Designing Access Controls
Choose Endpoint Integrity Testing Methods
Advantages and Disadvantages of ActiveX Testing
The ActiveX agent does not remain on the endpoint and does not require maintenance or
However, while the NAC agent requires a
Internet Explorer must be open for the NAC 800 to test the endpoint. If a user closes Internet Explorer after his or her endpoint has gained access, the NAC 800 cannot retest the endpoint. The user can continue to connect to the
Agentless
RPC was designed to provide a flexible framework for a variety of communi- cations between remote devices. The NAC 800 uses RPC to run integrity checks on endpoints, which must support RPC.
In order for an endpoint to accept the RPC messages, the NAC 800 must submit credentials for an administrator of that endpoint. On the NAC 800, these credentials are called agentless credentials and can be:
■Configured in cluster
■Submitted by the
C a u t i o n | Never make agentless testing the only method available to test |
| members. Because you will not know the administrator credentials for these |
| endpoints, agentless testing will not succeed. Depending on your configura- |
| tion, the user will probably be placed in a test or quarantine VLAN. |
|
|