Fig. 1–2Client-Server actions during connection, health validation and assigning network access

Client connection

Health state change

 

 

Server action

Client action

to server

 

 

Client

User

 

 

 

 

 

mode

 

 

 

 

 

 

Local

 

 

 

 

 

 

Machine

 

 

 

 

 

 

Client collects and sends

 

 

 

 

 

 

user & system information

 

 

 

 

 

 

to Access Control Service

 

 

 

 

User Information

 

 

 

 

 

Matching

Yes

Health condition

Yes

 

matching

 

 

 

Identity?

 

 

 

 

 

 

requirements?

 

 

 

 

 

 

exception

 

No

 

 

 

 

No Rule

 

 

 

 

 

Automatic

No

Already in

 

Yes

 

revalidation

 

probation?

 

 

 

(configurable)

 

 

 

 

 

 

Health state change to

Health state change to

 

Health state change to

Health state change to

Untrusted

Unhealthy: Probation

 

Unhealthy: Restricted

Healthy

Access Ctrl Service sends

Access Control Service sends

Access Ctrl Service sends

Access Ctrl Service sends

ACTION Get policy

probation actions

 

 

ACTION Activate policy

ACTION Get policy

attributes for Untrusted

to client

 

 

attributes for Quarantine

attributes for Healthy

Untrusted policy

Probation actions

 

 

 

Quarantine policy

Healthy policy

attributes requested

 

 

 

attributes activated

attributes requested

executed by client

 

 

 

and activated by client

 

 

 

by client

and activated by client

 

 

 

 

Access according to

Access rights

 

 

 

Restricted access

Full access

configured "Untrusted"

 

 

 

to Quarantine

according to

remain unchanged

 

 

 

rights profile

 

 

 

network segment

client profile

 

 

 

 

10 Introduction

Page 12
Image 12
Barracuda Networks VERSION SP4 manual Healthy, Probation actions