This document is for Cisco Engineers, McAfee Engineers, partners and customers deploying McAfee Data Exchange Layer (DXL) Broker 4.0., McAfee ePolicy Orchestrator (ePO 5.9) with Cisco Platform Exchange Grid (pxGrid) using Cisco Identity Services Engine (ISE 2.3).
This document illustrates the steps required to configure the use cases below. This document also includes the following use cases:
n An Eicar Virus is detected on the endpoint, McAfee ePO generates an automated response where the McAfee DXL broker triggers an ISE pxGrid Adaptive Network Control (ANC) mitigation action, quarantining the endpoint in ISE.
This is a basic use case and illustrates the integration between McAfee DXL broker and Cisco ISE pxGrid node.
n The McAfee DXL broker python client receives ISE ANC “quarantined policy” notifications through Cisco pxGrid and McAfee ePO assigns a policy tag of “quarantined” to the endpoint when a violation in the ISE ANC policy occurs. Once this endpoint has been tagged by McAfee ePO, McAfee ePO can take manual action as defied by the McAfee ePO admin.
This use case is more advanced and is optional.
n The endpoint does not have the McAfee agent installed, ISE posture will detect this, and deem the endpoint non-compliant. A remediation link will be provided to the end-user via ePO to download and install the application. Once ISE detects that the McAfee ePO is installed, the endpoint is now compliant and granted full network access.
This use case is more advanced and is optional
n An employee-owned laptop goes through the organization’s on-boarding process to satisfy the organization’s BYOD initiative. The EPO admin can then install on the endpoint centrally or manually by the by the end- user.
I have a Cisco 5506-x (5 VLAN limit) and a Catalyst 2960-CG. I want to create about 15 VLANS. I was wondering if i could just create these on the Catalyst 2960-CG and not create them on the ASA or would I need to create them on both and have m...
Hi, I edited the default policy for ikev2 ( it is done for ipsec site to site vpn policy )The below is before editing crypto ikev2 policy 1encryption aes-256integrity shagroup 5prf shalifetime seconds 86400 and the below is afte...
Dear all, I've configured authentication Using Ldap server but Failed.After save the configuration and logout to test, I can't access to my FMC with both Local and External User :( Please help me procedure to rollback my FMC configuration from C...
Hi, Does someone know if ASA supports client certificate authentication + SAML with anyconnect ?As I understand the certificate is verified on the ASA, then I need a second factor auth with a SAML connection to a 2FA provider. note : I also have...