06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Policies<br />

13-24<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 13 Posture Validation<br />

For descriptions of the options available on the External Policy Configuration page, see Configuring<br />

Policies, page 13-15.<br />

You can also set up an external AAA server that is used to evaluate SoHs from networks that include<br />

Microsoft Vista clients (NAC/NAP networks).<br />

To set up an external posture validation server:<br />

Step 1 After you choose External Posture Validation Setup, the External Posture Validation <strong>Server</strong>s page<br />

displays.<br />

Step 2 Under the External Posture AAA <strong>Server</strong>s table, click Add <strong>Server</strong>.<br />

The Add/Edit External Posture AAA <strong>Server</strong> page appears.<br />

Step 3 Name the server and provide a description if necessary.<br />

Step 4 Provide addressing in<strong>for</strong>mation <strong>for</strong> the primary and secondary servers:<br />

a. Check the Primary <strong>Server</strong> configuration check box.<br />

Note If you do not choose the Primary <strong>Server</strong> Configuration check box, ACS uses the secondary<br />

server configuration. If no secondary server configuration exists or the secondary server is<br />

unreachable, ACS rejects the posture validation request.<br />

b. Provide configuration details about the primary external AAA server. For more in<strong>for</strong>mation about<br />

the boxes and list in this area, see Configuring Policies, page 13-15.<br />

Step 5 (Optional) In the Secondary <strong>Server</strong> configuration pane:<br />

a. Check the Secondary <strong>Server</strong> configuration check box<br />

b. Enter configuration details about the secondary external AAA server. For more in<strong>for</strong>mation about<br />

the boxes and list in this area, see Configuring Policies, page 13-15.<br />

Step 6 Determine the <strong>for</strong>warding attributes to send to the primary or secondary external server by moving the<br />

available <strong>for</strong>warding attributes to the chosen <strong>for</strong>warding attributes column.<br />

Step 7 Click Submit to save your changes.<br />

Step 8 Click Apply and Restart to submit your changes to ACS.<br />

Editing an External Posture AAA <strong>Server</strong><br />

You can edit an external posture AAA server by accessing it through the Posture Validation pages.<br />

To edit an external posture validation server:<br />

Step 1 In the navigation bar, click Posture Validation.<br />

Step 2 Click External Posture Validation Setup.<br />

Step 3 Click the server name that you want to edit.<br />

The Add/Edit External Posture AAA <strong>Server</strong> page appears.<br />

Step 4 Edit the fields and click Submit.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!