04.03.2013 Views

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Trend</strong> Micro <strong>OfficeScan</strong> <strong>10.6</strong> Administrator’s <strong>Guide</strong><br />

Policy Server for NAC Deployment<br />

15-24<br />

The following procedures are for reference only and may be subject to change<br />

depending on updates to either the Microsoft and/or Cisco interfaces.<br />

Before performing any of the tasks, verify that the Network Access Device(s) on the<br />

network are able to support Cisco NAC (see Supported Platforms and Requirements on page<br />

15-22). See the device documentation for set up and configuration instructions. Also,<br />

install the ACS server on the network. See the Cisco Secure ACS documentation for<br />

instructions.<br />

1. Install the <strong>OfficeScan</strong> server on the network (see the Installation and Upgrade <strong>Guide</strong>).<br />

2. Install the <strong>OfficeScan</strong> client program on all clients whose antivirus protection you<br />

want Policy Server to evaluate.<br />

3. Enroll the Cisco Secure ACS server. Establish a trusted relationship between the<br />

ACS server and a Certificate Authority (CA) server by having the ACS server issue a<br />

certificate signing request. Then save the CA-signed certificate (called the ACS<br />

certificate) on the ACS server (see Cisco Secure ACS Server Enrolment on page 15-25<br />

for details).<br />

4. Export the CA certificate to the ACS server and store a copy on the <strong>OfficeScan</strong><br />

server. This step is only necessary if you have not deployed a certificate to clients<br />

and the ACS server (see CA Certificate Installation on page 15-25).<br />

5. Deploy the Cisco Trust Agent and the CA certificate to all <strong>OfficeScan</strong> clients so<br />

clients can submit security posture information to the Policy server (see Cisco Trust<br />

Agent Deployment on page 15-27).<br />

6. Install the Policy Server for Cisco NAC to handle requests from the ACS server (see<br />

Policy Server for Cisco NAC Installation on page 15-32).<br />

7. Export an SSL certificate from the Policy Server to the Cisco ACS server to<br />

establish secure SSL communications between the two servers (see Policy Server for<br />

Cisco NAC Installation on page 15-32).<br />

8. Configure the ACS server to forward posture validation requests to the Policy<br />

Server (see ACS Server Configuration on page 15-36).<br />

9. Configure the Policy Server for NAC. Create and modify Policy Server rules and<br />

policies to enforce your organization’s security strategy for <strong>OfficeScan</strong> clients (see<br />

Policy Server for Cisco NAC Configuration on page 15-37).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!