Remote Device Activity Capture
13
295
no
vd
ocx
(e
n)
24
Ma
rch 20
09
13
Remote Device Activity Capture
This section describes two ways to achieve Remote Device Activity Capture (RDAC):
Creating a DAC host
Using the Infoblox connector
The following sections contain more information:
Section 13.1, “Creating a DAC Host,” on page 295
Section 13.2, “Novell ZENworks Network Access Control to Infoblox Connector,” on
page 307
13.1 Creating a DAC Host
Novell ZENworks Network Access Control auto-discovers endpoints on your network so that the
testing and transition from quarantine to non-quarantine areas happens quickly and smoothly after
an endpoint is booted up. Novell ZENworks Network Access Control also relies on auto-discovery
functionality to track DHCP IP address transitions so that it can continue to communicate
seamlessly with endpoints after an IP change. The utility used for auto-discovery is Device Activity
Capture (DAC). DAC listens or sniffs the network for, most importantly, DHCP traffic, but can be
configured to discover other types of IP traffic if needed (such as from static IP addresses). DAC
listens for DHCP ACK (a unicast from the DHCP server to the endpoint) messages so that it knows
exactly when an endpoint has received a new IP address and can be tested with a TCP/IP
connection. DAC works in a number of configurations:
DHCP (Router) and Inline Mode
— DAC runs on the Enforcement Servers (ES) and
discovers endpoints when they generate traffic across the ES bridge. There is no need for you to
do any extra configuration of DAC in these modes.
802.1X Mode
Mirror Port
— DAC runs on the ESs. The eth1 interface of the ES is connected to a
mirror port on a switch that mirrors DHCP traffic. The eth1 interface can also be
configured to listen on a mirror port for other types of traffic to discover endpoints with
static IP addresses. Select the
local
radio button in the
Home window>>System
configuration>>802.1X Quarantine method>>Quarantining
window
to enable this mode.
Remote DAC (RDAC)
— DAC runs as a standalone service on a Windows DHCP server
and relays DHCP information back to the ESs. DAC can also be configured to run on a
non-DHCP server to discover endpoints with static IP addresses. Select the
remote
radio
button in the Select the local radio button in the
Home window>>System
configuration>>802.1X Quarantine method>>Quarantining
window
to enable this mode.
This section explains how to install DAC on a remote system. For Windows servers, use the
Windows installer to set up the first interface, then manually add other interfaces.
TIP:
When DAC is installed on the ES, it is sometimes referred to as Embedded DAC (EDAC).
When DAC is installed remotely, it is sometimes referred to as Remote DAC (RDAC).
Summary of Contents for ZENworks Network Access Control 5.0
Page 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Page 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...