Obligation of posture ISE to check if the USP of the endpoint port is disabled

Hello

I wonder if it is possible to define the USP Port disabled in the endpoints as a requirement in the Posture of the ISE?

Appreciate your comments.

Mike

If your question relates to the ability of the ISE, the disabling of the USB port on a PC, the answer is no.

The NAC agent using, however, you can check various programs and may be able to check the status of the USB.

You will need to create a new Condition of Posture and corrections.

The condition that I will use in this example is a registry key.

If the "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor\Start" key has a value of 3, the USB is enabled.  A value of 4 is disabled.

So set a Condition of Posture:

Click policy > policy elements > Conditions

Posture , choose the left menu:

Then choose Registry Condition in the left menu.

Click on + Add to add a new Condition of Posture:

Then, you must create remediation Actions.  Click the results button at the top of the left Menu:

Choose the repair Actions then reclamation that you want to use.  I chose the link cleanup.

+ Add to add a new link to the corrective measures:

Requirements , choose the menu on the left, and then create a new result of remediation:

Of course, you can choose different corrections if necessary for your environment.

Please rate useful messages and mark this question as answered if, in fact, does that answer your question.  Otherwise, feel free to post additional questions.

Charles Moreton

Tags: Cisco Security

Similar Questions

  • U2413, calibration solution Ultrasharp fails to connect to display via the USB port

    Dell U2413 SN: CN-0YCM0F-72872-48P-A81L REV A01 August 2014

    Try to run the ultrasharp Dell V1.5.3 on this monitor calibration solution, however, the software stops and displays "please connect the screen to your computer via a USB cable." I click the OK button after you have checked that the USB port on the computer is connected to the USB connection screen, but ultimately, this message appears:
    "Could not establish a connection to the screen. Please make sure that the USB cable is connected and try again. »

    Has tried this on two different computers, running Windows Pro 8.1. One was connected to the monitor cable HDMI to DVI (Thinkpad 10 via docking station), the other using the provided Dell Display Port printer for (Tablet Thinkpad X 230) mini display port cable.

    The USB ports on computers were connected the Dell supplied USB 3 cable to the monitor. Also tried this on a single computer by using a USB 2 port and a USB cable with the same result. The USB connections on the monitor seems to work ok when you plug a flash drive or the i1 Display Pro. Also, did a reset Monitor USB and verified that Windows has seen additional generic hubs when the USB Monitor is connected to the computer. There are 4 additional hubs when you use additional 2 usb hubs and USB 3 cable when using the USB 2 cable. In addition, power cycled the monitor several times (as recommended in the version that is known for this problem) without success.

    Before the attempt to make the calibration:
    A factory reset on the monitor.
    Ran the monitor self test and SUBMISSION. No problem found.
    Monitor purchased from Dell November 2014

    Same result with V1.5.7

    Any suggestions? Where should I go from here?

    I had success in the U2413 of profiling. I pulled out an old workhorse, a Thinkpad T43
    under Windows XP. Then installed the ultrasharp Dell V1.5.3 calibration solution and all
    updates available from Microsoft, but no other software - nothing of the Dell-supplied with
    the monitor. Used the DVI - connection DVI and USB 3 cable supplied with the monitor. The
    software Profiler has worked well with this configuration. When the program first took to the "Start
    Screen measure"(where the problem occurs already noted) Windows (message status bar)
    has reported that he accessed software Realtek 3.0. So I focused on research at the Realtek
    software on other systems.

    On the Thinkpad 10. There were two 1. "Realtek Card Reader" and 2. «Realtek USB 2.0 Card Reader» I have
    removed both and reinstalled the software Realtek for Dell monitor CD. Insert an SD card and
    a USB in the monitor and both were seen by Windows Explorer. There was also a Realtek USB
    3.0 card reader to showing in Manager devices under USB controllers. Using the connections between the T10 to monitor previously described the Profiler software, then ran normally.

