|
Concerning to Kaspersky Administration Kit 6.0 MP1
Kaspersky Administration Kit 6.0 MP1 supports co-work with Cisco Network Admission Control (NAC). This feature allows defining correspondence between the conditions of anti-virus computer protection and Cisco NAC states.
A special plug-in to work with Cisco NAC is installed on a client computer together with the Network Agent. This plug-in functions only if Cisco Trust Agent is installed on the same computer.
Parameters of the Cisco NAC co-work are set in the Administration Server properties on the Cisco NAC tab. You can configure correspondence conditions of anti-virus computer protection and Cisco NAC statuses on the same tab.
When co-working with Cisco NAC the Administration Server is a standard component Posture Validation Server (PVS) which the administrator can use to allow or ban computer access into the network (depending on the state of anti-virus protection).
In the upper filed you can select a Cisco NAC computer status: Healthy, Checkup, Quarantine or Infected.
The levels Checkup, Quarantine or Infected have the same conditions. The Healthy level has the conditions which are inverse to conditions of other levels.
In the table below check the necessary status to configure the corresponding values of anti-virus protection. Values of some conditions might be changed: choose the necessary condition in the Value column and using the Modify button open the edit window. In the edit window in the Value field enter the necessary parameters.
For the conditions Real-time protection level differs from that set by the administrator or Real-time protection same as set by Administrator:
- pay attention that for different versions of Kaspersky Anti-Virus for Windows Workstations/ File Servers statuses of real-time protection are different. That is why when choosing the values for these parameter, follow the list of statuses which real-time protection may take.
- using these conditions to define a computer the status is reasonable only when the user has the right to change real-time protection settings. I.e. real-time protection settings are not “locked” and they can be changed or stopped.
In the PVS port number field define Posture Validation Server port number via which the data are exchanged with the Cisco server. The default port is 18000.
|