System Configuration
Cluster Setting Defaults
3-114
You do not need to enter the IP address of the NAC 800 server here. If you
do, it can cause redirection problems when end-users try to connect. You
do need to add any update server names, such as the ones that provide
anti-virus and software updates. NAC 800 ships with many of the default
server names pre-populated, such as
windowsupdate.com
.
2.
Click
ok
.
The following table provides additional information about accessible services
and endpoints.
Topic
Tip
Modes and IP addresses
When using inline mode, enter IP addresses rather than domain
names.
When using DHCP mode, use domain names for sites the user needs
to access, such as update servers, and use IP addresses for endpoints
that sit behind NAC 800, such as authentication servers.
Ranges
Use a hyphen for a range of IP addresses (10.0.16.1/30) and a colon for
a range of ports (10.0.16.1:80:90).
DHCP server IP address
In inline mode, you might need to specify the DHCP server IP address
in this field.
Domain controller name
Regardless of where the Domain Controller (DC) is installed, you must
specify the DC name on the Quarantine tab in the Quarantine area
domain suffix field for each quarantine area defined.
DHCP server and Domain
controller
In DHCP mode, when your DHCP server and Domain Controller are
behind NAC 800, you must specify ports 88, 135 to 159, 389, 1025, 1026,
and 3268 as part of the address. If you do not specify a DHCP address,
users are blocked. If you specify only the IP address with no port,
endpoints are not quarantined, even for failed tests. If your domain
controller is not situated behind NAC 800, you must configure your
router to allow routes from the quarantine area to your domain
controller on ports 88, 135-159, 389, 1025, 1026, and 3268.
Windows update server
In inline mode, if an endpoint is quarantined and needs to access the
Windows Update server, it is not able to unless you enter
207.46.0.0/16
here. This is because iptables needs an IP
address, and would not be able to resolve the default of
windowsupdate.com
.
Table 3-4.
Accessible Services and Endpoints Tips
Summary of Contents for 800 Series
Page 1: ...Users Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Release 1 1 Users Guide ...
Page 43: ...2 1 2 Clusters and Servers Chapter Contents Overview 2 2 Installation Examples 2 3 ...
Page 70: ...System Configuration Management Server 3 22 Figure 3 9 System Configuration Management Server ...
Page 79: ...System Configuration User Accounts 3 31 Figure 3 12 System Configuration User Accounts ...
Page 87: ...System Configuration User Roles 3 39 Figure 3 16 System Configuration User Roles ...
Page 206: ... This page intentionally left blank ...
Page 229: ...End user Access Mac OS X Endpoint Settings 5 23 Figure 5 8 Mac System Preferences ...
Page 262: ... This page intentionally left blank ...
Page 284: ... This page intentionally left blank ...
Page 298: ... This page intentionally left blank ...
Page 302: ...High Availability and Load Balancing High Availability 8 4 Figure 8 2 DHCP Installation ...
Page 303: ...High Availability and Load Balancing High Availability 8 5 Figure 8 3 802 1X Installation ...
Page 305: ...9 1 9 Inline Quarantine Method Chapter Contents Inline 9 2 ...
Page 308: ... This page intentionally left blank ...
Page 311: ...DHCP Quarantine Method Overview 10 3 Figure 10 1 DHCP Installation ...
Page 314: ... This page intentionally left blank ...
Page 319: ...802 1X Quarantine Method NAC 800 and 802 1X 11 5 Figure 11 2 NAC 800 802 1X Enforcement ...
Page 320: ...802 1X Quarantine Method NAC 800 and 802 1X 11 6 Figure 11 3 802 1X Communications ...
Page 376: ... This page intentionally left blank ...
Page 414: ... This page intentionally left blank ...
Page 421: ...Reports Viewing Report Details 14 7 Figure 14 3 Test Details Report ...
Page 474: ... This page intentionally left blank ...
Page 520: ...Tests Help Security Settings Windows B 34 http www pcworld com article id 112138 article html ...
Page 526: ... This page intentionally left blank ...
Page 556: ... This page intentionally left blank ...
Page 584: ... This page intentionally left blank ...
Page 585: ......