IBM Tivoli and Cisco User Manual page 36

Building a network access control solution with ibm tivoli and cisco systems
Table of Contents

Advertisement

Port details and communication flows between Security Compliance Manager
server and client can be found in "Security Compliance Manager server and
client" on page 450.
Details of the activities performed by server and client include:
Security Compliance Manager server
– Provides an interface for defining complex policies that specify conditions
– Manages
– Determines
– Stores the security compliance data received from the clients in a central
– Provides security violation details as a basis for the compliance report
Security Compliance Manager client
– Collects information about its environment required to assess compliance
– If enabled for NAC, the client performs a local compliance assessment
– Receives the network admission decision from either the Cisco Secure
– On user request, it can initiate an automated remediation process.
More information about Tivoli Security Compliance Manager can be found in the
IBM Redbook Deployment Guide Series: IBM Tivoli Security Compliance
Manager, SG24-6450.
18
Building a Network Access Control Solution with IBM Tivoli and Cisco Systems
that should exist on a client.
when
the security compliance data is collected and which clients
collect what kind of data using the data collection components.
what
security compliance data is collected, and how to
interpret the data using the compliance management components.
database and provides the available data to users through the
administration console and administration commands.
components.
with the security policy at a predefined schedule. Using different
collectors
, this data is sent back to the Security Compliance Manager
posture collectors
server. With new
Manager Fix Pack 2, the data is stored locally in a posture cache.
using the security policy based on the data from the posture cache. It then
provides the posture assessment data to the Cisco Trust Agent via posture
plug-in for further processing.
Access Control Server (ACS) via Cisco Trust Agent (in case of using the
NAC Framework solution) or the Clean Access Server (CAS) via the Clean
Access Agent (in case of using the NAC Appliance solution) and presents
current status information using a GUI. It displays the compliance status
and posture data, and enables re-initiating the compliance scanning
process.
introduced with Security Compliance

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network access control solution

Table of Contents