beautypg.com

IBM Tivoli and Cisco User Manual

Page 131

background image

Chapter 5. Solution design

113

Quarantine System Posture Token for a policy violation, he will be mapped to the
Quarantine_Engineering_RAC (VLAN14). This allows for scalability and
granularity.

Figure 5-14 Shared RADIUS Authorization Components

In our scenario, we list the Cisco Trust Agent (Cisco:PA) and the Security
Compliance Manager agent (IBM Corporation:SCM) as our posture validation
policies. Thus in all, three pieces of information are used to make the access
decision:

IEEE 802.1x authentication (User Group Mapping)
The Security Compliance Manager policy version
The Security Compliance Manager posture policy violation count