Cisco NAC Appliance Agent Cisco NAA The Cisco NAA software resides on

Microsoft Windows systems and can verify if an application or service is running and if a registry key exists or if the value of a registry key is known. The Cisco NAA is referred to as a read-only agent; the Cisco NAA does not alter client system information, but reads the information and reports this information to the Cisco NAC Appliance Manager (Cisco NAM). The Cisco NAA ensures that, for example, a corporate laptop has an up-to-date configuration of the standard corporate software before the laptop is allowed to access the corporate network. The Cisco NAA can ensure that users install the resources necessary to keep their machines from becoming vulnerable or infected.

The Cisco NAA is included as part of the Cisco NAM software. When the Cisco NAM is installed, the Cisco NAA setup executable file is already present and is automatically published from the Cisco NAM to the Cisco NAC Appliance Servers (Cisco NASs). To distribute the Cisco NAA to clients, set up the Cisco NAA in the web administration console for the desired user role and operating system.

4-4 Implementing Cisco NAC Appliance (CANAC) v2.1 © 2007 Cisco Systems, Inc.

■ Network scanner: Network scans are implemented with Nessus plug-ins. Nessus is an open-source vulnerability scanner. Nessus plug-ins test client systems for security vulnerabilities over the network. If a system is scanned and found to be vulnerable or infected, Cisco NAC Appliance takes immediate action by alerting vulnerable users. Cisco NAC Appliance either blocks vulnerable users from the network or assigns users to a quarantine role in which they can fix their systems. When new Nessus plug-ins are released, they can be loaded into the Cisco NAM repository. The Cisco NAM distributes new plug-ins to the Cisco NASs. The Cisco NASs then perform client scanning using the latest vulnerability protection code.

■ Cisco NAC Appliance certification: Client devices that meet the configured Cisco NAC Appliance requirements are considered certified devices and are added to the certified devices list. A certified device remains on the certified devices list until one of these events takes place:

— The administrator manually removes the client from the list.

— The administrator manually clears the entire list.

— The list is automatically cleared using the certified devices timer.

When the client is taken off the certified devices list, the client must go through the Cisco NAC Appliance authentication process again to be readmitted to the network. You can add floating devices to the certified devices list that are certified only for the duration of a user session. Alternatively, you can exempt devices from the Cisco NAC Appliance certification process altogether by manually adding them to the certified list.

■ Role-based configuration: Cisco NAC Appliance network protection features are configured for users by role and by operating system. There are two types of roles specifically used by Cisco NAC Appliance. These roles are intended as temporary roles that offer users limited network access in order to fix their systems:

— Quarantine role: A user is put in the quarantine role after failing a network scan such as a Nessus plug-in check.

— Cisco NAA temporary role: A user is put in the temporary role when the machine is running the Cisco NAA and fails a required check (for example, a registry check).

When a user authenticates, either through the web login page or through the Cisco NAA, Cisco NAC Appliance determines the role of the user. After the user role is determined, Cisco NAC Appliance verifies that the requirements are met and performs the network scanning that is configured for that role and operating system.

The user role is determined immediately after the initial login to determine the scans or system requirements associated with that user. The user is not put into a normal login role until all requirements are met, scanning has occurred, and no vulnerabilities are found. If the client has not met requirements, the user stays in the Cisco NAA temporary role until requirements are met or the session times out. If the user has met requirements but is found with network scanning vulnerabilities, the user can be either assigned to a quarantine role or blocked, depending on the configuration for that role and operating system.

© 2007 Cisco Systems, Inc. Cisco NAC Appliance Implementation Options 4-5

Cisco NAC Appliance can be implemented on a network in three ways:

1. Network scanning only

2. Cisco NAA only

3. Cisco NAA with network scanning

© 2007 Cisco Systems, Inc. All rights reserved. CANAC v2.1—4-3

You can implement Cisco NAC Appliance on a network in these three ways:

■ Network scanning only: This method provides network-based vulnerability assessment and web-based remediation. The network scanner in the local Cisco NAS performs the actual network scanning and checks for well-known port vulnerabilities that a particular host may be prone to. If vulnerabilities are found, web pages that are configured in the Cisco NAM are available to distribute links to websites to the user or to provide information on how users can fix vulnerabilities in their systems.

■ Cisco NAA only: This method provides local machine agent-based vulnerability assessment and remediation. Users must download and install the Cisco NAA. The Cisco NAA allows for visibility into the host registry, process checking, application checking, and service checking. The Cisco NAA can be used to distribute links to websites or upload files to the Cisco NAM that users can access to fix vulnerabilities in their systems.

■ Cisco NAA with network scanning: This method combines the benefits of the Cisco NAA, Cisco NAS, and Cisco NAM. The Cisco NAA provides visibility into the host registry, process checking, application checking, and service checking. The Cisco NAS provides network scanning and port vulnerability checks. The Cisco NAM provides web-based remediation on how users can fix vulnerabilities in their systems.

4-6 Implementing Cisco NAC Appliance (CANAC) v2.1 © 2007 Cisco Systems, Inc.

Continue reading here: Loading Nessus Plug Ins Manually

Was this article helpful?

0 0