Quarantine System Posture Token for a policy violation, he will be mapped to the Quarantine_Engineering_RAC (VLAN14). This allows for scalability and granularity.

Figure 5-14 Shared RADIUS Authorization Components

In our scenario, we list the Cisco Trust Agent (Cisco:PA) and the Security Compliance Manager agent (IBM Corporation:SCM) as our posture validation policies. Thus in all, three pieces of information are used to make the access decision:

￿IEEE 802.1x authentication (User Group Mapping)

￿The Security Compliance Manager policy version

￿The Security Compliance Manager posture policy violation count

Chapter 5. Solution design 113

Page 131
Image 131
IBM Tivoli and Cisco manual Shared Radius Authorization Components