Résumé du contenu de la page N° 1 
                    
                        Front cover
 
Building a Network
Access Control Solution 
with IBM Tivoli and Cisco Systems
Covering Cisco Network Admission 
Control Framework and Appliance
Automated remediation of 
noncompliant workstations
Advanced security 
compliance notification
Axel Buecker
Richard Abdullah
Markus Belkin
Mike Dougherty
Wlodzimierz Dymaczewski
Vahid Mehr
Frank Yeh
ibm.com/redbooks                                                                                                                               
                    
                    Résumé du contenu de la page N° 2 
                    
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            
                    
                    Résumé du contenu de la page N° 3 
                    
                        International Technical Support Organization Building a Network Access Control Solution with  IBM Tivoli and Cisco Systems January 2007 SG24-6678-01                                                                                                                                                                                                                                                                                                                                                                
                    
                    Résumé du contenu de la page N° 4 
                    
                        Note: Before using this information and the product it supports, read the information in  “Notices” on page vii. Second Edition (January 2007) This edition applies to Tivoli Security Compliance Manager V5.1, Tivoli Configuration Manager  V4.2.3, and Cisco Secure ACS V4.0.  © Copyright International Business Machines Corporation 2005, 2007. All rights reserved. Note to U.S. Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp. 
                    
                    Résumé du contenu de la page N° 5 
                    
                        Contents Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vii Trademarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . viii Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .ix The team that wrote this redbook. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x Become a published author .
                    
                    Résumé du contenu de la page N° 6 
                    
                        3.1.1  Network Admission Control. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41 3.1.2  Compliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 3.1.3  Remediation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 3.2  Physical components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 3.2.1  Network client . . . . . . . . . . . . . . . . . . . . . . . . . . . 
                    
                    Résumé du contenu de la page N° 7 
                    
                        6.2.1  Posture collectors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 153 6.2.2  Policy collector . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154 6.2.3  Installation of posture collectors . . . . . . . . . . . . . . . . . . . . . . . . . . . 155 6.2.4  Customization of compliance policies . . . . . . . . . . . . . . . . . . . . . . . 161 6.2.5  Assigning the policy to the clients . . . . . . . . . . . . . . . . . . . . . . . . .
                    
                    Résumé du contenu de la page N° 8 
                    
                        Fault isolation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 448 Security Compliance Manager server and client . . . . . . . . . . . . . . . . . . . . . . 450 Communication port usage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 Tools and tricks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 Cisco NAC. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                    
                    Résumé du contenu de la page N° 9 
                    
                        Notices This information was developed for products and services offered in the U.S.A.  IBM may not offer the products, services, or features discussed in this document in other countries. Consult  your local IBM representative for information about the products and services currently available in your  area. Any reference to an IBM product, program, or service is not intended to state or imply that only that  IBM product, program, or service may be used. Any functionally equivalent product, pro
                    
                    Résumé du contenu de la page N° 10 
                    
                        Trademarks The following terms are trademarks of the International Business Machines Corporation in the United States,  other countries, or both:  Redbooks (logo) ™ DB2 Universal Database™ Redbooks™ developerWorks® DB2® Tivoli® ibm.com® IBM® WebSphere® Access360® NetView® AIX® PartnerWorld® The following terms are trademarks of other companies: Cisco, Cisco Systems, Cisco IOS, PIX, and Catalyst are trademarks of Cisco Systems, Inc. in the United  States, other countries, or both. Java, JVM, J2EE
                    
                    Résumé du contenu de la page N° 11 
                    
                        Preface In February of 2004, IBM® announced that it would be joining Cisco’s Network  Admission Control (NAC) program. In December of 2004, IBM released its first  offering for the Cisco NAC program in the form of the IBM Tivoli® compliance and  remediation solution. In June of 2005 the first edition of this IBM Redbook was  published.  A number of subsequent updates from Cisco have changed the dynamics of the  Network Access Control market, and have led to significant changes by IBM to  our com
                    
                    Résumé du contenu de la page N° 12 
                    
                        The team that wrote this redbook This redbook was produced by a team of specialists from around the world  working for the International Technical Support Organization, Austin Center. The  project was executed at the Cisco Headquarter in San Jose. Figure 1   Top left to right: Frank, Axel, Vahid, and Mike Bottom left to right: Vlodek, Markus, and Rich Axel Buecker is a Certified Consulting Software IT Specialist at the International  Technical Support Organization, Austin Center. He writes exten
                    
                    Résumé du contenu de la page N° 13 
                    
                        Richard Abdullah is a Consulting Engineer with Cisco Systems Strategic  Alliances. Prior to joining Cisco Systems in 2001, he worked in technical  capacities within various service providers. He has spent 19 years in the IT  industry focusing on networking and most recently on network security solutions.  He holds a BSEE degree from the University of Michigan, Dearborn. Markus Belkin is a Network Architect with IBM Australia. He has worked in the  IT Industry for 10 years and works predominately
                    
                    Résumé du contenu de la page N° 14 
                    
                        Thanks to the following people for their contributions to this project: Cheryl Gera, Erica Wazewski, Lorinda Schwarz, Julie Czubik International Technical Support Organization, Poughkeepsie Center Wing Leung, Alex Rodriguez IBM US Tadeusz Treit, Bogusz Piotrowski, Anna Iskra IBM Poland Cindra Ford, Zary Stahl, Nick Chong, Prem Ananthakrishnan, Brendan  O'Connell, Irene Sandler, Raju Srirajavatchavai, Alok Agrawal, Marcia Hanson Cisco Systems Inc. Thanks to following people for working on the fir
                    
                    Résumé du contenu de la page N° 15 
                    
                        Find out more about the residency program, browse the residency index, and  apply online at: ibm.com/redbooks/residencies.html Comments welcome Your comments are important to us! We want our Redbooks™ to be as helpful as possible. Send us your comments  about this or other Redbooks in one of the following ways:  Use the online Contact us review redbook form found at: ibm.com/redbooks  Send your comments in an e-mail to: redbook@us.ibm.com  Mail your comments to: IBM Corporation, International
                    
                    Résumé du contenu de la page N° 16 
                    
                        xiv Building a Network Access Control Solution with IBM Tivoli and Cisco Systems                                                                                                                                                                                                                                                                                                                                                                                                                                    
                    
                    Résumé du contenu de la page N° 17 
                    
                        Summary of changes This section describes the technical changes made in this edition of the book and  in previous editions. This edition may also include minor corrections and editorial  changes that are not identified. Summary of Changes for SG24-6678-01 for Building a Network Access Control Solution with IBM Tivoli and Cisco  Systems as created or updated on January 16, 2007. January 2007, Second Edition This revision reflects the addition, deletion, or modification of new and changed  informa
                    
                    Résumé du contenu de la page N° 18 
                    
                        xvi Building a Network Access Control Solution with IBM Tivoli and Cisco Systems                                                                                                                                                                                                                                                                                                                                                                                                                                    
                    
                    Résumé du contenu de la page N° 19 
                    
                        Part 1 Part 1 Architecture  and design In this part we discuss the overall business context of the IBM Integrated Security  Solution for Cisco Networks. We then describe how to technically architect the  overall solution into an existing environment, and introduce the logical and  physical components on both the IBM Tivoli and Cisco side. © Copyright IBM Corp. 2005, 2007. All rights reserved. 1                                                                                                       
                    
                    Résumé du contenu de la page N° 20 
                    
                        2 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems