Configuring Fail Open

You can configure fail open for errors that can prevent the retrieval of posture token from an upstream NAC server. If fail open is not configured, the user request is rejected.

You can select whether to enable fail open for:

• Audit Server—for profiles that are associated with an audit server

• External Posture Validation Server—for profiles that are associated with an External Posture Validation Server

If you enable fail open, you will need to select the posture token to be granted when an error occurs in the initial authentication.

To configure fail open for an audit server:

Step 1 Choose Network Access Profiles.

Step 2 Choose Posture Validation for the selected profile.

The Posture Validation Page appears. Step 3 Choose Select Audit.

The Select External Posture Validation Audit for Profile Page appears. Step 4 To enable fail open, check the Do Not reject when Audit failed check box. Step 5 Select the posture token to be used in the event of a failure. Step 6 Enter a value for session-timeout for the audit server. Step 7 Click Submit.

To configure fail open for an external posture validation server:

Step 1 Choose Network Access Profiles.

Step 2 Choose Posture Validation for the selected profile.

The Posture Validation Page appears.

Step 3 Select the Rule Name. To configure a rule, see Configuring Posture-Validation Policies, page 15-35.

Step 4 On the Posture Validation Rule for Profile page, check the check box in the Select column for the external posture validation server that you want to configure.

Step 5 Do one of the following:

• Check Reject User to deny access for fail open.

• In the Failure Posture Assessment field, select:

- Credential Type—The namespace for the APT which replaces the APT that should have been returned from the failed server.

- Posture Token—The posture token to be used in the event of a failure. Step 6 Click Submit.

Select External Posture Validation Audit for Profile Page

This page contains:

Field

Description

Select

Click the radio button to select the external posture-validation audit server. Click Do Not Use Audit Server radio button if you do not want to use an audit server for posture validation.

Fail Open Configuration

Configure this option for any errors that might occur that prevent the retrieval of posture token from an upstream NAC server. If fail open is not configured, the user request is rejected.

Do not reject when Audit failed

Check this check box to enable fail open. The default is checked.

Use this token when unable to retrieve posture data

Select a token from the drop-down list.

Timeout

Set the timeout for the session granted.

Continue reading here: Cisco IOS Dictionary of Radius Ietf

Was this article helpful?

0 0