Inhaltszusammenfassung zur Seite Nr. 1
Front cover
Building a Network
Access Control Solution
with IBM Tivoli and Cisco Systems
Covering Cisco Network Admission
Control Framework and Appliance
Automated remediation of
noncompliant workstations
Advanced security
compliance notification
Axel Buecker
Richard Abdullah
Markus Belkin
Mike Dougherty
Wlodzimierz Dymaczewski
Vahid Mehr
Frank Yeh
ibm.com/redbooks
Inhaltszusammenfassung zur Seite Nr. 2
Inhaltszusammenfassung zur Seite Nr. 3
International Technical Support Organization Building a Network Access Control Solution with IBM Tivoli and Cisco Systems January 2007 SG24-6678-01
Inhaltszusammenfassung zur Seite Nr. 4
Note: Before using this information and the product it supports, read the information in “Notices” on page vii. Second Edition (January 2007) This edition applies to Tivoli Security Compliance Manager V5.1, Tivoli Configuration Manager V4.2.3, and Cisco Secure ACS V4.0. © Copyright International Business Machines Corporation 2005, 2007. All rights reserved. Note to U.S. Government Users Restricted Rights -- Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.
Inhaltszusammenfassung zur Seite Nr. 5
Contents Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vii Trademarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . viii Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .ix The team that wrote this redbook. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x Become a published author .
Inhaltszusammenfassung zur Seite Nr. 6
3.1.1 Network Admission Control. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41 3.1.2 Compliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46 3.1.3 Remediation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 3.2 Physical components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 3.2.1 Network client . . . . . . . . . . . . . . . . . . . . . . . . . . .
Inhaltszusammenfassung zur Seite Nr. 7
6.2.1 Posture collectors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 153 6.2.2 Policy collector . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154 6.2.3 Installation of posture collectors . . . . . . . . . . . . . . . . . . . . . . . . . . . 155 6.2.4 Customization of compliance policies . . . . . . . . . . . . . . . . . . . . . . . 161 6.2.5 Assigning the policy to the clients . . . . . . . . . . . . . . . . . . . . . . . . .
Inhaltszusammenfassung zur Seite Nr. 8
Fault isolation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 448 Security Compliance Manager server and client . . . . . . . . . . . . . . . . . . . . . . 450 Communication port usage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 Tools and tricks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 451 Cisco NAC. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Inhaltszusammenfassung zur Seite Nr. 9
Notices This information was developed for products and services offered in the U.S.A. IBM may not offer the products, services, or features discussed in this document in other countries. Consult your local IBM representative for information about the products and services currently available in your area. Any reference to an IBM product, program, or service is not intended to state or imply that only that IBM product, program, or service may be used. Any functionally equivalent product, pro
Inhaltszusammenfassung zur Seite Nr. 10
Trademarks The following terms are trademarks of the International Business Machines Corporation in the United States, other countries, or both: Redbooks (logo) ™ DB2 Universal Database™ Redbooks™ developerWorks® DB2® Tivoli® ibm.com® IBM® WebSphere® Access360® NetView® AIX® PartnerWorld® The following terms are trademarks of other companies: Cisco, Cisco Systems, Cisco IOS, PIX, and Catalyst are trademarks of Cisco Systems, Inc. in the United States, other countries, or both. Java, JVM, J2EE
Inhaltszusammenfassung zur Seite Nr. 11
Preface In February of 2004, IBM® announced that it would be joining Cisco’s Network Admission Control (NAC) program. In December of 2004, IBM released its first offering for the Cisco NAC program in the form of the IBM Tivoli® compliance and remediation solution. In June of 2005 the first edition of this IBM Redbook was published. A number of subsequent updates from Cisco have changed the dynamics of the Network Access Control market, and have led to significant changes by IBM to our com
Inhaltszusammenfassung zur Seite Nr. 12
The team that wrote this redbook This redbook was produced by a team of specialists from around the world working for the International Technical Support Organization, Austin Center. The project was executed at the Cisco Headquarter in San Jose. Figure 1 Top left to right: Frank, Axel, Vahid, and Mike Bottom left to right: Vlodek, Markus, and Rich Axel Buecker is a Certified Consulting Software IT Specialist at the International Technical Support Organization, Austin Center. He writes exten
Inhaltszusammenfassung zur Seite Nr. 13
Richard Abdullah is a Consulting Engineer with Cisco Systems Strategic Alliances. Prior to joining Cisco Systems in 2001, he worked in technical capacities within various service providers. He has spent 19 years in the IT industry focusing on networking and most recently on network security solutions. He holds a BSEE degree from the University of Michigan, Dearborn. Markus Belkin is a Network Architect with IBM Australia. He has worked in the IT Industry for 10 years and works predominately
Inhaltszusammenfassung zur Seite Nr. 14
Thanks to the following people for their contributions to this project: Cheryl Gera, Erica Wazewski, Lorinda Schwarz, Julie Czubik International Technical Support Organization, Poughkeepsie Center Wing Leung, Alex Rodriguez IBM US Tadeusz Treit, Bogusz Piotrowski, Anna Iskra IBM Poland Cindra Ford, Zary Stahl, Nick Chong, Prem Ananthakrishnan, Brendan O'Connell, Irene Sandler, Raju Srirajavatchavai, Alok Agrawal, Marcia Hanson Cisco Systems Inc. Thanks to following people for working on the fir
Inhaltszusammenfassung zur Seite Nr. 15
Find out more about the residency program, browse the residency index, and apply online at: ibm.com/redbooks/residencies.html Comments welcome Your comments are important to us! We want our Redbooks™ to be as helpful as possible. Send us your comments about this or other Redbooks in one of the following ways: Use the online Contact us review redbook form found at: ibm.com/redbooks Send your comments in an e-mail to: redbook@us.ibm.com Mail your comments to: IBM Corporation, International
Inhaltszusammenfassung zur Seite Nr. 16
xiv Building a Network Access Control Solution with IBM Tivoli and Cisco Systems
Inhaltszusammenfassung zur Seite Nr. 17
Summary of changes This section describes the technical changes made in this edition of the book and in previous editions. This edition may also include minor corrections and editorial changes that are not identified. Summary of Changes for SG24-6678-01 for Building a Network Access Control Solution with IBM Tivoli and Cisco Systems as created or updated on January 16, 2007. January 2007, Second Edition This revision reflects the addition, deletion, or modification of new and changed informa
Inhaltszusammenfassung zur Seite Nr. 18
xvi Building a Network Access Control Solution with IBM Tivoli and Cisco Systems
Inhaltszusammenfassung zur Seite Nr. 19
Part 1 Part 1 Architecture and design In this part we discuss the overall business context of the IBM Integrated Security Solution for Cisco Networks. We then describe how to technically architect the overall solution into an existing environment, and introduce the logical and physical components on both the IBM Tivoli and Cisco side. © Copyright IBM Corp. 2005, 2007. All rights reserved. 1
Inhaltszusammenfassung zur Seite Nr. 20
2 Building a Network Access Control Solution with IBM Tivoli and Cisco Systems