Users Guide

66 | Policy Manager Policy Model Dell Networking W-ClearPass Policy Manager 6.4 |User Guide
Component Service:
Component
ratio
Description
Some Services (for example, MAC-based
Authentication) may handle role mapping differently:
l For MAC-based Authentication Services, where role
information is not available from an authentication
source, an audit server can determine the role by
applying post-audit rules against the client
attributes gathered during the audit.
D - Internal Posture Policies Zero or more per
service
An Internal Posture Policy tests Requests against
internal Posture rules to assess health. Posture rule
conditions contain attributes present in vendor-
specific posture dictionaries.
E - Posture Servers Zero or more per
service
Posture servers evaluate client health based on
specified vendor-specific posture credentials. These
posture credentials cannot be evaluated internally by
Policy Manager (that is, not by internal posture
policies).
Currently, Policy Manager supports the following
forms of posture server interfaces:
l HCAP
l RADIUS
l GAMEv2
F - Audit Servers Zero or more per
service
Audit Servers evaluate the health of clients that do
not have an installed agent, or which cannot respond
to Policy Manager interactions. Audit Servers
typically operate instead of authentication methods,
authentication sources, internal posture policies, and
posture server.
In addition to returning posture tokens, Audit Servers
can contain post-audit rules that map results from the
audit into Roles.
G - Enforcement Policy One per service
(mandatory)
Policy Manager tests Posture Tokens, Roles, and
system time against the Enforcement Policy rules to
return one or more matching the Enforcement
Policy rules to return one or more matching
Enforcement Profiles that define scope of access for
the client.
H - Enforcement Profile One or more per
service
Enforcement Profiles contain attributes that define a
client's scope of access for the session. Policy
Manager returns these Enforcement Profile
attributes to the switch.
Table 28:
Policy Manager Service Components (Continued)
Viewing Existing Services
You can view all configured services in a list or drill down to individual services in the Services page. Click
Configuration > Services to view a list of services that you can filter by phrase or sort by order. In the