HP Access Control Client Software manual Figure A-6. HRA Network Access

Models: Access Control Client Software

1 338
Download 338 pages 18.69 Kb
Page 323
Image 323

Addendum to the ProCurve Access Control Security Design Guide

Microsoft NAP

Figure A-6. HRA Network Access

1.The NAP client connects to the HRA over HTTP or HTTPS, sends a SSoH, and requests a certificate.

2.The HRA sends the client’s SSoH to the NPS over RADIUS.

3.The NPS performs a system health validation and sends its verdict to the HRA.

If the client’s SSoH is not up to requirements, the NPS denies permission to the endpoint and sends remediation instructions through the HRA. Without a certificate, the endpoint can only communicate with other non- compliant endpoints and with servers in the boundary network. These servers can help remediate the endpoint so that it can become healthy.

4.If the NPS has given the endpoint permission to connect, the HRA requests a certificate from a CA over HTTP or HTTPS.

5.The CA sends the certificate to the HRA.

6.The HRA sends the certificate to the endpoint. The endpoint can now communicate with the rest of the network.

A-19

Page 323
Image 323
HP Access Control Client Software manual Figure A-6. HRA Network Access