cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2141
Views
5
Helpful
2
Replies

WSUS with ISE Posture

Greetings,

Can anyone tell me how to implement an ISE WSUS posture that will check if the last update date of a windows workstation is less than two months.

Thanks.

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

here is deployment case :

 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119214-configure-ise-00.html

 

I do not belive it has option(nor i have seen that 2months old), you can make condition for for the critical patches applied as per security requirement.

 

Other way you can run the script to check when when was the last time it has updated (i have not done, just my suggestion).

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

here is deployment case :

 

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119214-configure-ise-00.html

 

I do not belive it has option(nor i have seen that 2months old), you can make condition for for the critical patches applied as per security requirement.

 

Other way you can run the script to check when when was the last time it has updated (i have not done, just my suggestion).

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Jason Kunst
Cisco Employee
Cisco Employee

have you looked at the ise posture guide?
https://community.cisco.com/t5/security-documents/ise-posture-prescriptive-deployment-guide/ta-p/3680273

 

You're right there is no way to get more granular than that. I have tagged our SME @Timothy Abbott