06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 13 Posture Validation<br />

Creating an Internal Policy<br />

OL-14386-02<br />

Editing a Policy, page 13-19<br />

Deleting a Policy or Rule, page 13-21<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Configuring Policies<br />

Use internal posture validation to write your own policies <strong>for</strong> access in your network. After you have<br />

created policies, you can then profile rules to use these policies.<br />

You can select internal policies <strong>for</strong> more than one profile. To add the policy to a profile, use the Network<br />

<strong>Access</strong> Profiles page.<br />

For descriptions of the options available on the Internal Posture Validation Setup page, see Configuring<br />

Policies, page 13-15.<br />

For details on how to set up your third-party component policies, see the related documentation on the<br />

Go NAC website on <strong>Cisco</strong>.com. For in<strong>for</strong>mation on adding internal policies to your profiles, see<br />

Posture-Validation Policy Configuration <strong>for</strong> NAPs, page 14-29.<br />

Once you have set up at least one policy, you can use the clone rule option to save time by copying a<br />

policy and customizing it. For details on how to use cloning, see Cloning a Policy or Policy Rule,<br />

page 13-20.<br />

To create your internal posture validation policy:<br />

Step 1 <strong>Access</strong> the Internal Policy Validation Setup page:<br />

a. In the navigation bar, click Posture Validation.<br />

b. Click Internal Posture Validation Setup.<br />

ACS displays a list of posture validation policies, if available.<br />

c. Click Add Policy.<br />

Step 2 In the Name box, type a descriptive name <strong>for</strong> the policy.<br />

Step 3 In the Description box, type a useful description of the policy.<br />

Step 4 Click Submit.<br />

Step 5 Click Add Rule.<br />

Step 6 For each condition set that you want to add to the rule:<br />

a. Select an attribute. For more in<strong>for</strong>mation about attribute types, see Posture Validation Attribute Data<br />

Types, page 13-6.<br />

b. Select an entity (only available <strong>for</strong> extended attributes).<br />

c. Select an operator.<br />

d. Type a value.<br />

e. Click Enter and then Submit.<br />

For example, if you create a policy <strong>for</strong> the CSA, you might create the following condition sets:<br />

<strong>Cisco</strong>:PA:PA-Version >= 2.0.0.0 AND <strong>Cisco</strong>:PA:Machine-Posture-State = 1 with a Posture<br />

token=Healthy.<br />

<strong>Cisco</strong>:PA:PA-Version >= 2.0.0.0 AND <strong>Cisco</strong>:PA:Machine-Posture-State = 2 with a Posture<br />

Token=Transition.<br />

Match OR inside Condition and AND between Condition Sets to allow ACS to choose between<br />

tokens.<br />

13-17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!