1-28
Overview of the ProCurve NAC 800
Endpoint Integrity
Requirements for Agentless Testing.
To undergo agentless testing, the
endpoint must make its RPC service available to the NAC 800. The endpoint
must meet these requirements:
■
RPC service supported (native on all testable Windows OS) and activate
■
File and print sharing enabled—On the firewall, ports 137, 138, 139, and
445 are open to the NAC 800
For the user to view all end-user windows, the endpoint’s browser security
settings must allow Java scripting from the NAC 800.
In addition, as discussed above, the NAC 800 requires administrator creden-
tials for the endpoint (typically, those of a domain administrator).
Advantages and Disadvantages of Agentless Testing.
Agentless testing
does not require any installation on the endpoint, so it is easy to deploy and
maintain and involves little administrative overhead. In addition, the testing
can occur—from beginning to end—without user interaction.
However, you must ensure that the endpoints meet the requirements listed
above, and you must know the correct agentless credentials. For these rea-
sons, agentless testing works best on managed endpoints that are members
of your domain.
Endpoint Integrity Posture
As the NAC 800 tests an endpoint, it assigns it an endpoint integrity posture
based on the results of tests:
■
Unknown
—not yet tested
■
Healthy
—passed all tests
■
Check-up
—failed at least one test but allowed temporary access
■
Quarantine
—failed at least one test for which the penalty is quarantining
(and a temporary access period, if allowed, has expired); or was incapable
of being tested (and your network quarantines untestable endpoints)
■
Infected
—infected with malware (failed the Worms, Viruses, and
Trojans test)
Accessible Services
The NAC 800 allows quarantined endpoints to access the limited set of
resources listed on its
Home
>
System configuration
>
Accessible ser-
vices
window. By default, the window lists Web sites from which endpoints
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......