HP 3350 - Cisco NAC Appliance Spezifikationen Seite 327

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 326
9-21
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 9 Configuring Cisco NAC Appliance for Agent Login and Client Posture Assessment
Setting Up Agent Distribution/Installation
Figure 9-7 Agent Installation Page
Discovery Host—This field is used by the Agent to send a proprietary, encrypted, UDP-based
protocol to the Clean Access Manager to discover the Clean Access Server in Layer 3 deployment.
The field automatically populates with the CAM’s IP address (or DNS host name). In most cases,
the default IP address does not need to be changed, but in cases where the CAM’s IP address is not
routed through the CAS, the Discovery Host can be any IP address or host name that can be reached
from client machines via the CAS. Upon initial installation or when a new Agent configuration XML
file is passed to the client machine via the CAS, the Cisco NAC Agent automatically uses this value
for the DiscoveryHost parameter in the Agent configuration XML file, which is required to perform
successful Agent login.
Note When the Discovery Host value is changed, it is received only by the new Agents that are
deployed. The existing Agents do not receive the changed IP address. You need to use the
“overwrite” function in the DiscoveryHost parameter in the Agent configuration XML file, for
the existing Agents to receive the changed Discovery Host value. Refer to Table 9-4 on
page 9-27 for more information.
Note The Discovery Host is set to the IP of the CAM by default because the CAM must always be on
a routed interface on the trusted side of the CAS. This means any client traffic on the untrusted
side must pass through a CAS in order to reach the IP of the CAM. When the client attempts to
contact the Discovery Host IP, the CAS will intercept the traffic and start the login process. It is
assumed that best practices are applied to protect the CAM with ACLs, and that no client traffic
should ever actually arrive at the CAM. For extra security (once L3 is correctly deployed), you
can change the Discovery Host to an IP other than the CAM IP on the trusted side.
Seitenansicht 326
1 2 ... 322 323 324 325 326 327 328 329 330 331 332 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare