1-26
Overview of the ProCurve NAC 800
Endpoint Integrity
Requirements for NAC Agent Testing.
The agent must be installed on the
endpoint. For the NAC 800 to download the agent to endpoints automatically,
the endpoints must allow ActiveX content from the NAC 800.
Otherwise, either the IT staff or the user must install the NAC agent on the
endpoint before the user attempts to connect to the network.
If a router lies between the NAC 800 and the endpoints, the router must keep
port 1500 open. In most cases, the NAC 800 can automatically open the correct
ports through the endpoints’ firewall.
N o t e
This rule has one exception. You must open port 1500 on an endpoint that
meets these three conditions:
■
Is unmanaged
■
Runs Windows XP
■
Uses a non-SP2 firewall such as Norton
Advantages and Disadvantages of NAC Agent Testing.
The NAC agent
can be installed on any Windows station capable of being tested (OS
version 2000 or higher). Once installed, the NAC agent allows the NAC 800 to
test the endpoint in the background at any time. In addition, the NAC agent
automatically receives updates from the NAC 800. Finally, the NAC 800 can
test an endpoint through its firewall, generally opening the necessary ports
automatically.
However, the NAC agent does require the initial setup and user interaction
described above.
ActiveX
When using the ActiveX method, the NAC 800 automatically downloads and
installs the ActiveX agent on the endpoint to be tested. Unlike the NAC agent,
after the check is complete, the ActiveX agent is removed from the endpoint.
Requirements for ActiveX Testing.
The ActiveX agent uses ActiveX con-
tent and Java script. The endpoint’s browser security settings must allow such
content from the NAC 800.
ActiveX testing requires the endpoint’s Web browser to be open for every test.
The Web browser must be IE version 6.0 or later.
If a router lies between the NAC 800 and the endpoints, it must keep port 1500
open. In most cases, the NAC 800 can automatically open the correct ports
through the endpoints’ firewall.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......