Administrator Guide

Table Of Contents
The following table describes the Patch Management parameters:
Interface
Parameter
Description
Patch Management Page l A patch management
application is on
l Auto Remediation
l User Notification
l Uncheck to allow any
product
l Check the A patch management application is on
to enable testing of health data for configured
Antivirus application(s).
l Check the Auto Remediation check box to enable
auto remediation of patch management status.
l Check the User Notification check box to enable
user notification of policy violation of patch
management status.
l Clear Uncheck to allow any product check box to
check whether any patch management application
(any vendor) is running on the end host.
Patch Management Page
(Detail 1)
l Add
l Trashcan icon
l To configure patch management application
attributes for testing against health data, click Add.
l To remove configured patch management
application attributes from the list, click the
trashcan icon in that row.
Patch Management Page
(Detail 2)
Product/Version
Configure settings for which to test against health data.
All checks might not be available for some products.
Where checks are not available, they are shown in
disabled state on the UI.
l Select Patch Management product: Select a
vendor. This option is only enabled if the Product-
specific checks check box is checked.
l Product version is at least: Enter version number.
This option is only enabled if the Product-specific
checks check box is checked.
l Status Check Type: Select this field to check
whether Patch Agent is enabled or not. W-ClearPass
Policy Manager server compares the Patch Agent
Status sent by OnGuard Agent with the configured
value. If the Patch Agent Status value is different
from configured value, then client is treated as
unhealthy. If Auto-remediation is enabled, then
OnGuard Agent changes the Patch Agent Status on
client to the configured value. Select any of the
following options:
n No Check - W-ClearPass Policy Manager server
ignores Patch Agent Status value. This means it
will not check status of Patch Agent application
on client.
n Enabled - Patch Agent is turned on and
automatically update the client.
n Disabled - Patch Agent is disabled and it will not
check for missing patches and update the client.
n Notify Before Download - Patch Agent is turned
on and will notify user before downloading
updates.
Table 146: Patch Management Page Parameters
Dell Networking W-ClearPass Policy Manager 6.6 | User Guide Posture | 289