10 Introduction

Fig. 1–2 Client-Server actions during connection, health validation and assigning network access
Client
Client collects and sends
User Information
Matching Health condition
matching
requirements?
mode
user & system information
to Access Control Service
Identity?
Health state change to
Untrusted
Already in
probation?
Access Ctrl Service sends
ACTION Get policy
attributes for Untrusted
Untrusted policy
attributes requested
and activated by client
Access according to
configured "Untrusted"
rights profile
Access Control Service sends
probation actions
to client
Probation actions
executed by client
Access rights
remain unchanged
Health state change to
Unhealthy: Restricted
Access Ctrl Service sends
ACTION Activate policy
attributes for Quarantine
Quarantine policy
attributes activated
by client
Restricted access
to Quarantine
network segment
Health state change to
Healthy
Access Ctrl Service sends
ACTION Get policy
attributes for Healthy
Healthy policy
attributes requested
and activated by client
Full access
according to
client profile
Health state change to
Unhealthy: Probation
YesNo
Yes
No
Yes
No Rule
Health state change Server action Client action
exception
User
Local
Machine
Automatic
revalidation
(configurable)
Client connection
to server