Specifications
10-57
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 10 Cisco NAC Appliance Agents
Mac OS X Cisco NAC Agent
g. Error—When an error occurs (for example, if the client cannot validate the CAS certificate,
sees an invalid CAS certificate, or domain name resolution fails) the status icon changes to the
exclamation point (!) icon.
14. Following user log in, if any mandatory or optional requirements fail, the user is assigned to the
default Temporary role and sees the Assessment Report window (see Figure 10-67) containing the
following information for each requirement in the report:
–
Run—This column either contains a checkbox that the user can choose to check or leave
unchecked (if the requirement is optional), or a “grayed-out” checkbox (if the requirement is
mandatory). This enables the user to select the optional requirements to remediate before
clicking the Remediate button to address all requirements listed in the Assessment Report
window.
–
Name—This is the name of the requirement the administrator configures on the CAM.
–
Description—This field contains text from the “Description” field the administrator enters in
the CAM when configuring the requirement to provide information/explanation.
–
Type (icons)—The icons in this column denote the requirement type (“Link,” “Update,” or
“Message”).
–
Required—Specifies whether the requirement is Mandatory or Optional.
If there are Mandatory requirements associated with the user login session that do not pass
upon posture assessment, the Mac OS X Agent automatically displays the Assessment Report
dialog after the user enters login credentials.
If the only requirements that fail are Optional requirements, the Agent still displays the
Assessment Report dialog to the user, but they are allowed to click the Complete button and
successfully log in to the network. (In this situation, the Agent assumes that all Mandatory
requirements (if any) have passed and the user has a choice to remediate or log in.)
Note Audit requirements are always checked/verified in the background and do not appear in
the user-facing Assessment Report window with “failed” mandatory or optional
requirements.
–
Status (icons)—Displays the current status of the requirement type in the report dialog. When
an assessment dialog first opens, all of the requirement types in the report are “failed” (denoted
by an “X” icon). As the user addresses each requirement in turn, the status icons can change to
“passed” (denoted by a checkmark icon), or “Skip” in the case of optional requirement types or
mandatory requirements that the user could not remediate at that time.
Note If a user chooses to “Skip” a mandatory requirement, they are able to progress through
and address the other requirement types/entries in the Assessment Report, but cannot
log into the network until they have successfully remediated their client machine and
passed all of the mandatory requirements. (See Figure 10-70.)
The Assessment Report window also displays the time remaining (in the upper right corner) before
the Agent Temporary role expires and the client remediation window closes, requiring the user to
log in and resume remediation again.