Dell Powerconnect W-ClearPass Hardware Appliances W-ClearPass Policy Manager 6 - Page 205

Built-In Audit Servers, Adding Auditing to a Policy Manager Service, Table 109

Page 205 highlights

Built-In Audit Servers When configuring an audit as part of an Policy Manager Service, you can select the default Nessus ([Nessus Server]) or NMAP ([Nmap Audit]) configuration. Adding Auditing to a Policy Manager Service 1. Navigate to the Audit tab l To configure an audit server for a new service (as part of the flow of the Add Service wizard), navigate to Configuration > Services. Select the Add Services link. In the Add Services form, select the Audit tab. NOTE: You must select the Audit End-hosts check box on the Services tab in order for the Audit tab to display. l To modify an existing audit server, navigate to Configuration > Posture > Audit Servers, then select an audit server from the list. 2. Configure auditing Complete the fields in the Audit tab as follows: Figure 172: Audit Tab Table 109: Audit Tab Parameter Description Audit Server/Add new Audit Server Select a built-in server profile from the list: l The [Nessus Server] performs vulnerability scanning. It returns a Healthy/Quarantine result. l The [Nmap Audit] performs network port scans. The health evaluation always returns Healthy. The port scan gathers attributes that allow determination of Role(s) through post-audit rules. NOTE: For Policy Manager to trigger an audit on an end-host, it needs to get the IP address of this end-host. The IP address of the end-host is not available at the time of initial authentication, in the case of 802.1X and MAC authentication requests. Policy Manager has a built-in DHCP snooping service that can examine DHCP request and response packets to derive the IP address of the endhost. For this to work, you need to use this service, Policy Manager must be configured as a DHCP "IP Helper" on your router/switch (in addition to your main DHCP server). Refer to your switch documentation for "IP Helper" configuration. To audit devices that have a static IP addresss assigned, it is recommended that a static binding between the MAC and IP address of the endpoint be created in your DHCP server. Refer to your DHCP Server documentation for configuring such static bindings. Note that Policy Manager does not issue IP address; it just examines the DHCP traffic in order to derive the IP address of the end-host. Dell Networking W-ClearPass Policy Manager 6.0 | User Guide 205

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372

Built-In Audit Servers
When configuring an audit as part of an Policy Manager Service, you can select the default Nessus (
[Nessus Server
])
or NMAP (
[Nmap Audit]
) configuration.
Adding Auditing to a Policy Manager Service
1.
Navigate to the
Audit
tab
l
To configure an audit server for a new service (as part of the flow of the Add Service wizard), navigate to
Configuration > Services
. Select the
Add Services
link. In the
Add Services
form, select the
Audit
tab.
NOTE: You must select the
Audit End-hosts
check box on the
Services
tab in order for the
Audit
tab to display.
l
To modify an existing audit server, navigate to
Configuration > Posture > Audit Servers
, then select an
audit server from the list.
2.
Configure auditing
Complete the fields in the
Audit
tab as follows:
Figure 172:
Audit Tab
Table 109:
Audit Tab
Parameter
Description
Audit
Server/Add
new Audit
Server
Select a built-in server profile from the list:
l
The
[Nessus Server]
performs vulnerability scanning. It returns a Healthy/Quarantine result.
l
The
[Nmap Audit]
performs network port scans. The health evaluation always returns
Healthy
.
The port scan gathers attributes that allow determination of Role(s) through post-audit rules.
NOTE:
For Policy Manager to trigger an audit on an end-host, it needs to get the IP address of this
end-host. The IP address of the end-host is not available at the time of initial authentication, in the
case of 802.1X and MAC authentication requests. Policy Manager has a built-in DHCP snooping
service that can examine DHCP request and response packets to derive the IP address of the end-
host. For this to work, you need to use this service, Policy Manager must be configured as a DHCP
“IP Helper” on your router/switch (in addition to your main DHCP server). Refer to your switch
documentation for “IP Helper” configuration.
To audit devices that have a static IP addresss assigned, it is recommended that a static binding
between the MAC and IP address of the endpoint be created in your DHCP server. Refer to your
DHCP Server documentation for configuring such static bindings.
Note that Policy Manager does not issue IP address; it just examines the DHCP traffic in order to
derive the IP address of the end-host.
Dell Networking W-ClearPass Policy Manager 6.0 | User Guide
205