SSE in Device Intelligence
SSE in Device Intelligence
You can now configure SSE Integration in Device Intelligence and share device detail data from Device Intelligence to SSE. This feature allows you to use device details captured by Device Intelligence in SSE.
Netskope Security Service Edge (SSE) is a data-centric, cloud-native, and fast security solution. This feature enables you to create granular level policies with device context and device risk in Netskope SSE. The integration ensures that Device Intelligence integrates with SSE as a platform so the policy enforcement will be a common point of enforcement facilitated.
To do so, you need to follow a few steps:
- Configure SSE in Device Intelligence
- SSE use cases
- SSE UI
Configure SSE in Device Intelligence
Follow the procedure to configure SSE in Device intelligence UI:
-
Navigate to the Manage > Configurations menu.
-
Give a unique name to the integration configuration.
-
Add a description.
-
Choose the type of supported remediation integration configurations as Firewall.
-
Choose a supported vendor from the dropdown list as SSE.
-
Provide a valid host IP address or a domain name to connect to the network.
-
Choose an authentication type:
-
Username/password – provide the credentials for configuration.
-
Token – provide a token for configuration.
-
-
Choose a connection method as HTTPS.
-
Optionally, you can add extra key-value pair parameters to pass to this configuration.
-
Click Create Configuration button
Once you configure SSE in Device Intelligence, you can use this as an action for your policies in the next step.
SSE Use Case
Follow the procedure to create the policy:
-
Navigate to the Policies menu and click on the Create Policy tab.
-
Mark the status of the policy to be active on creation.
-
Give a unique policy name.
-
Select the type as context policy.
-
Give a category of the policy as Computers.
-
Add a description to explain the policy behavior.
-
Define a custom condition to capture managed and unmanaged devices.
-
Click on Add Rule and select field as Managed, condition as Equals, value as True. Add one more condition with OR conjunction and select field as Managed, condition as Equals, value as False. This condition will capture managed and unmanaged devices.
-
Select the alert severity as High.
-
Select the action to take as NAC.
-
Select the SSE configured in Step 1.
-
Select action as Segment and give a Segment Name as “SSE unsegment”.
-
Click Save Policy.
You will simultaneously see the policy results in SSE UI when this policy will capture devices with a high-risk score.
SSE UI
Login to the SSE UI using your credentials and you will see the Device Intelligence information in the Network Location tab > Segment Name section.