
Designing Access Controls
Choose Endpoint Integrity Testing Methods
In this case, your choice of testing methods is limited to ActiveX because the requirements for ActiveX are less stringent. The browser must be configured to allow JavaScript and ActiveX. (If Windows XP endpoints are running a non- SP2 firewall, port 1500 must be opened. By default, the Windows XP firewall opens port 1500.)
If you have more control over endpoints, you can require users to download and run the NAC EI agent. For the endpoints in a Windows domain, you can supply the admin credentials and use the agentless test method.
Table
Table 3-44. Testing Method by Control over Endpoints
Agentless | ActiveX | NAC EI Agent |
|
|
|
Admin control needed | High | Low to medium |
Requirements | • Admin credentials for | • Browser security settings |
| each endpoint must be | must allow JavaScript and |
| known. | ActiveX scripting. |
| • File and print sharing must | • Port 1500 may need to be |
| be enabled. | opened manually on the |
| • RPC service must be | endpoint.* |
| enabled. |
|
| • Ports 137, 138, 139, and 445 |
|
| must be opened on the |
|
| firewall. |
|
Medium to high
•All endpoints must have the agent installed.
•Port 1500 may need to be opened on the endpoint.*
•ActiveX controls must be allowed on the endpoint.
* Only on unmanaged endpoints that run Windows XP with
Example. At PCU, network administrators have some influence over staff and faculty
The network administrators can ask students, faculty, and staff members to download the NAC EI agent. On other endpoints, ActiveX is a more realistic option, although guests might allow the NAC EI agent to install automatically.
Table 3-45. Testing Method by Administrative Control
Factor | Public Wired | Private Wired | Public Wireless | Private Wireless | Remote |
Administrative control | ActiveX | Agentless | ActiveX | NAC EI agent | ActiveX |
| NAC EI agent | NAC EI agent | NAC EI agent | ActiveX | NAC EI agent |
|
|
|
|
|
|