background image

Avaya Endpoint Access Control Agent

User’s Guide

5.0

NN47230-501, 03.02

May 2011

Summary of Contents for Endpoint Access Control Agent

Page 1: ...Avaya Endpoint Access Control Agent User s Guide 5 0 NN47230 501 03 02 May 2011...

Page 2: ...OU ON BEHALF OF YOURSELF AND THE ENTITY FOR WHOM YOU ARE INSTALLING DOWNLOADING OR USING THE SOFTWARE HEREINAFTER REFERRED TO INTERCHANGEABLYAS YOU AND END USER AGREE TO THESE TERMS AND CONDITIONS AND...

Page 3: ...s 18 Recovery from initial check failure 20 Avaya EAC Agent additional features 20 Windows 802 1x Supplicant 20 Multi OS Applet Support 20 NAP interoperability 21 Chapter 3 Using the Avaya Endpoint Ac...

Page 4: ...Configuring the Avaya Endpoint Access Control Agent 42 Variable definition 43 Index 45 4 Avaya Endpoint Access Control Agent User s Guide May 2011...

Page 5: ...th network management Before you begin To install and run the Avaya EAC Agent your PC must meet the following minimum requirements Windows XP Vista or Windows 7 200 MHz Pentium 64 MB memory 10 MB free...

Page 6: ...mmand Example If the command syntax is show ip interfaces alerts you can enter either show ip interfaces or show ip interfaces alerts ellipsis points Repeat the last element of the command as needed E...

Page 7: ...VR Avaya VPN Router formerly Nortel VPN Router NVR SNAS Secure Network Access Switch VM Virtual Machine JVM Java Virtual Machine DLL Dynamic link library JRE Java Runtime Environment VPN Virtual Priva...

Page 8: ...e notes see http www avaya com support find the product for which you need documentation then locate the specific category and model or version for your hardware or software product Use Adobe Reader t...

Page 9: ...If you purchased a service contract for your Avaya product from a distributor or authorized reseller contact the technical support staff for that distributor or reseller for assistance Getting technic...

Page 10: ...Introduction 10 Avaya Endpoint Access Control Agent User s Guide May 2011...

Page 11: ...time Environment JRE Selection on page 13 Installation kits on page 13 Avaya EAC Agent additional features on page 20 NAP interoperability on page 21 Avaya EAC Agent The Avaya Endpoint Access Control...

Page 12: ...s agent is installed through the SNAS captive portal as a Java Webstart application on the Windows platform and runs as Windows system tray application The advantages of using the Downloadable EAC Age...

Page 13: ...elect bundled JVM not available for NoVM kit JVM installed on local machine with version greater than or equal to 1 5 0 If you select a bundled JVM a jre directory is installed under the installation...

Page 14: ...You can also to deploy the MSI installer by using Windows Group Policy which is commonly used by IT administrators Note Double clicking the MSI installer directly prompts to exit even if you are an ad...

Page 15: ...tomize installation by changing the title changing the icon or changing the files to be installed Here are examples of how to make some of these changes using ORCA Important All commands are case sens...

Page 16: ...ract the Agent properties from MSI 2 Modify Agent properties according to your requirements 3 Modify MSI file to replace Agent properties under INSTALLDIR resources with the modified file Example of m...

Page 17: ...b cab NhaExeVm msi is now successfully updated with the new files Customizing Login dialog box image To customize the Login dialog box Image use the following steps Procedure steps 1 Create an 100x200...

Page 18: ...t Core EAC Agent Tray Monitor This separation allows the administrator to configure MSI installer to provide customized installer to the end user Avaya EAC Agent Core contains all of the Avaya EAC Age...

Page 19: ...1 The DisableLogging registry location is HKEY_LOCAL_MACHINE Software Avaya EACA No or limited pop up messages The Avaya EAC Agent pops up a dialog window whenever there is an SRS check failure regar...

Page 20: ...pliance checking by the Avaya EAC Agent The Avaya EAC Agent does not engage the SNAS until there is a change in compliance Once the system falls into compliance or the Failure Recovery Mode interval e...

Page 21: ...health state of a network client which attempts to connect to a network and restricts the access of the network client until the policy requirements for connecting to the network are met The SNAS NAP...

Page 22: ...Installing the Avaya Endpoint Access Control Agent 22 Avaya Endpoint Access Control Agent User s Guide May 2011...

Page 23: ...s towards the Avaya EACAgent Avaya EAC Core verifies the rule and returns the health status to the VPN gateway which determines the fail action if necessary If the SRS rule check succeeded required co...