    X 230 - I removed the "Realtek Card Reader" (V6.2.9600.30168) software and tried to start the
    Software Profiler and it does not at the same point as before. Then I installed the Realtek USB 2.0
    Software for the Dell card reader. However, there was still no Realtek USB 3.0 card reader
    display in the Manager of devices under USB controllers. Software Profiler is not like before. I then
    inserted an SD card in the monitor and the "Realtek USB Card Reader 3.0" appeared in the device
    Manager. Software Profiler, then ran normally.

    So now my two systems Windows 8.1 software profiling will not work if the 'Realtek USB 3.0 Card '.
    Reader"is not listed in Device Manager. To do this the software must be installed (for example
    starting from the Dell CD) AND an SD card must be inserted into the SD slot on the monitor. Remove the SD card
    Card and the device disappears and profiling software will not run. Insert an SD card and the
    Software Profiler works normally.

    How can I get the "Realtek USB 3.0 card reader ' to automatically load before running the Profiler software?

  • Problem with update 1.2 Posture ISE

    ISE 1.2 message below is showed when we do an update of manual or automatic web posture.

    "Remote address is not accessible. Please make sure that updated feed url, proxy address and proxy port are configured properly."

    It worked very well for a long time and all of a sudden it has stopped working
    and no changes were made on the network side.
    https://www.Cisco.com/Web/secure/pmbu/posture-update.XML works in the browser.

    Some customers have reported the same. Boxes are installed with the latest version of patch 7.

    We can download updates via offline.

    I had the same problem. Both the posture feed URL updated

    1. https://www.cisco.com/web/secure/pmbu/posture-update.xml

    2. https://www.perfigo.com/ise/posture-update.xml

    giving the same error, when ISE boxes try to do updates. But these URLs are accessible from the outside.

    A TCP dump from a watch as "Unkown Alert certificates" box (when he tries to update) for the certificate received from the other end. Then the box ISE sends a (FIN, ACK) and ends the session.

    The relevant pcap file is attached

  • ISE Local certificate and the certificates in the certificate store

    Hello

    I'm pretty new to ISE and read the document in the link below to create understanding "Local certificates" and "certificate store certificates. It seems that in the former certificate is used to identify the EHT on customers and is later used to identify customers at the ISE.

    http://www.Cisco.com/c/en/us/TD/docs/security/ISE/1-2/installation_guide...

    Now, what part of the ISE configuration told him to check the certificate sent by the client in its certificate store? I am somehow the mixture up with "Certificate authentication Profile", which is used in the identity Source sequence. But I guess that the certificate authentication profile is used to verify the certificates from a source of external identity as AD or LDAP. So where do we consider 'certificate certificate store' in our configuration of ISE.

    Thanks in advance for help out me.

    Kind regards

    Quesnel

    Hi Quesnel-

    (ISE) server certificate can be used for are:

    1 HTTP/HTTPs - is for the ISE web server that is used to host various portals (comments, Sponsor, BYOYD, my devices, etc.). This certificate is normally issued by a public CA such as VeriSign or GoDaddy. A public certification authority is not necessary, but outside your environment, customers who do not trust the certification authority that issued the certificate will get an error HTTPs warning to users that the certificate could not be verified.

    2 EAP - this is for EAP based authentication (EAP - TLS, EAP-PEAP, EAP-PEAP-TLS, etc.). This certificate is usually issued by an internal CA. The same certification authority issues usually user and/or computer-based certificates that can be used for the authentication type EAP - TLS.

    The certificate store is used to store root certificates and intermediate certificate authorities you ISE to trust. By example, if a computer is running a machine ISE authentication must trust the certification authority who has signed/issued the machine certificate. Therefore, the machine will also have to trust the certification authority which has issued/signed the ISE server certificate that you torque to the EAP process.

    Profile of teh authentication certificate is required if you want to use certificate based authentication. The CAPE tells ISE which attribute of the certificate should be used for the usernmane. Then based on that you can create more specific authorization profiles/rules information. You can also configure CAP to make a comparison of binary certificate with AD and confirm wheather or not the certificate is/has been published to AD.

    I hope this helps!

    Thank you for evaluating useful messages!

  • ISE is associated with the AD, but some groups are missing

    People,

    In my ISE I already joined my announcement on a Windows 2008 Server. But when I retrieve groups with *, some groups are missing. I mean there is a band like XXX.COM\COMPANY\IDG\HR in my 2008 Server, but I can't get back in my ISE, the group is Global. Is this a bug of ISE or are there special limits in import of my groups in ISE?

    Kind regards

    ISE can retrieve the list of groups max 100 and as you have said that the number did not reach 100, check if the configuration of Active Directory in the user node Administration ISE
    the interface is correct or you can add that the lack of groups directly use that check the following to add groups manually

    http://www.Cisco.com/en/us/docs/security/ISE/1.0/user_guide/ise10_man_id_stores.html#wp1059262

  • How to check if the discoverer is installed in the oracle application server?

    Hello

    I'm a developer, and I had an obligation to prepare a few reports of discoverer.

    However, I am new to Discoverer and as a result, I am facing problems during indexing of discoverer as Oracle Applications users.

    When I give the credentials, it asks me to choose a responsibility, and then he throws me error like "invalid username/password".

    applied patches according to metalink notes.

    but before that, I would like to know if I can really see whether or not the discoverer has been installed on the server of Oracle Applications.

    As my DBA also ignorant of the installation of discoverer, he also could not help me in this.

    How can we check if the discoverer has been installed on the server side and if not, how do install us it?

    Sorry for the stupid question.

    Hello

    The owner EUL is APPS and I might be able to connect to the Admin with this database user.

    I think you have an installation of database in mode EUL. You may not use APPS as the owner of the END user license. Therefore, you need to create a new mode of EUL requests in a separate schema.

    Is it possible that we can connect to Disco Admin/Desktop tool as a user of the database even though Disco is not installed on the server of Oracle Applications

    Yes, no problem. You only need server discoverer of applications if you want to use more or spectator.

    Rod West

  • Firefox 34.0.5 cannot print correctly. I checked all the pages on firefox problems and still can not solve the problem.

    I use 34.0.5 with Windows 7 and that you cannot print correctly. In print preview, it appears in a label size. I double checked all my settings in firefox and my preferences from the printer, I checked all the pages on firefox problems and still can not solve the problem.

    I was able to finally solve the problem, but I had to do a complete reset of firefox. Thank you for your time.

  • I check on the status of the claim

    I check on the status of the claim # 1112557863

    Apple isn't here.

    Username just like you who can't do anything to help you with the status of your application.

  • Stolen phone. How can I check when the last time saved my phone to my laptop (without my iphone of course)?

    My iPhone was stolen. How can I check when the last time that I backed up my phone to my laptop without my iPhone?

    Click here and either use iTunes to check or browse to the path of the backup manually.

    (142338)

  • Check the PLUG INS tells me that the Shockwave Flash plugin is obsolete. But when I check on the Adobe website, I have the latest version of this plugin (11.3.300.257)

    Check the PLUG INS tells me that the Shockwave Flash plugin is obsolete. But when I check on the Adobe website, I have the latest version of this plugin (11.3.300.257)
    I saw similar posts, but none of these.

    No, IE uses its own version of ActiveX of Flash plugin and that version will stay at the 11.3.300.257

  • I updated Firefox on my Mac (10.6.8), and now the story is not known (that option is checked) and the back button will not work. Help?

    I updated Firefox on my Mac (10.6.8), and now the story is not known (that option is checked) and the back button will not work. Help?

    One possible cause is a problem with the places.sqlite file that stores the bookmarks and history.

    You can also try to repair the database of places with this extension:

  • How to check if the mobile/cell the same phone number is registered on the different apple ID?

    Hello

    Is it possible to have the same number of mobile/cell phone with several Apple ID?

    If Yes, is it possible to check if the number is connected to several Apple ID? and how it can be removed?

    When I changed my job, I got a new cell phone number.

    I disconnected all my devices and removed my old number of my Apple ID, after that, I added my new number to my Apple ID and connected to my devices (iPhone, iPad and MacBook Air).

    The thing is that the person who had my new phone number previously, had the same phone number, added to their Apple ID.

    I get time iMessage and FaceTime applications contact the previous owner of my phone number.

    Even if it's annoying that I don't really like, I just block the numbers I don't recognize.

    But my big question is, if my friends iMessage and FaceTime applications for my new phone number can be found at the i-devices previous holders?

    I hope it's understandable - because it feels like a security risk.

    / Calle

    Unregister the old number

    https://selfsolve.Apple.com/deregister-IMessage

  • I have the time to default iPhone 4 iOS 7.1.2 iPhone App not updated since the last 3 days and also checked all the settings for location and also set as new iPhone always present problem... Please try to fix... Thanx

    I have the time to default iPhone 4 iOS 7.1.2 iPhone App not updated since the last 3 days and also checked all the settings for location and also set as new iPhone always present problem... Please try to fix... Thanx

    Turn off your device and turn it on again. If this does not help, sign out of your account and reconnect.

    In addition, you can try to reset your settings.

    • Press and hold the sleep/wake button
    • Press and hold the Home button
    • Press and hold both buttons until the display turns off and on again with the Apple logo on the subject.

    Alternatively, you can go to settings - general - reset - Reset all settings

  • My toolbar bookmarks no longer appear on my tabs even if it is checked in the Options.

    Usually, I have my favorites favorite under the tabs and other buttons. But they disappeared. Bookmarks bar is checked in the Options menu, and I unchecked it and rechecked it, but nothing happens. Bookmarks always appear when I click Favorites, then toolbar bookmarks, but they do not appear in the top of my screen. I've recently updated to the latest Firefox, but I don't know when the bookmarks disappeared... they just were not there this morning. I use Firefox 6.0.2 with Windows XP Professional.

    Make sure the bookmarks toolbar is visible and "Bookmarks Toolbar items" are always placed on the bookmarks toolbar.
    If the menu bar is hidden, then press F10, or press and hold the ALT key, which should make the "menu bar" appear.

    Make sure the toolbars like the toolbar 'Navigation' and the 'personal bar' are visible: "view > toolbars".

    • Open the Customize via "view > toolbars > customize" or "Options of > Firefox > toolbars" (Windows) and check that the "Bookmarks Toolbar items" are on the personal bar
    • If the "Bookmarks Toolbar items" is not on the bookmarks toolbar, then FRY it in the toolbar palette in the window the bookmarks toolbar Customize
    • If you do not see the "Bookmarks Toolbar items" or other items which do not appear in the palette of the toolbar or a toolbar, then click on the button "Restore Default Set"
  • My MacBook Pro suddenly becomes very slow, accepting orders very slow how to check if the ram is working properly

    My MacBook Pro suddenly becomes very slow, accepting orders very slow how to check if the ram is working properly

    You can try this download.   Etrecheck.   https://etrecheck.com/#about

    Then publish the report as a reply in this thread.

    It will allow us to review your system without disclosing a private matter.

Maybe you are looking for

  • How to go from iPhoto, while preserving the keywords and albums

    I use iPhoto on OS 10.8 and 10.9, topic.  It works great but looks like I'll need to move off of it for later OS versions. What I need, it is -keep the key words of my current missions and all other metadata -maintain the Organization into groups, al

  • The password of BIOS HP 15 f305dx

    Hi, I have a HP 15 f305dx, I need the BIOS admin password. Disabled system code: 82588657. Any help would be appreciated.

  • Replacement of the WRT54G Router

    I have a router that my cable company feel needs replacing. I don't really know if it's true, because they tried to sell me a new router or rent one for me. In any case I guess that replacement is necessary. I'm not a geek and my existing WRT54G Rout

  • How to get the old product key?

    Original title: product number The Microsoft sticker rubbed on the bottom of my computer.  Is it possible to get the numbers out of that so I can reload Windows on my computer?

  • __Restoring your laptop to factory settings _

    I'm certainly not great computer so I need some help on how I would be able to restore my laptop to factory settings, since I don't have disks for it at all. I HAD PURCHASEED IT OF A FRIEND OF A FRIEND AND ALL THEIR INFO IS ON IT AND I have JUST the