HP 3350 - Cisco NAC Appliance Spezifikationen Seite 227

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 226
6-13
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 6 User Management: Configuring User Roles and Local Users
Create User Roles
Enable Passive
Re-assessment
This option allows periodic re-assessment on client systems that are online to
ensure continuous compliancy of the current network policies. This option is
disabled by default.
Passive Re-assessment enables the persistent Agent (Cisco NAC Agent) on the
client machine to periodically verify that the client machine is still compliant
with imposed network security policies without requiring the user to log out of
Cisco NAC Appliance and go through posture assessment to “regain” network
access.
Note For OOB deployment, you must enable the Out-of-Band Logoff function
in order to enforce Passive Re-assessment. See Configure Out-of-Band
Logoff, page 9-6 for details.
Note Passive Re-assessment is available for NAC Agent 4.8.0.32 or later only.
Note While using Passive Re-assessment, the client should communicate with
the same CAS that authenticated the user.
Re-assessment Interval—The time interval in minutes between the
completion of login process and the first re-assessment, and between
consecutive re-assessment attempts on the client machine. The timer starts
once the login is completed successfully.
The time can vary from 60 minutes (1 hour) to 1440 minutes (24 hours). The
default value is 240 minutes (4 hours).
Grace Timer—The time in minutes for which the Agent waits for the users
to remediate any failed posture checks, when the Default action on failure
option has been set to Allow user to remediate.
The time can vary from 5 minutes to 30 minutes. The default value is 5
minutes.
Default action on failure—Select the default action to be performed if the
re-assessment fails:
Continue—The user can continue using the network. No interaction is
required by the user with the agent. This is the selected by default.
Allow user to remediate—The user is prompted for remediation when
there is a failure in any of the optional or mandatory requirements. If the
user cancels the remediation, then the CAM receives a failed
requirement report from the client machine performing Passive
Re-Assessment.
Logoff user immediately—The user is logged out immediately when
any of the mandatory requirements fails, and placed back to the
unauthenticated network.
The CAM/CAS keep track of the Passive Re-assessment reports and save failed
reports, which can be viewed using the Clean Access Agent Report Viewer. If the
servers do not receive any report from the Agent within a time interval, then the
user is removed from the on-line user list. The maximum time interval for which
the server waits is Re-assessment Interval + 2 x Grace Timer.
Table 6-1 Role Properties (continued)
Control Description
Seitenansicht 226
1 2 ... 222 223 224 225 226 227 228 229 230 231 232 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare