Specifications
Policy Server for Cisco NAC
10-7
The Client Validation Sequence
Client validation refers to the process of evaluating an OfficeScan client’s security
posture and returning instructions for the client to perform if the Policy Server
considers it to be at-risk. The Policy Server validates an OfficeScan client by using
configurable rules and policies.
Below is the sequence of events that occurs when an OfficeScan client attempts to
access the network:
1. The Cisco Network Access Device starts the validation sequence by requesting the
security posture of the client when it attempts to access the network.
2. The Network Access Device then passes the security posture to the ACS server.
3. The ACS server passes the security posture to the Policy Server, which performs
the evaluation.
4. In a separate process, the Policy Server periodically polls the OfficeScan server for
Virus Pattern and Virus Scan Engine version information to keep its data current.
It then uses a policy you configure to perform a comparison of this information
with the client security posture data.
5. Following that, the Policy Server creates a posture token, and passes it back to the
OfficeScan client.










