06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14 Network <strong>Access</strong> Profiles<br />

Table 14-26 Posture Validation Rule <strong>for</strong> profile_name Page<br />

Field Description<br />

Select External<br />

Posture Validation<br />

<strong>Server</strong><br />

OL-14386-02<br />

Related Topics<br />

Setting Up Posture Validation Policies, page 13-16<br />

Setting Up an External Policy <strong>Server</strong>, page 13-22<br />

Setting a Posture-Validation Policy, page 14-30<br />

Select External Posture Validation Audit <strong>for</strong> profile_name Page<br />

Network <strong>Access</strong> Profiles Pages Reference<br />

Select the external posture validation server policies that ACS will apply to the attributes received in the<br />

request <strong>for</strong> this rule.<br />

Failure Action Check to configure the Fail Open feature.<br />

Failure Posture Select the credential type (AV pair) that is returned to the supplicant.<br />

Token<br />

Select the Posture Token <strong>for</strong> the credential type.<br />

System Posture Use this table to configure the SPT to return to the AAA client. There are six predefined, nonconfigurable<br />

Token<br />

SPTs. The SPT results are listed in order from best to worst:<br />

Configuration<br />

System Posture Token—A Posture Agent Message and URL Redirect <strong>for</strong> each posture token.<br />

System Posture Token—A message that will appear <strong>for</strong> each posture agent.<br />

URL Redirect—The URL redirect that will be sent to the AAA client <strong>for</strong> each posture token.<br />

Use this page to select an external posture validation audit server <strong>for</strong> posture validation.<br />

To display this page, click Select Audit in the Posture Validation Page, page 14-48.<br />

Field Description<br />

Select Select the external posture-validation audit server or select Do Not Use Audit <strong>Server</strong>.<br />

Fail Open Determines treatment of errors that might occur, thereby preventing the retrieval of a posture token from an<br />

Configuration upstream NAC server. If fail open is not configured, ACS rejects the user request.<br />

Do not reject Enables or disables fail open (default = enabled).<br />

when Audit<br />

failed<br />

Use this token when unable to retrieve posture data—An appropriate token.<br />

Timeout—The timeout value <strong>for</strong> the session.<br />

Assign a <strong>User</strong> Group—The destination user group.<br />

Related Topics<br />

Setting Up an External Audit Posture Validation <strong>Server</strong>, page 13-25<br />

Configuring Posture Validation <strong>for</strong> Agentless Hosts, page 14-33<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

14-49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!