06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 13 Posture Validation<br />

Table 13-13 External Posture Validation Audit <strong>Server</strong> Setup Options (continued)<br />

Option Description<br />

Assign This Group if Audit <strong>Server</strong> Did<br />

not Return a Device Type<br />

OL-14386-02<br />

Posture Validation Pages Reference<br />

Enables assignment of a device to any administrator-defined group when the audit<br />

server does not return a device type.<br />

<strong>User</strong> Group Lists all user groups, including Any. The device type that MAC authentication<br />

returns is initially compared with this list of device types.<br />

Device Type Defines the comparison criteria <strong>for</strong> the <strong>User</strong> Group, using an operator and device<br />

type.<br />

Valid values <strong>for</strong> the operator are:<br />

match-all<br />

=<br />

!=<br />

contains<br />

starts-with<br />

regular-expression<br />

Valid values <strong>for</strong> the device type drop-down are not editable. They include:<br />

Printer<br />

IP Phone<br />

Network Infrastructure<br />

Wireless <strong>Access</strong> Point<br />

Windows<br />

Unix<br />

Mac<br />

Integrated Device<br />

PDA<br />

Unknown<br />

Type a device type in the text box if the device type drop-down does not contain a<br />

particular device.<br />

Assign <strong>User</strong> Group A drop-down list of administrator-defined user groups. If the comparison of the<br />

initial <strong>User</strong> Group with the Device Type succeeds, ACS will assign this user group.<br />

Add, Delete, Up, Down <strong>Control</strong>s that affect the user groups.<br />

Submit, Delete, Cancel <strong>Control</strong>s that affect the whole policy.<br />

An audit policy can be in use with more than one NAC Network <strong>Access</strong> Profile.<br />

Be<strong>for</strong>e deleting a policy, you must identify the NAC Network <strong>Access</strong> Profiles that<br />

the deletion will affect.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

13-39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!