Agents & Options
The Symantec Network Access Control architecture includes three core components: policy management, endpoint evaluation, and network enforcement. All three components work together as a single solution without relying upon external elements for functionality.
Options
Symantec Network Access Control allows you to select the most appropriate enforcement method for different parts of your network without increasing operational complexity or cost. The Symantec Enforcers verify that a host is compliant with minimum security policies before allowing normal network access. The primary types of enforcement are:
- Gateway
- LAN
- DHCP
- Self-Enforcement
- Peer-to-Peer Enforcement
- Microsoft Network Access Protection (NAP)
- Set policies
- Control Symantec Network Access Control client
- View logs
- Run reports
Symantec Network Access Control offers three distinct endpoint evaluation technologies when determining endpoint compliance.
- Persistent Agents are installed by administrators on Corporate-owned and other managed systems to determine compliance status.
- Dissolvable Agents are placed on non-corporate devices or systems that are not currently managed by administrators. They are java-based agents are delivered on-demand and without administrative privileges to evaluate endpoint compliance posture.
- As an alternative, remote vulnerability scanning can be used to extend the information gathering functionality to systems for systems such and Linux and Unix.