Endpoint Activity
153
no
vd
ocx
(e
n)
24
Ma
rch 20
09
DHCP
mode
Network
enforcement
DHCP server (Novell ZENworks
Network Access Control) gives the
endpoint:
Quarantine range IP address
Appropriate netmask for
quarantine subnet
Appropriate default gateway
Novell ZENworks Network Access
Control server's IP as DNS server
(will resolve everything except
Accessible services
to the
Novell ZENworks Network Access
Control IP address)
The switch is configured with
additional IP helper addresses to
forward broadcast DHCP
requests to ESs as well as
production DHCP servers.
Switches must be configured for
multinetting (
multinetting segment
) so
there can be two networks on the same
physical device (or devices) that
cohabitate, but they should not be able
to talk to one another as enforced by
the switch (using ACLs). Each port on
the switch will be allowed to be on
either the production or quarantine
network, and the switch will have a
secondary IP address assigned to the
gateway port (so there will be different
gateway IP addresses for the
production and quarantine networks).
Novell ZENworks Network Access
Control (fake root) DNS
— As in
endpoint enforcement (for access to
names in Accessible services). The
DNS server forwards requests for
accessible services to a real DHCP
server for resolution.
ACLs on the switch
prevent
quarantined systems from talking to
production systems, but allow for the
following specific traffic:
Quarantine --> Novell ZENworks
Network Access Control (OK)
Production --> Quarantine (OK)
Quarantine -|-> Production (NO)
Quarantine -?-> Internet (Maybe*)
Enforcement Mode
How endpoints are quarantined and
redirected to Novell ZENworks Network
Access Control
How quarantined endpoints reach
accessible devices
Summary of Contents for ZENworks Network Access Control 5.0
Page 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Page 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...