Designing Access Controls

Finalize Security Policies

3.Quarantine—In a network with endpoint integrity, you must create a rule that matches the EI postures Quarantine or Infected with the quarantine access profile. (Typically, the other inputs should be “any” because you always want non-compliant endpoints quarantined.) You must also create a rule for the Unknown posture. Either match that posture to a test access profile or the quarantine access profile. If you want all users to be placed in the same quarantine VLAN, you can create global rules.

Plan your access policy group rules in Table 3-89.

Table 3-89. Access Policy Group Rules

Access Policy

Inputs

 

 

 

 

Outputs—Access Profile

Group

 

 

 

 

 

 

Location

Time

System

WLAN

EI

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Table 3-90presents an example of policy group rules for PCU.

Table 3-90. Sample Access Policy Group Rules for PCU

Access Policy

Inputs

 

 

 

 

Outputs—Access Profile

Group

 

 

 

 

 

 

Location

Time

System

WLAN

EI

 

 

 

 

 

 

 

 

 

 

Global

any

any

any

any

Unknown

Quarantine

 

 

 

 

 

 

 

Global

any

any

any

any

Fail

Quarantine

 

 

 

 

 

 

 

Global

any

any

any

any

Infected

Quarantine

 

 

 

 

 

 

 

IT admin

any

any

any

any

Pass

IT admin

 

 

 

 

 

 

 

President and

any

any

any

PCU

Pass

President, etc.

other

 

 

 

 

 

 

executives

 

 

 

 

 

 

 

 

 

 

 

 

 

Partners and

any

any

any

Guests

Pass

Unencrypted

customers

 

 

 

 

 

 

 

 

 

 

 

 

 

3-116