Tuesday, August 21, 2018

ISE compliance checking with remediation for VPN

Hey guys, I've been using a guide that's made for a much older version of Cisco's ISE, and a lot of stuff doesn't quite match what we're using in production. I'm using ISE 2.2, and the compliance module is different, the layout of the Policy Element Conditions is quite different, and unfortunately it's messing me up in this deployment.

Long term goal is to have any non domain joined machines that connect to VPN should pull the Anyconnect Compliance Module (which I have already loaded the headend installer on our ASA), then check for certain AV software installations, definition ages, and Windows patch levels.

If anybody can point me to a guide that's good for ISE 2.2, and includes specifically the compliance checking integrated into VPN, I'd sure appreciate it.



No comments:

Post a Comment