Page 24: ...to green If the rule can t be successfully checked compliance failed the Avaya EAC Agent state changes to New Error Occurred and the icon to green with red color X If an SRS rule fails the user is not...

Page 25: ...The run once mode is applicable only for portal and SPO clients It also prevents session exit due to heartbeat timeout and rechecks Run Once Mode is configured on the VPN gateway Avaya NAP Enforcemen...

Page 26: ...ent to other components of the NAP client architecture Avaya NAP Enforcement Client TheAvaya NAPEnforcement Client is a key component ofAvaya EACAgent It is automatically installed on client s compute...

Page 27: ...ternet Network and Sharing Center and click View Status in the Network Access Protection panel The Network Access Protection dialog shows the security state of the computer Avaya NAP Enforcement Clien...

Page 28: ...ialog box appears 2 Click the Policy tab to view the policy details 3 Click the SNAS Status tab to view the SNAS status 4 Click Clear Logs to clear the logs 5 Click OK to close the Avaya EAC Agent Sta...

Page 29: ...Username and Password fields respectively 3 Click Login 4 The Avaya EAC Agent Applet downloads to the user s machine The SRS rule mapped to the users group is automatically checked 5 If Avaya EAC Age...

Page 30: ...to the portal Periodically Avaya EACAgentApplet checks the SRS rule to determine if the user s computer meets the security policy configured on the gateway Using the Avaya Endpoint Access Control Age...

Page 31: ...of single sign on log on The Avaya EAC Agent collects the log on credentials for each user login to the network domain TheAvaya EACAgent forwards log on credentials to the SNAS server as a part of th...

Page 32: ...e Specifies the user name Password Specifies the password Managing profiles You can create maintain and configure user profiles to log on to SNAS You can also create and maintain system profiles to ch...

Page 33: ...on page 33 modify a user profile Modifying a user profile on page 35 delete a user profile Deleting a user profile on page 35 Creating a user profile Use the following procedure to create a user prof...

Page 34: ...pecifies the unique name assigned to the user profile Use Domain User Information Specifies that the Avaya EAC Agent obtains windows domain username when user log onto the PC Use Profile Defined User...

Page 35: ...EAC Agent icon and select Manage SNAS Profiles The Manage Profiles dialog box appears 2 Click the User Profiles tab 3 Select the profile to be modified 4 Modify the required details 5 Click Save Profi...

Page 36: ...nage the system profiles use the following create a system profile Creating a system profile on page 36 modify a system profile Modifying a system profile on page 38 delete a system profile Deleting a...

Page 37: ...2 Click the System Profile tab 3 Specify the name of the server 4 Click Add The Add New System Id dialog box appears Managing profiles Avaya Endpoint Access Control Agent User s Guide May 2011 37...

Page 38: ...iles dialog box appears 2 Click the System Profile tab 3 Select the server for which you want to modify the details 4 Click Modify The existing credentials appear 5 Modify the details 6 Click OK to sa...

Page 39: ...page 41 delete a global user profile Deleting a global user profile on page 41 Creating a global user profile Use the following procedure to create a global user profile Procedure steps 1 In the Wind...

Page 40: ...ble Value Profile Name Specifies the unique name assigned to the user profile Use Domain User Information Specifies that the Avaya EAC Agent gets the logon credentials from the domain Use Profile Defi...

Page 41: ...dows taskbar notification area right click the Avaya EAC Agent icon and select Manage SNAS Profiles The Manage Profiles dialog box appears 2 Click the Global User Profiles tab 3 Select the profile to...

Page 42: ...ertificates already installed on your desktop in the MSCAPI Certificate stores Note To use MSCAPI Certificates Avaya EAC Agent must be installed with a bundled JRE or with JRE 6 or later For JRE 6 Ava...

Page 43: ...e Avaya EAC Agent Configuration dialog box appears 2 Complete the Avaya EAC Agent configuration details 3 Click OK to save the details Variable definition Use the information in the following table to...

Page 44: ...gent Log Tunnel Up and Down Events Check to log Avaya EAC Agent up and down events Number of recent checking logs shown in status dialog Specifies the total number of checking logs that are displayed...

Page 45: ...Index C conventions text 5 customer service 8 D distributor 9 documentation 8 R reseller 9 T text conventions 5 training 9 Avaya Endpoint Access Control Agent User s Guide May 2011 45...

Page 46: ......

Reviews: