background image

Component

Service:
component ratio

Description

installed agent, or which cannot respond to Policy Manager
interactions. Audit servers typically operate in lieu of
authentication methods, authentication sources, internal
posture policies and posture server.

In addition to returning posture tokens, Audit Servers can
contain post-audit rules that map results from the audit into
Roles.

G

- Enforcement Policy

One per service
(mandatory)

Policy Manager tests Posture Tokens, Roles (and system time)
against Enforcement Policy rules to return one or more
matching Enforcement Policy rules to return one or more
matching Enforcement Profiles (that define scope of access
for the client).

H

- Enforcement Profile

One or more per
service

Enforcement Policy Profiles contain attributes that define a
client's scope of access for the session. Policy Manager
returns these Enforcement Profile attributes to the switch.

4

Dell Networking W-ClearPass Policy Model 6.0 | An Introduction

Summary of Contents for Powerconnect W-ClearPass Hardware Appliances

Page 1: ...s Requests Requests against available Services to provide robust differentiation of requests by access method location or other network vendor specific attributes NOTE Policy Manager ships configured with a number of basic Service types You can flesh out these Service types copy them for use as templates import other Service types from another implementation from which you have previously exported...

Page 2: ...EAP non tunneled EAP TLS or EAP MD5 l Non EAP non tunneled CHAP MS CHAP PAP or MAC AUTH l MAC_AUTH must be used exclusively in a MAC based Authentication Service When the MAC_AUTH method is selected Policy Manager 1 makes internal checks to verify that the request is indeed a MAC Authentication request and not a spoofed request and 2 makes sure that the MAC address of the device is present in the ...

Page 3: ...cy Manager evaluates Requests against Role Mapping Policy rules to match Clients to Role s All rules are evaluated and Policy Manager may return more than one Role If no rules match the request takes the configured Default Role Some Services for example MAC based Authentication may handle role mapping differently l For MAC based Authentication Services where role information is not available from ...

Page 4: ...les G Enforcement Policy One per service mandatory Policy Manager tests Posture Tokens Roles and system time against Enforcement Policy rules to return one or more matching Enforcement Policy rules to return one or more matching Enforcement Profiles that define scope of access for the client H Enforcement Profile One or more per service Enforcement Policy Profiles contain attributes that define a ...

Reviews: