Specifications

Policy Server for Cisco NAC
10-17
Synchronization
Regularly synchronize the Policy Server with registered OfficeScan servers to keep the
Policy Server versions of the Virus Pattern, Virus Scan Engine, and server outbreak
status (normal mode or outbreak mode) up-to-date with those on the OfficeScan server.
Use the following methods to perform synchronization:
Manually: Perform synchronization at any time on the Summary screen (see
Summary Information for a Policy Server on page 10-36).
By schedule: Set a synchronization schedule (see Administrative Tasks on page
10-39).
Certificates
Cisco NAC technology uses the following digital certificates to establish successful
communication between various components:
TABLE 10-46. Cisco NAC certificates
CERTIFICATE DESCRIPTION
ACS certifi-
cate
Establishes trusted communication between the ACS server
and the Certificate Authority (CA) server. The Certificate
Authority server signs the ACS certificate before you save it
on the ACS server.
CA certificate Authenticates OfficeScan clients with the Cisco ACS server.
The OfficeScan server deploys the CA certificate to both the
ACS server and to OfficeScan clients (packaged with the
Cisco Trust Agent).
Policy Server
SSL certifi-
cate
Establishes secure HTTPS communication between the Policy
Server and ACS server. The Policy Server installer automati-
cally generates the Policy Server SSL certificate during Policy
Server installation.
The Policy Server SSL certificate is optional. However, use it
to ensure that only encrypted data transmits between the Pol-
icy Server and ACS server.