Put a Device in Quarantine Using Cisco ISE pxGrid
Let’s say you want to quarantine a device because you saw an alert that concerns
you. In Device Security in Strata Cloud Manager, use the
Quarantine via Cisco pxGrid option.
Device Security sends a quarantine command through Cortex XSOAR, the
Cortex XSOAR engine, and pxGrid to ISE.
In response, ISE sends a
Disconnect-Request message to the switch through which the impacted
device accesses the network and disconnects it. When the device
reconnects, ISE checks the quarantine policy it received from
Device Security, finds that it applies to the device requesting access,
and assigns it to a quarantine VLAN. The device remains in quarantine
while you investigate the cause of the alert. Once it’s resolved,
you can then use the Release via Cisco pxGrid option to return the device
to its regularly assigned VLAN.