cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1290
Views
5
Helpful
3
Replies

ISE Posturing and WSUS

Daniel Lucas
Level 1
Level 1

Is there way to check against a local WSUS server for determining if an endpoint is up-to-date? I have a situation where corporate endpoints typically don't have the absolute latest windows patch, and is intentionally left out of WSUS for a period before pushing them out. Is there a way to check if the endpoint has the latest update per the corporate WSUS policy, and not the latest published by microsoft/OPSWAT?

 

-Thanks

1 Accepted Solution

Accepted Solutions

howon
Cisco Employee
Cisco Employee

Yes, ISE posture policy can use local WSUS policy. However, there are no settings to configure on ISE aside from making WSUS condition. AnyConnect posture module simply interfaces with the WSUS agent to get status update. If the WSUS agent is configured for local WSUS then WSUS agent will verify with local WSUS server to see if it compliant and report back to AnyConnect posture module of the status.

 

View solution in original post

3 Replies 3

howon
Cisco Employee
Cisco Employee

Yes, ISE posture policy can use local WSUS policy. However, there are no settings to configure on ISE aside from making WSUS condition. AnyConnect posture module simply interfaces with the WSUS agent to get status update. If the WSUS agent is configured for local WSUS then WSUS agent will verify with local WSUS server to see if it compliant and report back to AnyConnect posture module of the status.

 

Ok thanks!

Hello,

can you provide some more details about this type of integration?

does this mean that we need to allow WSUS agent on PC to communicate to WSUS server? (authorization profile/result when postrue status is unknown ou non-compliant?)

Thanks for your help