154
Novell ZENworks Network Access Control Users Guide
no
vd
ocx
(e
n)
24
Ma
rch 20
09
Inline /
Gatewa
y
VPN split
tunnel
(multihomed
endpoint)
Novell ZENworks Network Access
Control acts as the man-in-the-middle,
iptables rewrites packets, and forwards
traffic to the Novell ZENworks Network
Access Control system itself.
The production network is protected
from VPN users by iptables acting as a
firewall. VPN users can only get
through iptables by becoming
compliant with a Novell ZENworks
Network Access Control policy, after
which a hole is opened for their VPN IP
address.
NOTE:
In this configuration, the user
has to try and access an internal site in
order to be redirected to Novell
ZENworks Network Access Control
(unless they have the Novell ZENworks
Network Access Control Agent
installed)
No need to
allow
public sites (endpoint
can get there directly, without going
through VPN and Novell ZENworks
Network Access Control).
iptables does NOT rewrite traffic
destined for (internal) IP addresses in
Accessible services
.
The names listed in
Accessible
services
are not used.
Inline /
Gatewa
y
VPN not split
tunnel
(all traffic
through
VPN)
Novell ZENworks Network Access
Control acts as the man-in-the-middle,
iptables rewrites packets, and forwards
traffic to the Novell ZENworks Network
Access Control system itself.
The production network is protected
from VPN users by iptables acting as a
firewall. VPN users can only get
through iptables by becoming
compliant with a Novell ZENworks
Network Access Control policy, after
which a hole is opened for their VPN IP
address.
iptables(?) does NOT rewrite traffic
destined for IP addresses in
Accessible services
.
The names listed in
Accessible
services
are not used.
Enforcement Mode
How endpoints are quarantined and
redirected to Novell ZENworks Network
Access Control
How quarantined endpoints reach
accessible devices
Summary of Contents for ZENworks Network Access Control 5.0
Page 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Page 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...