cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
448
Views
0
Helpful
2
Replies

CSA Configuration suggestion??

cbigas
Level 1
Level 1

How would you recommend a rule setup to lock down your SOE. For example I have an application class that has all our approved software listed, how could you then block/restrict anything that is not on this list???

2 Replies 2

pcomeaux
Cisco Employee
Cisco Employee

Hey there -

Seems like permitting your SOE then denying *.exe, *.com, etc would be the easiest route. It would take a clean PC to ensure your App Class had just the processes you wanted to run.

Another alternative is that you could restrict the ability for the user's to install any program, while only permitting them to install from internal websites or from a pre-defined public share.

So for your question, if you had an App Class with all your permits, add a Deny to deny all executables you don't want to launch. This could be any executable from the all hard drives, or maybe just executables in c:\program files\**

Let us know what you think and we can continue discussing this.

thanks

peter

Peter,

Thanks for your suggestions. I've been away for a few days, I'll try them out and let you know.

rgds

cbigas

Review Cisco Networking for a $25 gift card