System Configuration
Cluster Setting Defaults
3-115
You do not need to enter the IP address of the NAC 800 server here. If you
do, it can cause redirection problems when end-users try to connect. You
do need to add any update server names, such as the ones that provide
anti-virus and software updates. NAC 800 ships with many of the default
server names pre-populated, such as
windowsupdate.com
.
2.
Click
ok
.
The following table provides additional information about accessible services
and endpoints.
Topic
Tip
Modes and IP addresses
When using inline mode, enter IP addresses rather than domain
names.
When using DHCP mode, use domain names for sites the user needs
to access, such as update servers, and use IP addresses for endpoints
that sit behind NAC 800, such as authentication servers.
Ranges
Use a hyphen for a range of IP addresses (10.0.16.1/30) and a colon for
a range of ports (10.0.16.1:80:90).
DHCP server IP address
In inline mode, you might need to specify the DHCP server IP address
in this field.
Domain controller name
Regardless of where the Domain Controller (DC) is installed, you must
specify the DC name on the Quarantine tab in the Quarantine area
domain suffix field for each quarantine area defined.
DHCP server and Domain
controller
In DHCP mode, when your DHCP server and Domain Controller are
behind NAC 800, you must specify ports 88, 135 to 159, 389, 1025, 1026,
and 3268 as part of the address. If you do not specify a DHCP address,
users are blocked. If you specify only the IP address with no port,
endpoints are not quarantined, even for failed tests. If your domain
controller is not situated behind NAC 800, you must configure your
router to allow routes from the quarantine area to your domain
controller on ports 88, 135-159, 389, 1025, 1026, and 3268.
Windows update server
In inline mode, if an endpoint is quarantined and needs to access the
Windows Update server, it is not able to unless you enter
207.46.0.0/16
here. This is because iptables needs an IP
address, and would not be able to resolve the default of
windowsupdate.com
.
Table 3-4.
Accessible Services and Endpoints Tips
Содержание ProCurve NAC 800
Страница 1: ...HP ProCurve Network Access Controller 800 Users Guide ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Release 1 1 Users Guide ...
Страница 32: ...Introduction Technical Support 1 14 Technical Support Technical support is available through www procurve com ...
Страница 43: ...2 1 2 Clusters and Servers Chapter Contents Overview 2 2 Installation Examples 2 3 ...
Страница 71: ...System Configuration Management Server 3 23 Figure 3 9 System Configuration Management Server ...
Страница 80: ...System Configuration User Accounts 3 32 Figure 3 12 System Configuration User Accounts ...
Страница 88: ...System Configuration User Roles 3 40 Figure 3 16 System Configuration User Roles ...
Страница 100: ...System Configuration Quarantining General 3 52 1 Select a cluster Figure 3 23 System Configuration Quarantining ...
Страница 171: ...System Configuration Cluster Setting Defaults 3 123 Figure 3 55 System Configuration Agentless Credentials ...
Страница 180: ... This page intentionally left blank ...
Страница 208: ... This page intentionally left blank ...
Страница 234: ...End user Access Mac OS X Endpoint Settings 5 26 Figure 5 14 Mac System Preferences ...
Страница 288: ... This page intentionally left blank ...
Страница 302: ... This page intentionally left blank ...
Страница 303: ...8 1 8 High Availability and Load Balancing Chapter Contents High Availability 8 2 Load Balancing 8 6 ...
Страница 306: ...High Availability and Load Balancing High Availability 8 4 Figure 8 2 DHCP Installation ...
Страница 307: ...High Availability and Load Balancing High Availability 8 5 Figure 8 3 802 1X Installation ...
Страница 309: ...9 1 9 Inline Quarantine Method Chapter Contents Inline 9 2 ...
Страница 312: ... This page intentionally left blank ...
Страница 315: ...DHCP Quarantine Method Overview 10 3 Figure 10 1 DHCP Installation ...
Страница 318: ... This page intentionally left blank ...
Страница 323: ...802 1X Quarantine Method NAC 800 and 802 1X 11 5 Figure 11 2 NAC 800 802 1X Enforcement ...
Страница 324: ...802 1X Quarantine Method NAC 800 and 802 1X 11 6 Figure 11 3 802 1X Communications ...
Страница 380: ... This page intentionally left blank ...
Страница 418: ... This page intentionally left blank ...
Страница 425: ...Reports Viewing Report Details 14 7 Figure 14 3 Test Details Report ...
Страница 459: ...System Administration Creating and Replacing SSL Certificates 15 31 10 Save and exit the file ...
Страница 468: ... This page intentionally left blank ...
Страница 480: ... This page intentionally left blank ...
Страница 526: ...Tests Help Security Settings Windows B 34 http www pcworld com article id 112138 article html ...
Страница 532: ... This page intentionally left blank ...
Страница 535: ...Important Browser Settings Pop up Windows C 3 1 Clear the Block Popup Windows check box 2 Close the Content window ...
Страница 562: ... This page intentionally left blank ...
Страница 590: ... This page intentionally left blank ...