Adaptive Network Control Policy Guidelines

Adaptive Network Control (ANC) is a service that runs on the Cisco ISE Policy Administration Node (PAN) that you can use to monitor and control network access for endpoints. ANC supports wired and wireless deployments.

You can invoke ANC actions on endpoints using APIs or scripts.

The following scripts are available:

  • Quarantine authenticated 802.1X endpoint

  • Unquarantine (clear) the endpoint

  • Provide a list of endpoints, based on triggered ANC policy

  • Subscribe to ANC capability to receive remediation and provisioning notices

ANC Endpoint and ANC Policy are documented in the Cisco ISE API Reference Guide.

The following actions are available:

  • QUARANTIINE: Disconnects the target client (after which it may reconnect)

  • RE_AUTHENTICATE: Forces the target client to do Re-Authentication, optionally implement an updated policy. This requires pxGrid 2.0.

  • SHUTDOWN: For a wired device, shutdown the port of the device, preventing reconnection.

The discovery ports listed in the following table are used to determine what device is present.

Port number Port assignment
4Closed Port
21FTP
22SSH
23telnet
80HTTP
135Windows RPC
161SNMP
443HTTPS
513rlogin
902VMware Authentication Daemon
3940Discovery for z/OS Agent
5985PowerShell HTTP
5986PowerShell HTTPS
5988WBEM HTTP
5989WBEM HTTPS
Adaptive Network Control
SourceDefault Port ProtocolDirectionalityReason
Main Appliance (MA)389 (TCP/UDP)LDAPMA to targets Active Directory Sync
Remote Collector(s) RC 53 (TCP) DNSDevice to targets DNS Zone Discovery
Remote Collector(s) RC 623 (UDP)IPMIRC to targetsIPMI-based discovery of management interfaces
Remote Collector(s) RC 22 (TCP)SSHRC to targetsSSH-based discovery of Linux and Unix systems
Remote Collector(s) RC 161 (UDP)SNMPRC to targetsSNMP discovery of network equipment

Introduction

This document describes Configuration of Rapid Threat Containment (Adaptive Network Control) on Cisco ISE® version 3.3 and Stealthwatch.

Prerequisites

Cisco recommends knowledge in these topics:

  • Identity Services Engine (ISE)

  • Platform Exchange Grid (PxGrid)

  • Secure Network Analytics (Stealthwatch)

  • Rapid Threat Containment (Adaptive Network Control - ANC).

In this document it is assumed that the Cisco Identity Services Engine is integrated with Secure Network Analytics (Stealthwatch) using pxGrid that is ANC-enabled.

Components Used

The information in this document is based on these software and versions:

  • Cisco Identity Services Engine (ISE) version 3.3

  • Secure Network Analytics (Stealthwatch) 7.5.1

  • Catalyst 9300

The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.

Cisco ISE

Live instant demo

​Try it yourself. Learn how to detect and neutralize threats in our live environment.

Cisco ISE