06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 13 Posture Validation<br />

Table 13-12 Add/Edit External Posture Validation <strong>Server</strong> Page (continued)<br />

OL-14386-02<br />

Posture Validation Pages Reference<br />

Option Description<br />

URL Specifies the HTTP or HTTPS URL <strong>for</strong> the server. The <strong>for</strong>mat <strong>for</strong> URLs is:<br />

[http[s]://]host[:port]/resource<br />

where host is the hostname or IP address of the NAC server, port is the port number used,<br />

and resource is the rest of the URL, as required by the NAC server itself. The URL varies<br />

depending on the server vendor and configuration. For the URL that your NAC server<br />

requires, refer to your NAC server documentation.<br />

The default protocol is HTTP. URLs beginning with the hostname are assumed to be using<br />

HTTP. To use HTTPS, you must specify the URL beginning with https:// and import a<br />

self-generated CA certificate into ACS <strong>for</strong> this policy server. See ACS Certificate Setup,<br />

page 9-22.<br />

If the port is omitted, the default port is used. The default port <strong>for</strong> HTTP is port 80. The<br />

default port <strong>for</strong> HTTPS is port 443.<br />

If the NAC server hostname is antivirus1, which uses port 8080 to respond to HTTP<br />

requests <strong>for</strong> the service provided policy.asp, a script kept in a web directory called cnac,<br />

valid URLs would be:<br />

http://antivirus1:8080/cnac/policy.asp<br />

antivirus1:8080/cnac/policy.asp<br />

If the same server used the default HTTP port, valid URLs would be:<br />

http://antivirus1/cnac/policy.asp<br />

http://antivirus1:80/cnac/policy.asp<br />

antivirus1/cnac/policy.asp<br />

antivirus1:80/cnac/policy.asp<br />

If the same server used HTTPS on the default port, valid URLs would be:<br />

https://antivirus1/cnac/policy.asp<br />

https://antivirus1:443/cnac/policy.asp<br />

<strong>User</strong>name Specifies the username required <strong>for</strong> access to the server. The server ignores the values in<br />

the <strong>User</strong>name and Password fields if the server is not password protected.<br />

Password Specifies the password required <strong>for</strong> access to the server. The server ignores the values in<br />

the <strong>User</strong>name and Password fields if the server is not password protected.<br />

Timeout (Sec) The number of seconds that ACS waits <strong>for</strong> a result from the external server, including<br />

domain name resolution. The Timeout value must be greater than zero (0). The default is<br />

10.<br />

ACS <strong>for</strong>wards requests to the secondary server (if configured) when the primary server<br />

times out. If no secondary server is configured or if a request to the secondary server also<br />

times out, ACS cannot apply the external policy and there<strong>for</strong>e rejects the posture<br />

validation request.<br />

For each posture validation request, ACS always tries the primary server first, regardless<br />

of whether previous requests timed out.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

13-35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!