1-18
Overview of the ProCurve NAC 800
Endpoint Integrity
An endpoint integrity solution automates the process of checking whether an
endpoint meets security standards, and it enforces the standards—imposing
penalties if an endpoint fails the integrity check. The ProCurve NAC 800
provides such a solution.
Endpoint Integrity Capabilities of the NAC 800
The NAC 800 supports endpoint integrity as follows:
■
When it detects a new endpoint, it subjects it to a series of tests to ensure
that the endpoint meets your organization’s security policies.
■
It handles endpoints according to the results of these tests:
•
It allows “healthy” endpoints (those that pass all tests) full access.
•
It takes action against endpoints that fail tests, quarantining them
immediately or granting them temporary access, as you choose.
•
It allows quarantined endpoints to reach “accessible services,” which
help in remediation.
The following sections describe the components of the endpoint integrity
solution in more detail.
NAC Tests
The NAC 800 supports many different tests; each test checks for a particular
setting or component on an endpoint. For example, the Windows XP hotfixes
test checks the patches and updates installed on a Windows XP station. And
the IE Internet Security Zone test checks the security level that the endpoint’s
IE browser enforces for Internet Web sites.
The NAC 800 can also integrate with Microsoft Systems Management Software
(SMS) for patch management. If an endpoint requires a patch, NAC 800
contacts SMS to ensure that the patch has been applied.
Tests are organized into the following categories:
■
Security Settings—Windows
These tests examine an endpoint’s security settings, checking, among
other settings:
•
Enabled services
•
Networks to which the endpoint connects
•
Security settings for macros
•
Local security settings, which determine how users are allowed to
access the endpoint
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......