The system used by ABBC for the Security Compliance Manager server is:

￿Windows 2003 Server Enterprise Edition with SP1 installed

￿Pentium® IV @ 3.0Ghz CPU

￿512 MB of system memory

￿3 GB of free disk space

IBM Tivoli Security Compliance Manager client

The required IBM Security Compliance Manager client software is Version 5.1.1 (also known as 5.1.0 Fix Pack 30). This version contains the DLLs required to enable the Cisco integration.

With this version the client and server components are using different Java runtime environment versions and the installation packages for Security Compliance Manager server and Security Compliance Manager client components were separated. Although Security Compliance Manager supports many platforms as clients, the Cisco Trust Agent supports only Windows and Linux systems at this time.

Note: There are specific sequence requirements for the installation of the Cisco Trust Agent, the Security Compliance Manager client code. Refer to 6.3, “Deploying the client software” on page 189, for full details.

The system used by ABBC for the Security Compliance Manager client is:

￿Windows XP professional with SP2 installed

￿Pentium IV @ 3.0Ghz CPU

￿512 MB of system memory

￿3 GB of free disk space

Network Admission Control subsystem

The Network Admission Control (NAC) subsystem has three components:

￿The Access Control Server (ACS)

￿A NAC-enabled network device (for example, a switch)

￿The Cisco Trust Agent with or without IEEE802.1x supplicant

Find additional information and individual component descriptions in 3.1.1, “Network Admission Control” on page 41. In this section we provide more details for each of the components as they relate to this solution implementation.

Access Control Server

The IBM Integrated Security Solution for Cisco Networks requires Version 4.0 of the Cisco Secure ACS. Detailed specifications follow.

118Building a Network Access Control Solution with IBM Tivoli and Cisco Systems

Page 136
Image 136
IBM Tivoli and Cisco manual Network Admission Control subsystem, IBM Tivoli Security Compliance Manager client