Specifications
Policy Server for Cisco NAC
10-17
Synchronization
Regularly synchronize the Policy Server with registered OfficeScan servers to keep the 
Policy Server versions of the Virus Pattern, Virus Scan Engine, and server outbreak 
status (normal mode or outbreak mode) up-to-date with those on the OfficeScan server. 
Use the following methods to perform synchronization:
• Manually: Perform synchronization at any time on the Summary screen (see 
Summary Information for a Policy Server on page 10-36).
• By schedule: Set a synchronization schedule (see Administrative Tasks on page 
10-39).
Certificates
Cisco NAC technology uses the following digital certificates to establish successful 
communication between various components:
TABLE 10-46.  Cisco NAC certificates
CERTIFICATE DESCRIPTION
ACS certifi-
cate
Establishes trusted communication between the ACS server 
and the Certificate Authority (CA) server. The Certificate 
Authority server signs the ACS certificate before you save it 
on the ACS server. 
CA certificate Authenticates OfficeScan clients with the Cisco ACS server. 
The OfficeScan server deploys the CA certificate to both the 
ACS server and to OfficeScan clients (packaged with the 
Cisco Trust Agent).
Policy Server 
SSL certifi-
cate
Establishes secure HTTPS communication between the Policy 
Server and ACS server. The Policy Server installer automati-
cally generates the Policy Server SSL certificate during Policy 
Server installation.
The Policy Server SSL certificate is optional. However, use it 
to ensure that only encrypted data transmits between the Pol-
icy Server and ACS server.










