Endpoint Activity
Troubleshooting Quarantined Endpoints
4-25
DHCP mode
Network
enforcement
DHCP server (NAC 800) gives the
endpoint:
• Quarantine range IP address
• Appropriate netmask for quarantine
subnet
• Appropriate default gateway
• NAC 800 server's IP as DNS server
(will resolve everything except
Accessible services
to the NAC
800 IP address)
• The switch is configured with
additional IP helper addresses to
forward broadcast DHCP requests to
ESs as well as production DHCP
servers.
Switches must be configured for
multinetting (
multinetting segment
) so
there can be two networks on the same
physical device (or devices) that
cohabitate, but they should not be able
to talk to one another as enforced by the
switch (using ACLs). Each port on the
switch will be allowed to be on either
the production or quarantine network,
and the switch will have a secondary IP
address assigned to the gateway port
(so there will be different gateway IP
addresses for the production and
quarantine networks).
NAC 800 (fake root) DNS – As in
endpoint enforcement (for access to
names
in Accessible services). The
DNS server forwards requests for
accessible services to a real DHCP
server for resolution.
ACLs on the switch prevent
quarantined systems from talking to
production systems, but allow for the
following specific traffic:
• Quarantine --> NAC 800 (OK)
• Production --> Quarantine (OK)
• Quarantine -|-> Production (NO)
• Quarantine -?-> Internet (Maybe*)
Enforcement Mode
How endpoints are quarantined and
redirected to NAC 800
How quarantined endpoints reach
accessible devices
NOTES:
• (*) The gateway does not have to be in the broadcast domain (which is good, since the netmask gives the endpoint no
real broadcast domain), as long as it is in the same (Layer 2) subnet—the router will get you there.
• (**) Allowing access to the Internet is up to the customer, but is necessary for access to any
IP addresses
in
Accessible services
(
System configuration>>Cluster setting defaults area>>Accessible services
).
Table 4-1.
Troubleshooting Quarantined Endpoints (cont.)
Summary of Contents for 800 Series
Page 1: ...Users Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Release 1 1 Users Guide ...
Page 43: ...2 1 2 Clusters and Servers Chapter Contents Overview 2 2 Installation Examples 2 3 ...
Page 70: ...System Configuration Management Server 3 22 Figure 3 9 System Configuration Management Server ...
Page 79: ...System Configuration User Accounts 3 31 Figure 3 12 System Configuration User Accounts ...
Page 87: ...System Configuration User Roles 3 39 Figure 3 16 System Configuration User Roles ...
Page 206: ... This page intentionally left blank ...
Page 229: ...End user Access Mac OS X Endpoint Settings 5 23 Figure 5 8 Mac System Preferences ...
Page 262: ... This page intentionally left blank ...
Page 284: ... This page intentionally left blank ...
Page 298: ... This page intentionally left blank ...
Page 302: ...High Availability and Load Balancing High Availability 8 4 Figure 8 2 DHCP Installation ...
Page 303: ...High Availability and Load Balancing High Availability 8 5 Figure 8 3 802 1X Installation ...
Page 305: ...9 1 9 Inline Quarantine Method Chapter Contents Inline 9 2 ...
Page 308: ... This page intentionally left blank ...
Page 311: ...DHCP Quarantine Method Overview 10 3 Figure 10 1 DHCP Installation ...
Page 314: ... This page intentionally left blank ...
Page 319: ...802 1X Quarantine Method NAC 800 and 802 1X 11 5 Figure 11 2 NAC 800 802 1X Enforcement ...
Page 320: ...802 1X Quarantine Method NAC 800 and 802 1X 11 6 Figure 11 3 802 1X Communications ...
Page 376: ... This page intentionally left blank ...
Page 414: ... This page intentionally left blank ...
Page 421: ...Reports Viewing Report Details 14 7 Figure 14 3 Test Details Report ...
Page 474: ... This page intentionally left blank ...
Page 520: ...Tests Help Security Settings Windows B 34 http www pcworld com article id 112138 article html ...
Page 526: ... This page intentionally left blank ...
Page 556: ... This page intentionally left blank ...
Page 584: ... This page intentionally left blank ...
Page 585: ......