Specifications

9-96
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 9 Configuring Cisco NAC Appliance for Agent Login and Client Posture Assessment
Configuring Agent-Based Posture Assessment
Figure 9-49 Optional/Audit Requirement
Step 2 Choose a Requirement Type from the dropdown.
Step 3 Choose Optional (do not enforce) or Audit (silent assessment) as the Enforce Type from the dropdown
menu.
For an Optional requirement, the user is informed of the requirement but can bypass it if desired (by
clicking Next/Skip in the Agent dialog). The client system does not have to meet the requirement for the
user to proceed or have network access. For an Audit requirement, the system generates audit reports,
but no user dialogs appear on the client machine and the user’s network access is unaffected.
Step 4 Choose the Priority of execution for this requirement on the client. A high priority (e.g. 1) means this
requirement is checked on the system ahead of all other requirements (and appears in the Agent dialogs
in that order). Note that if a Mandatory requirement fails, the Agent does not continue past that point
until that requirement succeeds.
Note The Mac OS X Agent does not support automatic remediation. Therefore, the Remediation functions that
appear on the New Requirement configuration page (Remediation Type, Interval, and Retry Count) do
not serve any purpose when creating requirement types for Macintosh client remediation.
Step 5 If you want to enable and configure Auto Remediation for the Agent:
a. Choose the Remediation Type [Manual | Automatic] from the dropdown menu. Choosing Manual
preserves previous Agent behavior. The user has to click through each of the requirements using the
Next/Skip button in the Agent. Choosing Automatic sets the Agent to perform Auto Remediation,
where the Agent automatically performs updates or launches required programs on the client after
the user logs in.
b. If you configure the requirement to use automatic remediation, specify the Interval in seconds (the
default interval is 0). Depending on the requirement type, this interval either sets the delay before
the Agent re-attempts remediation or sets the total time allowed for a particular remediation process.