Posture refers to the process of checking and ensuring that endpoint devices connected to a network meet the required security standards.
Cisco Identity Services Engine (ISE) is a network access control (NAC) solution that provides posture services to secure network access.
This article will explore the concept of posture in Cisco ISE and its significance in network security.
I strongly recommend checking the CISCO ISE Course for those who want to learn more about this topic.
What Is Cisco ISE?
Before diving deeper into posture, it helps to understand the platform behind it. Cisco ISE is an Identity Services Engine that provides authentication, authorization, and accounting (AAA) services for devices on a network. It can be used to manage wired, wireless, and remote access connections.
Cisco ISE acts as a policy enforcement point (PEP) that sits in the data path between clients and servers. It can authenticate users and devices before allowing them access to network resources, authorize devices for specific types of traffic, and track user activity for billing or security purposes. In general terms, it is considered one of the most popular NAC solutions in the world.
What Is a NAC Solution?
A NAC solution is a Network Access Control solution: a security system that allows an administrator to control and manage who or what has access to the network and how they access it. A NAC solution can do things like:
- Check the security of a device before it is allowed onto the network
- Prevent infected devices from spreading malware or other infections to other devices on the network
- Limit the type or amount of data that can be transmitted by devices on the network
- Block devices from accessing certain websites or applications
Deployment Options
Cisco ISE is a critical part of the Cisco security architecture and can be deployed in various ways: on-premises, in the cloud, or as a hybrid solution. It is cloud-enabled and can also run on Azure virtual machines, letting you take advantage of the scalability and elasticity of the cloud while still maintaining complete control over your network security.
Understanding Posture in Cisco ISE
Posture assessment involves checking endpoint devices such as computers, laptops, smartphones, and tablets to ensure they comply with the network's security policies before granting them network access.
Cisco ISE provides various posture assessment methods, such as file integrity checking, antivirus protection, and host intrusion prevention systems (HIPS). These checks help ensure that endpoint devices do not introduce security threats to the network.
Cisco ISE Posture Components
Cisco ISE posture consists of the following components:
Posture Policies
Posture policies define the requirements that endpoint devices must meet to be granted network access. These policies can include antivirus protection, operating system updates, and firewall configuration.
Posture Agents
Posture agents are installed on endpoint devices to check for compliance with posture policies. These agents communicate with the Cisco ISE server to verify that the endpoint device meets the required security standards.
Posture Conditions
Posture conditions determine how Cisco ISE evaluates endpoint device compliance with posture policies. These conditions can include antivirus version checks, registry key checks, and file existence checks.
Posture Remediation
Posture remediation is the process of correcting non-compliant endpoint devices to meet the required security standards. Cisco ISE can automatically remediate non-compliant devices or quarantine them until remediation occurs.
Importance of Posture in Cisco ISE
Posture is crucial in ensuring network security in organizations. By verifying that endpoint devices comply with security policies before granting them network access, posture helps prevent security breaches and data theft. Furthermore, posture enables organizations to monitor endpoint device compliance continually, ensuring that they remain secure over time.
Posture and BYOD
Bring Your Own Device (BYOD) policies enable employees to use personal devices to access corporate networks, increasing the risk of security threats. Cisco ISE posture can help mitigate this risk by checking endpoint devices for compliance with security policies before granting them network access. Posture can also ensure that personal devices do not introduce security risks to the corporate network.
Posture and Profiling in Cisco ISE
Posture is not the only visibility mechanism in Cisco ISE. Profiling is the ability to identify users and devices as they interact with the network: it allows you to see what applications are being used, what sites are being visited, and how much bandwidth is being consumed. While posture verifies that an endpoint complies with security policy, profiling tells you what that endpoint actually is and how it behaves — the two capabilities complement each other.
Cisco ISE uses a variety of profiling techniques, including active monitoring (which observes traffic as it flows through the network), passive monitoring (which captures traffic that has already passed through the network), and fingerprinting (which identifies devices by their unique characteristics).
This information can be used to improve security by identifying risky behavior, or to optimize network resources by identifying which applications or websites are consuming the most bandwidth.
Guest Services in Cisco ISE
Alongside posture for managed endpoints, Cisco ISE also handles devices that are not yours at all. Guest services in Cisco ISE allow businesses to provide temporary network access to non-employees, such as contractors, vendors, partners, and visitors, without compromising the security of their networks. Cisco ISE enables businesses to create and manage guest accounts, restrict network access, and monitor guest activity.
Creating and Controlling Guest Accounts
Guest accounts can be created in two ways: with the self-registration feature, guests register themselves by entering their name, email address, and other relevant information, and the system generates temporary login credentials; alternatively, administrators can manually create guest accounts and set up the login credentials themselves.
Businesses can then restrict the level of network access that guests have: policies define what guests can access, how long they can access it, and when they can access it, while rules limit the number of devices guests can connect, which devices they can connect, and the level of access each device has. Cisco ISE also monitors guest activity — what guests are doing, which devices they are using, and how long they access the network — helping identify security breaches or policy violations and take corrective action.
Implementing Guest Services
Implementation follows four steps:
- Set up guest services: configure Cisco ISE to enable guest access and create a guest portal that allows self-registration or manual account creation.
- Define guest policies: specify what guests can access, for how long, and when, plus device-count and per-device access rules.
- Configure guest access: create a WLAN or VLAN for guests and configure its network settings, such as the SSID, security settings, and network address translation (NAT) settings.
- Test guest access: verify that guests can connect, reach the resources they need, and that their activity is being monitored.
Done right, guest services deliver improved security and regulatory compliance (guests are authenticated and authorized before accessing the network), a smoother user experience through seamless and customized access, and reduced costs by automating guest account management.
Limitations of Posture
While posture is an essential component of network security, it has some limitations. For instance, posture checks may not detect zero-day vulnerabilities that are not yet known. Moreover, posture checks may not be effective against insider threats, where a malicious insider intentionally compromises network security.
Conclusion
In summary, posture is a vital concept in Cisco ISE and network security. By verifying that endpoint devices comply with security policies before granting them network access — and by combining posture with profiling and guest services — organizations can prevent security breaches, keep endpoints compliant over time, and safely accommodate both corporate and visitor devices.
In today's fast-paced and ever-changing technological landscape, cyber-attacks and data breaches are becoming more sophisticated and frequent, making these skills more valuable than ever. Cisco also offers the Implementing and Configuring Cisco Identity Services Engine (SISE) exam, which covers the deployment and operation of Cisco ISE, including guest services. To gain in-depth knowledge and hands-on experience with posture and the rest of the platform, take a look at the Cisco ISE course.
