Since scenarios 5 and 6 are the most complex, the sequence of events for these scenarios is depicted in Figure 8-43.

Rem ediation U I

statuscheck .exe

TSC M C lient

Sem aphore

TSCM Agent.exe

NAC Appliance Agent

 

N AC Appliance Manager

 

pquery

 

 

 

 

 

 

 

 

Sem aphore=0

 

 

 

 

 

 

Violations>0

 

 

 

 

 

 

 

pnotify

 

 

 

 

 

 

 

 

Sem aphore?

 

 

 

 

 

 

 

Sem aphore=0

 

 

 

 

 

 

Sem aphore=0

 

KickU ser

 

 

 

 

 

 

 

 

 

#5

 

 

 

 

 

 

 

 

 

 

 

 

 

Authenticate

Starts

 

 

 

 

 

 

 

 

 

 

 

Sem aphore?

 

 

here

 

 

 

 

Sem aphore<1

 

 

 

 

 

 

 

 

 

Quarantine

 

 

 

 

 

 

Execute

 

 

 

 

 

 

Sem aphore=-1

 

 

 

 

 

Execute

 

 

 

 

 

 

pquery

 

 

 

 

 

 

 

Violations>0

 

 

 

 

 

 

 

pnotify

 

 

 

 

 

 

 

 

Sem aphore?

 

 

 

 

 

 

Execute

Semaphore=-1

 

 

 

 

 

 

 

 

 

 

 

 

Rem ediate

R escan

 

 

 

 

 

 

 

 

Sem aphore=1

 

 

 

 

 

 

 

 

 

Sem aphore?

 

 

 

 

 

 

 

Sem aphore=1

 

 

 

 

 

 

 

 

 

Admit

 

Figure 8-43 Sequence of Events for Scenarios #5 and #6

￿Scenario 7 - pre-admission, Security Compliance Manager running, compliant client

NAC Appliance restarts admission process.

Security Compliance Manager Client is running and semaphore = 1

Admit client

￿Scenario 8 - post-admission, Security Compliance Manager running, compliant client

In this case, the semaphore should start as 1 since we have been admitted.

Windows Scheduler or cron job runs statuscheck.exe.

Appendix A. Hints and tips 469

Page 487
Image 487
IBM Tivoli and Cisco manual Sequence of Events for Scenarios #5 and #6