03-28-2023 04:50 PM
Hello
in Cisco ISE 3.1, I see that there is no automatic remediation for the anti-malware solution I have. Therefore, manual remediation should be configured.
In that case, what could I configure in ISE to present the user a way to remediate an outdated anti-malware?
Thank you
Marcos
Solved! Go to Solution.
03-28-2023 07:32 PM
Hello Marcos , what you need to do is to configure the remediation for anti-malware you are talking to be applied manually as the following example suggests :
Then you need to configure a requirement in the menu Work Centers> Posture > Policy Elements > Requirements from there you need to configure an anti-malware action for the condition you created to detect that the anti-malware is outdated, click in edit for any requirement and then "insert new requirement" and in remediation action select the example I posted above , for this scenario you configure to show a message to the user no compliant
Lastly you will need to enforce this requirement within a posture policy as the next example shows from Work Centers> Posture> Posture Policy
Please notice here that the remediation configured will trigger in case the user does not met the condition configured for anti-malware , hence the status of the machine will be non- compliant, you need to adjust the non-compliant status to grant the machine the access it requires to become compliant depending upon the anti-malware you are talking , also during the configuration for the remediation message you can customize and instruct the end user in how to update by himself the anti-malware to become compliant , in any case you can find more insight in this guide https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273 .
Rate and comment if this helped you .
03-28-2023 07:32 PM
Hello Marcos , what you need to do is to configure the remediation for anti-malware you are talking to be applied manually as the following example suggests :
Then you need to configure a requirement in the menu Work Centers> Posture > Policy Elements > Requirements from there you need to configure an anti-malware action for the condition you created to detect that the anti-malware is outdated, click in edit for any requirement and then "insert new requirement" and in remediation action select the example I posted above , for this scenario you configure to show a message to the user no compliant
Lastly you will need to enforce this requirement within a posture policy as the next example shows from Work Centers> Posture> Posture Policy
Please notice here that the remediation configured will trigger in case the user does not met the condition configured for anti-malware , hence the status of the machine will be non- compliant, you need to adjust the non-compliant status to grant the machine the access it requires to become compliant depending upon the anti-malware you are talking , also during the configuration for the remediation message you can customize and instruct the end user in how to update by himself the anti-malware to become compliant , in any case you can find more insight in this guide https://community.cisco.com/t5/security-knowledge-base/ise-posture-prescriptive-deployment-guide/ta-p/3680273 .
Rate and comment if this helped you .
03-29-2023 06:51 AM
Thank you Rodrigo for your reply.
So, I understand that since the endpoint will need a manual remediation, the end users will need to remediate the laptop by themselves (let's say that it is an outdated antivirus). In that case, the end users do not have admin rights to their laptops and they will have to open a ticket to service desk to update their antivirus. Am I correct?
03-29-2023 10:46 PM
That would depend mostly on the application that is out of date, as per my understanding some of the anti-malware or anti virus upgrade procedures don't need admin privileges to run , in your scenario I would test it out first in lab environment with some users to double confirm about what they need to become compliant .
Let me know if that helped you .
03-12-2024 11:58 PM - edited 03-13-2024 12:01 AM
Hi Rodrigo,
I'm curious about which method of remediation action will force the client to update the anti-virus,
1. going online to download the patch from internet.
2. reading configuration from anti-virus program that installed and patching through internal server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide