05-24-2018 05:32 PM - edited 02-21-2020 10:56 AM
Does anyone know a good doc or video on ISE 2.4 Remediation for Windows Update and McAfee? Customer has SCCM running with Anyconnect and that checks for compliance. Customer wants to use ISE to remediate the SCCM/Anyconnect's noncompliance machines.
I am new to posturing and remeidation on ISE and SCCM/Anyconnect. So basically the compliance checks is done already and ISE is a new implementation and want to use it for remediation only of Windows Update and Antivirus.
Thank you!
05-25-2018 01:23 AM
05-25-2018 02:24 AM
05-25-2018 03:26 AM
05-25-2018 03:38 AM
05-25-2018 03:47 AM
05-25-2018 05:58 AM
05-25-2018 11:38 AM
05-25-2018 01:00 PM
06-01-2018 08:57 AM
Hi RichardAtikin,
thank you for this. Just saw your last response.
I was trying to replicate this and when I scanned my ISE server using Zenmap, I don't see ports 8905, 89095, 8443, or 8445 listen. I just see port 80, 427, 443, 8000 ( see attached)
I have enabled posturing under the admin settings. Are these ports supposed to be listening? How to enable them?
thank you!
06-01-2018 10:16 AM
Hi RichardAtkin,
Also, I was wondering if there is a way to test this (at least the wired part) without having a WLC? I am trying to see if I can get a vWLC set up but need to get the image first. I already have a switch and an ISE server.
thank you,
LN
06-02-2018 10:45 PM
Sure, WLC not required. ISE posture works for wired, wireless, and VPN connections.
06-03-2018 06:56 AM
06-03-2018 07:45 AM
ISE posture policy does not depend on the connection types unless we specify conditions based based on how the endpoints connect.
Please see Posture & Compliance for a collection of ISE design guides on that area.
06-04-2018 02:26 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide