Endpoint Compliance Flashcards
Posture Configuration flow
Posture Conditions (What conditions need to be met)
Posture Remediation (Actions for endpoints where Condition isn’t met)
Posture Requirement (Ties together Condition & Requirement)
Posture Policy (Tie together multiple Requirements)
Client Provisioning (Configure settings for AnyConnect)
Access Policy (Tie Posture Policy against Unknown, Non-Compliant or Compliant Authorization policy)
Posture Condition
What CAN be checked & Which conditions need to be met
Posture Remediation
What actions are taken if an endpoint fails the Posture Conditions
Posture Requirement
Posture Condition + Posture REmediation + OS + AnyConnect Compliance Module Type/Version
Posture Policy
Tie together multiple Requirements and enable
Client Provisioning
Configure settings for AnyConnect agent on ISE
Access Policy
Configure Unknown, Compliant & Non-Compliant authorization policies.
Unknown endpoints get re-directed to ISE Client Provisioning Portal
What is CoA used for
Following initial authentication and authorization CoA allows ISE to initiate a request to a NAD to disconnect user session, bounce the port or have endpoint or user perform re-authentication
CoA Types
No CoA: Device remains in Unknown state until next re-authentication
Port Bounce / Session Bounce: ISE forces NAD to reset switchport (wired) or bounce session (Wireles)
Reauth: Forces user/endpoint to re-authenticate
What is MAB
MAC Authentication Bypass
Device without 802.1x supplicant uses MAC address to authenticate.
MAB RADIUS Service-Type
Call-Check
How MAB Works
MAC address of endpoint is added to Endpoint Identity Group in ISE.
AuthZ Policy configured for MAB devices.
Device authenticates using MAC address
ISE does Lookup against Endpoint Identity Group
If MAC is present AuthC is granted and AuthZ policy applied.
Access-Accept Returned to NAD
MAC address length
48-bit Hexadecimal
e.g 1A:2B:3B:4D:5E:6F
1A:2B:3C = Organization Unique Identifier
Devices which often lack Supplicants
Printers, Scanners, IP Cameras, Door Card readers
What can Posture Assessment check for
Files including existence, version, date
Registry conditions on Windows OS
If service is running on Windows OS