scenario I would test it out first in lab environment with some users to double confirm about what they need to become compliant . 

Let me know if that helped you .

Hi Rodrigo,

I'm curious about which method of remediation action will force the client to update the anti-virus,
1. going online to download the patch from internet.
2. reading configuration from anti-virus program that installed and patching through internal server.