Specifications
9-30
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 9 Configuring Cisco NAC Appliance for Agent Login and Client Posture Assessment
Setting Up Agent Distribution/Installation
Table 9-8 HTTP Discovery Customization
Parameter
Default
Value
(Sec-
onds)
Valid
Range Description/Behavior
HttpDiscoveryTimeout 30 3 and
above
The default timeout is 30 seconds. This is the time for
which the HTTPS discovery from Agent waits for the
response from Clean Access Server. If there is no
response for the specified time, then the discovery is
timed out.
The minimum value that can be set is 3. If the value is
set to 1 or 2, the timeout is recognized as 3 seconds.
If this value is set to zero (0), then the Windows default
timeout settings are used.
Note In Cisco NAC Appliance 4.9 and later, the
HTTPS discovery from Agent checks the
network every 30 minutes. In the previous
releases, the HTTPS discovery would stop
checking after 30 minutes and would resume
only when there is a change in the network.
HttpTimeout 120 3 and
above
The default timeout is 120 seconds. This is the time for
which the HTTP request from Agent waits for the
response. If there is no response for the specified time,
the request is timed out.
The minimum value that can be set is 3. If the value is
set to 1 or 2, the timeout is recognized as 3 seconds.
If this value is set to zero (0), then the Windows default
timeout settings are used. If the value is less than zero
(0), the timeout is set to 120 seconds.
Note HttpTimeout is applied only to posture HTTP
communications.
Table 9-9 Access to Authentication VLAN Change Detection on Clients with Multiple Active
NICs
Parameter
Default
Value
(Decimal)
Valid
Range Description/Behavior
RetryDetection 3 0 and
above
If ICMP or ARP polling fails, this setting configures the
Agent to retry <x> times before refreshing the client IP
address.
PingArp
1
00-2• If this value is set to 0, poll using ICMP.
• If this value is set to 1, poll using ARP.
1
• If this value is set to 2, poll using ICMP first, then
(if ICMP fails) use ARP.