Endpoint Activity
Troubleshooting Quarantined Endpoints
4-25
DHCP mode
Network
enforcement
DHCP server (NAC 800) gives the
endpoint:
• Quarantine range IP address
• Appropriate netmask for quarantine
subnet
• Appropriate default gateway
• NAC 800 server's IP as DNS server
(will resolve everything except
Accessible services
to the NAC
800 IP address)
• The switch is configured with
additional IP helper addresses to
forward broadcast DHCP requests to
ESs as well as production DHCP
servers.
Switches must be configured for
multinetting (
multinetting segment
) so
there can be two networks on the same
physical device (or devices) that
cohabitate, but they should not be able
to talk to one another as enforced by the
switch (using ACLs). Each port on the
switch will be allowed to be on either
the production or quarantine network,
and the switch will have a secondary IP
address assigned to the gateway port
(so there will be different gateway IP
addresses for the production and
quarantine networks).
NAC 800 (fake root) DNS – As in
endpoint enforcement (for access to
names
in Accessible services). The
DNS server forwards requests for
accessible services to a real DHCP
server for resolution.
ACLs on the switch prevent
quarantined systems from talking to
production systems, but allow for the
following specific traffic:
• Quarantine --> NAC 800 (OK)
• Production --> Quarantine (OK)
• Quarantine -|-> Production (NO)
• Quarantine -?-> Internet (Maybe*)
Enforcement Mode
How endpoints are quarantined and
redirected to NAC 800
How quarantined endpoints reach
accessible devices
NOTES:
• (*) The gateway does not have to be in the broadcast domain (which is good, since the netmask gives the endpoint no
real broadcast domain), as long as it is in the same (Layer 2) subnet—the router will get you there.
• (**) Allowing access to the Internet is up to the customer, but is necessary for access to any
IP addresses
in
Accessible services
(
System configuration>>Cluster setting defaults area>>Accessible services
).
Table 4-1.
Troubleshooting Quarantined Endpoints (cont.)
Содержание 800 Series
Страница 1: ...Users Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Release 1 1 Users Guide ...
Страница 32: ...Introduction Technical Support 1 14 Technical Support Technical support is available through www procurve com ...
Страница 43: ...2 1 2 Clusters and Servers Chapter Contents Overview 2 2 Installation Examples 2 3 ...
Страница 70: ...System Configuration Management Server 3 22 Figure 3 9 System Configuration Management Server ...
Страница 79: ...System Configuration User Accounts 3 31 Figure 3 12 System Configuration User Accounts ...
Страница 87: ...System Configuration User Roles 3 39 Figure 3 16 System Configuration User Roles ...
Страница 170: ...System Configuration Cluster Setting Defaults 3 122 Figure 3 55 System Configuration Agentless Credentials ...
Страница 206: ... This page intentionally left blank ...
Страница 229: ...End user Access Mac OS X Endpoint Settings 5 23 Figure 5 8 Mac System Preferences ...
Страница 262: ... This page intentionally left blank ...
Страница 284: ... This page intentionally left blank ...
Страница 298: ... This page intentionally left blank ...
Страница 299: ...8 1 8 High Availability and Load Balancing Chapter Contents High Availability 8 2 Load Balancing 8 6 ...
Страница 302: ...High Availability and Load Balancing High Availability 8 4 Figure 8 2 DHCP Installation ...
Страница 303: ...High Availability and Load Balancing High Availability 8 5 Figure 8 3 802 1X Installation ...
Страница 305: ...9 1 9 Inline Quarantine Method Chapter Contents Inline 9 2 ...
Страница 308: ... This page intentionally left blank ...
Страница 311: ...DHCP Quarantine Method Overview 10 3 Figure 10 1 DHCP Installation ...
Страница 314: ... This page intentionally left blank ...
Страница 319: ...802 1X Quarantine Method NAC 800 and 802 1X 11 5 Figure 11 2 NAC 800 802 1X Enforcement ...
Страница 320: ...802 1X Quarantine Method NAC 800 and 802 1X 11 6 Figure 11 3 802 1X Communications ...
Страница 376: ... This page intentionally left blank ...
Страница 414: ... This page intentionally left blank ...
Страница 421: ...Reports Viewing Report Details 14 7 Figure 14 3 Test Details Report ...
Страница 474: ... This page intentionally left blank ...
Страница 520: ...Tests Help Security Settings Windows B 34 http www pcworld com article id 112138 article html ...
Страница 526: ... This page intentionally left blank ...
Страница 529: ...Important Browser Settings Pop up Windows C 3 1 Clear the Block Popup Windows check box 2 Close the Content window ...
Страница 556: ... This page intentionally left blank ...
Страница 584: ... This page intentionally left blank ...
Страница 585: ......
Страница 586: ... Copyright 2007 2008 Hewlett Packard Development Company L P June 2008 Manual Part Number 5991 8571 ...