
334
Novell ZENworks Network Access Control Users Guide
no
vd
ocx
(e
n)
24
Ma
rch 20
09
When the end-user logs in, they will be able to authenticate from quarantine even if credentials are
not cached:
->
lookup
the
_kerberos
and
_ldap
service location
<-
receive dc01.mycompany.com
&
dc02.mycompany.com
->
lookup
the dc01 IP address
<-
receive
the dc IP address forwarded through Novell ZENworks Network Access Control
named
to the real DNS server (since
dc01.mycompany.com
is in the accessible services list).
->
authenticate
16.5.2 Matching Windows Domain Policies to NAC Policies
Using a Windows domain might affect the end-user’s ability to change their system configuration to
pass the tests. For example, in a corporate environment, each machine gets their domain information
from the domain controller, and the user is not allowed to change any of the related settings, such as
receiving automatic updates and other IE security settings.
The Novell ZENworks Network Access Control administrator needs to make sure the global policy
on their network matches the NAC policy defined, or skip the test.
For example, if the global network policy is to not allow Windows automatic updates, any user
attempting to connect through the
High security
NAC policy fails the test, and is not able to
change their endpoint settings to pass the test.
For example, to change the NAC policy to not run the Windows automatic update
test:
Home window>>NAC policies
1
Select the NAC policy that tests the domain's endpoints.
2
Select the
Tests
menu option.
3
Clear the
Windows automatic updates
check box.
4
Click
ok
.
16.5.3 Setting the Access Mode
The access mode selection is a quick way to select enforcement (normal mode) for all traffic into an
Enforcement cluster, or open it up for trial-use purposes (allow all).
To change the access mode:
Home window>>System monitor>>Select an Enforcement cluster
1
Select one of the following from the
Access mode
area:
normal
— Access is regulated by the NAC policies
allow all
— All requests for access are granted, but endpoints are still tested
2
Click
ok
.
Summary of Contents for ZENworks Network Access Control 5.0
Page 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Page 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Page 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...