Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 103

Table 41, Service General Parameters

Page 103 highlights

Table 41: Service Page (General Parameters) Label Description Type Select the desired service type from the drop down menu. When working with service rules, you can select from the following namespace dictionaries: l Application: The type of application for this service. l Authentication: The Authentication method to be used for this service. l Connection: Originator address (Src-IP-Address, Src-Port), Destination address (Dest-IP-Address, Dest-Port), and Protocol l Device: Filter the service based on a specific device type, vendor, operating system location, or controller ID. l Date: Time-of-Day, Day-of-Week, or Date-of-Year l Endpoint: Filter based on endpoint information, such as enabled/disabled, device, OS, location, and more. l Host: Filter based on host Name, OSType, FQDN, UserAgent, CheckType, UniqueID, Agent-Type, and InstalledSHAs, l RADIUS: Policy Manager ships with a number of vendor-specific namespace dictionaries and distinguishes vendor-specific RADIUS namespaces with the notation RADIUS:vendor (sometimes with an additional suffix for a particular device). To add a dictionary for a vendor-specific RADIUS namespace, navigate to Administration > Dictionaries > Radius > Import Dictionary (link). The notation RADIUS:IETF refers to the RADIUS attributes defined in RFC 2865 and associated RFCs. As the name suggests, RADIUS namespace is only available when the request type is RADIUS. l Any other supported namespace. See "Namespaces" on page 341 for an exhaustive list of namespaces and their descriptions. To create new Services, you can copy or import other Services for use as is or as templates, or you can create a new Service from scratch. Name Label for a Service. Description Description for a Service (optional). Monitor Mode Optionally check the Enable to monitor network access without enforcement to allow authentication and health validation exchanges to take place between endpoint and Policy Manager, but without enforcement. In monitor mode, no enforcement profiles (and associated attributes) are sent to the network device. Policy Manager also allows Policy Simulation (Monitoring > Policy Simulation) where the administrator can test for the results of a particular configuration of policy components. More Options Select any of the available check boxes to enable the configuration tabs for those options. The available check boxes varies based on the type of service that is selected and may include one or more of the following: l Authorization: Select an authorization source from the drop down menu to add the source or select the Add new Authentication Source link to create a new source. l Posture Compliance: Select a Posture Policy from the drop down menu to add the policy or create a new policy by clicking the link. Select the default Posture token. Specify whether to enable auto-remediation of non-compliant end hosts. If this is enabled, then enter the Remediation URL. Finally, specify the Posture Server from the drop down menu or add a new server by clicking the Add new Posture Server link. Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 103

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Table 41:
Service Page (General Parameters)
Label
Description
Type
Select the desired service type from the drop down menu. When working with service rules, you can
select from the following namespace dictionaries:
l
Application
: The type of application for this service.
l
Authentication
: The Authentication method to be used for this service.
l
Connection:
Originator address (Src-IP-Address, Src-Port), Destination address (Dest-IP-Address,
Dest-Port), and Protocol
l
Device: Filter the service based on a specific device type, vendor, operating system location, or
controller ID.
l
Date:
Time-of-Day, Day-of-Week, or Date-of-Year
l
Endpoint
: Filter based on endpoint information, such as enabled/disabled, device, OS, location,
and more.
l
Host
: Filter based on host Name, OSType, FQDN, UserAgent, CheckType, UniqueID, Agent-Type,
and InstalledSHAs,
l
RADIUS:
Policy Manager ships with a number of vendor-specific namespace dictionaries and
distinguishes vendor-specific RADIUS namespaces with the notation
RADIUS:vendor
(sometimes
with an additional suffix for a particular device). To add a dictionary for a vendor-specific RADIUS
namespace, navigate to
Administration > Dictionaries > Radius > Import Dictionary
(link).
The notation
RADIUS:IETF
refers to the RADIUS attributes defined in RFC 2865 and associated
RFCs. As the name suggests, RADIUS namespace is only available when the request type is
RADIUS.
l
Any other supported namespace. See
"Namespaces" on page 341
for an exhaustive list of
namespaces and their descriptions.
To create new Services, you can copy or import other Services for use
as is
or as templates, or you
can create a new Service from scratch.
Name
Label for a Service.
Description
Description for a Service (optional).
Monitor
Mode
Optionally check the
Enable to monitor network access without enforcement
to allow authentication
and health validation exchanges to take place between endpoint and Policy Manager, but without
enforcement. In monitor mode, no enforcement profiles (and associated attributes) are sent to the
network device.
Policy Manager also allows
Policy Simulation
(
Monitoring > Policy Simulation
) where the
administrator can test for the results of a particular configuration of policy components.
More
Options
Select any of the available check boxes to enable the configuration tabs for those options. The
available check boxes varies based on the type of service that is selected and may include one or
more of the following:
l
Authorization
: Select an authorization source from the drop down menu to add the source or
select the
Add new Authentication Source
link to create a new source.
l
Posture Compliance:
Select a Posture Policy from the drop down menu to add the policy or
create a new policy by clicking the link. Select the default Posture token. Specify whether to
enable auto-remediation of non-compliant end hosts. If this is enabled, then enter the
Remediation URL. Finally, specify the Posture Server from the drop down menu or add a new
server by clicking the
Add new Posture Server
link.
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
103