Adding or Editing a Policy

Cisco NAC > Policy Servers > Policy Server Summary screen > Policies link

From the Policy Server console:

Summary > Policies link

Configurations > Policies

 

Policies include rules. Assign one policy to each registered OfficeScan server on your network for both outbreak mode and normal mode. After configuring new rules or ensuring that the default rules are suitable for your security enforcement needs, configure policies that registered OfficeScan servers can use (see Policy composition for detailed information on policies).

To add a new policy:

  1. To add a policy, click Add. The New Policy screen appears.

To edit a policy, click a policy name. The Edit Policy screen for that policy appears.

  1. Note: You cannot delete policies currently is use. They appear with the icon.

  1. Next to Policy name and Description, type a name to represent the policy and an optional description.

  2. Under Rules, select which existing rules will compose this policy. Existing rules appear in the Rules available column. The Policy Server enforces rules in the order that they appear in the Rules in use column.

  3. Note: If there are no matches to the criteria of a rule, the Policy Server continues to the next rule.

  4. To move rules between the Rules Available and Rules in use columns, click a rule and then click either or .

  5. To change the order of the rules in use, click the rule and then click either or .

  1. Under Default Response, select a response for the Policy Server to return if none of the rules returns a response:

  1. Healthy

  2. Checkup

  3. Infected

  4. Quarantine

  5. Unknown

  6. Note: You cannot add or delete items from the Default response list.

  1. Under Server-side actions, select the Log this incident if all criteria matched check box to have the Policy Server log this incident (see Viewing Client Validation Logs for more information on logs).

  2. Under Client-side actions, select from among the following options for OfficeScan clients if all policy criteria match:

  1. Display notification message on client computer (Maximum of 200 single-byte characters)

  1. Click Save.