Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 172

Adding and Modifying Posture Policies, ClearPass Windows Universal System Health Validator.

Page 172 highlights

Configurable Component How to Configure endpoints. Remediation URL This URL defines where to send additional remediation information to endpoints. Sequence of Posture Servers Select a Posture Server, then select Move Up, Move Down, Remove, or View Details. l To add a previously configured Posture Server, select from the Select drop- down list, then click Add. l To configure a new Posture Server, click Add New Posture Server (link) and refer to "Adding and Modifying Posture Servers " on page 199. l To edit the selected posture server, click Modify and refer to "Adding and Modifying Posture Servers " on page 199. Enable auto-remediation of non-compliant end-hosts Select the Enable auto-remediation of non-compliant end-hosts check box to enable the specified remediation server to enable auto-Remediation. Remediation server is optional. A popup appears on the client box, with the URL of the Remediation server. Adding and Modifying Posture Policies Policy Manager supports pre-configured posture plugins, against which administrators can configure rules that test for specific attributes of client health and correlate the results to posture tokens: l If you have NAP Agent (USHA) running on a NAP-compatible client (Microsoft Windows 8, Windows 7, Windows Vista, Windows XP SP3, Windows Server 2008), use: ClearPass Windows Universal System Health Validator. Configurable checking for present/absent Registry Keys, Services and processes, and product-/version-/update- specific checking for Antivirus, Antispyware, and Firewall applications. Checks for peer-to-peer applications or networks, patch management applications, hotfixes, USB devices, virtual machines, and network devices. l If you have ClearPass Linux NAP Agent running on a Linux client (CentOS, Fedora, Red Hat Enterprise Linux, SUSE Linux Enterprise Desktop), use: ClearPass Linux Universal System Health Validator. Configurable checking for present/absent Services, and product-/version-/update- specific checking for Antivirus application, and Firewall configuration. l If you have a Microsoft NAP Agent running on the client, use: n Windows System Health Validator. Configurable checking for required operating system versions and service packs. n Windows Security Health Validator. Configurable checking for Antivirus/Antispyware/Firewall applications, as well as automatic updates and security updates. l If you have ClearPass OnGuard Agent (dissolvable or persistent) running on the client (Windows 8, Windows 7, Windows XP SP3, Windows Vista, Windows Server 2008, Windows 2003, SUSE Linux, Redhat Enterprise Linux, Fedora Linux, CentOS Linux, MAC OS X), use: n ClearPass Windows Universal System Health Validator. Configurable checking for present/absent Registry Keys and Services, and product-/version-/update- specific checking for Antivirus, Antispyware, and Firewall applications. Checks for peer-to-peer applications or networks, patch management applications, hotfixes, USB devices, virtual machines, and network devices. n Windows System Health Validator. Configurable checking for required operating system versions and service packs. 172 Dell Networking W-ClearPass Policy Manager 6.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

172
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
Configurable Component
How to Configure
endpoints.
Remediation URL
This URL defines where to send additional remediation information to endpoints.
Sequence of Posture Servers
Select a Posture Server, then select
Move Up
,
Move Down
,
Remove
, or
View
Details
.
l
To add a previously configured Posture Server, select from the
Select
drop-
down list, then click
Add.
l
To configure a new Posture Server, click
Add New Posture Server
(link) and
refer to
"Adding and Modifying Posture Servers " on page 199
.
l
To edit the selected posture server, click
Modify
and refer to
"Adding and
Modifying Posture Servers " on page 199
.
Enable auto-remediation of
non-compliant end-hosts
Select the
Enable auto-remediation of non-compliant end-hosts
check box to
enable the specified remediation server to enable auto-Remediation.
Remediation server is optional. A popup appears on the client box, with the URL of
the Remediation server.
Adding and Modifying Posture Policies
Policy Manager supports pre-configured posture plugins, against which administrators can configure rules that test for
specific attributes of client health and correlate the results to posture tokens:
l
If you have NAP Agent (USHA) running on a NAP-compatible client (Microsoft Windows 8, Windows 7, Windows
Vista, Windows XP SP3, Windows Server 2008), use:
ClearPass Windows Universal System Health Validator.
Configurable checking for present/absent Registry Keys,
Services and processes, and product-/version-/update- specific checking for Antivirus, Antispyware, and Firewall
applications. Checks for peer-to-peer applications or networks, patch management applications, hotfixes, USB
devices, virtual machines, and network devices.
l
If you have ClearPass Linux NAP Agent running on a Linux client (CentOS, Fedora, Red Hat Enterprise Linux,
SUSE Linux Enterprise Desktop), use:
ClearPass Linux Universal System Health Validator.
Configurable checking for present/absent Services, and
product-/version-/update- specific checking for Antivirus application, and Firewall configuration.
l
If you have a Microsoft NAP Agent running on the client, use:
n
Windows System Health Validator.
Configurable checking for required operating system versions and service
packs.
n
Windows Security Health Validator.
Configurable checking for Antivirus/Antispyware/Firewall applications, as
well as automatic updates and security updates.
l
If you have ClearPass OnGuard Agent (dissolvable or persistent) running on the client (Windows 8, Windows 7,
Windows XP SP3, Windows Vista, Windows Server 2008, Windows 2003, SUSE Linux, Redhat Enterprise Linux,
Fedora Linux, CentOS Linux, MAC OS X), use:
n
ClearPass Windows Universal System Health Validator.
Configurable checking for present/absent Registry
Keys and Services, and product-/version-/update- specific checking for Antivirus, Antispyware, and Firewall
applications. Checks for peer-to-peer applications or networks, patch management applications, hotfixes, USB
devices, virtual machines, and network devices.
n
Windows System Health Validator.
Configurable checking for required operating system versions and service
packs.