Cisco AMP - Isolate Assets
  • 20 Mar 2025
  • 1 Minute to read
  • Dark
    Light
  • PDF

Cisco AMP - Isolate Assets

  • Dark
    Light
  • PDF

Article summary

Cisco ISE - Isolate Assets quarantines each of the assets (endpoints) returned by the selected query or assets selected on the relevant asset page, from the network.

See Creating Enforcement Sets to learn more about adding Enforcement Actions to Enforcement Sets.

Note:

Required Fields

  • Action name - The name of this Enforcement Action. The system sets a default name. You can change the name.
  • Configure Dynamic Values - Toggle on to enter a Dynamic Value statement. See Creating Enforcement Action Dynamic Value Statements to learn more about Dynamic Value statement syntax.

  • Use stored credentials from the Cisco Advanced Malware Protection (AMP) adapter - Select this option to use credentials from the adapter connection. By default, the first connection is selected.

  • Comment - Describe the reason for the action.

  • Unlock Code - Enter the unlock code to isolate the assets.

  • Compute Node - The Axonius node to use when connecting to the specified host. For more details, see Connecting Additional Axonius Nodes.

Additional Fields

These fields are optional.

Connection and Credentials

When Use stored credentials from the adapter is toggled off, some of the connection fields below are required to create the connection, while other fields are optional.

  • Domain - URL of the Cisco AMP domain.
  • Client ID and API Key - The credentials for a user account that has permission to fetch assets.
  • HTTPS Proxy - A proxy to use when connecting to the value supplied in Domain.
    • When supplied, Axonius uses the proxy when connecting to the value supplied in Domain.
    • When not supplied, Axonius connects directly to the value supplied in Domain.
  • Gateway Name - Select the Gateway through which to connect to perform the action.

Required Permissions

The stored credentials, or those provided in Connection and Credentials, must have permission to perform this Enforcement Action.


For more details about other Enforcement Actions available, see Action Library.



Was this article helpful?