CEPM Install and Config Guide
Cisco EPM Overview

Table Of Contents

Cisco EPM Overview


Cisco EPM Overview


The Cisco Enterprise Policy Manager (EPM) consists of the following components:

The Policy Decision Point (PDP), which is an entitlement engine, evaluates application-specific authorization policies. PDPs connect with existing information repositories, for example, LDAP, AD, and databases.

The Policy Administration Point (PAP), also called the administration console, provides central administration, management and monitoring of entitlement policies with delegation and integration with an Entitlement Repository.

The Policy Enforcement Point (PEP), also called the agent, enforces entitlement policy decisions that are made by the PDP.

Figure 1-1 CEPM Deployment Diagram

The CEPM installer (the distribution) is used to install the PAP and PDP only. The third component, PEP (an agent), is embedded into the application for which the entitlement solution is sought.

The installation is done purely on the user's discretion. Appropriate arrangements are made within the installer for the user to choose whether the PAP and PDP are installed together in a single server or separately in individual servers.