18.4. Policy Decision Point

In most NAC architectures, the Policy Decision Point (PDP) corresponds to the solution's main policy server. The PDP applies three basic steps:

  1. Collect a full range of information about a user or machine's session — authentication and authorization information, endpoint integrity, location, time of day, and more.

  2. Use this information to decide which resources (applications, data, and network segments) can allow the user to access during that session.

  3. Push this decision to the Policy Enforcement Point (PEP) in the form of a policy that the PEP implements until either

    • The session expires.

    • The PDP revises and refreshes the policy decision.

The PDP is the device or service that provides authorization to the Policy Enforcement Point(s) for every user and machine that attempts to access network resources.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.224.52.200