06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Posture Validation Pages Reference<br />

Table 13-13 External Posture Validation Audit <strong>Server</strong> Setup Options (continued)<br />

Option Description<br />

URL The URL of the audit server. Specify the HTTP or HTTPS protocol.<br />

URLs must con<strong>for</strong>m to the following <strong>for</strong>mat:<br />

13-38<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

[http[s]://]host[:port]/resource<br />

Chapter 13 Posture Validation<br />

where host is the hostname or IP address of the external server, port is the port<br />

number used, and resource is the rest of the URL, as required by the external server.<br />

The URL varies depending on the server vendor and configuration.<br />

The audit server documentation contains specific <strong>for</strong>mat guidelines.<br />

<strong>User</strong>name The username that the audit server requires.<br />

Password The password that the audit server requires.<br />

Timeout (sec) The number of seconds that ACS waits <strong>for</strong> a result from the audit server, including<br />

domain name resolution. The Timeout value must be greater than zero (0).<br />

Trusted Root CA A certification authority that is required if the URL of the audit server specifies the<br />

HTTPS protocol. This option should match the certification authority that issued<br />

the audit server certificate installed on the primary server.<br />

Validate Certificate Common Name When checked (enabled), this option shows the host name within the URL <strong>for</strong><br />

purposes of comparison with the common name in the certificate. If the names do<br />

not match, ACS closes the SSL connection, posture validation fails, and user access<br />

is denied.<br />

Audit Flow Settings<br />

Use this Posture Token while Audit Interim posture token sent from ACS to the NAD while waiting <strong>for</strong> a result. ACS<br />

<strong>Server</strong> does not yet have a posture uses the In Progress token be<strong>for</strong>e the Audit <strong>Server</strong> determines the actual posture of<br />

validation result<br />

the nonresponsive host.<br />

Polling Intervals and Session-Timeout Either the timeout values that are sent by the audit server or that are set in the<br />

authorization policy. ACS requires a polling interval if the configuration uses the<br />

values that are set in the authorization policy. The authorization policy must<br />

include the necessary RACs in order to assign specific timeout values in the final<br />

resulting tokens. See Configuring an Authorization Rule, page 14-36.<br />

Maximum amount of times the Audit<br />

<strong>Server</strong> should be polled<br />

Policy string to be sent to the Audit<br />

<strong>Server</strong><br />

GAME Group Feedback<br />

The maximum number of times that ACS will query the audit server <strong>for</strong> a result<br />

(posture token). Range of 1–10 times.<br />

The name of the policy, if the audit server supports named policy invocation.<br />

Request Device Type from Audit <strong>Server</strong> Enables the audit policy configuration options. When enabled, the Audit feature<br />

can request a device type from the audit server and then check the device type<br />

against the device type that MAC authentication returns.<br />

If this check box is not available, define an audit device type attribute <strong>for</strong> the<br />

vendor in the internal ACS dictionary.<br />

ACS <strong>for</strong> Windows: Use the CSUtil.exe command. See Posture-Validation<br />

Attributes, page C-29 <strong>for</strong> in<strong>for</strong>mation.<br />

ACS SE: Use the NAC Attributes Management page in the web interface. See NAC<br />

Attribute Management (ACS SE Only), page 8-44 <strong>for</strong> more in<strong>for</strong>mation.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!