Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello Cisco brains, I recently deployed Cisco ISE (3.1P3) and I'm running into an issue with Anomalous Behavior and Detection. I understand that in order for ISE to trigger an anomaly, it must hit the following:NAS-Port-Type - Determines if the acces...
Yes. It turns out the team that manages QRadar had an error in their setup, and they resolved it. I would hope that the TCPDUMP would cover the UDP traffic to at least prove that I am sending the logs.
Thanks for the input! @ahollifield . The goal is to keep things as simple as possible without restricting access to deploying new machines. These options helped confirm our thought process as well.
@ahollifield That would be an easy way out however our Security Team wants us to enable ISE on all ports. Unfortunately having a select group of ports on the network open is not an option.