System Administration
Working with Ranges
15-25
Working with Ranges
In NAC 800 implementations, particularly in trial installations where you are
connecting and disconnecting cables to a number of different types of end-
points, you can filter the activity by specifying the following:
■
Ranges to monitor – This property filters results in the display
window. Only the ranges specified here are shown and tested.
Endpoints that fall outside this range will not be tested.
■
Ranges to ignore – This property filters results in the display window.
Only ranges that fall outside of this list are shown and tested; ranges
in this list are ignored. Endpoints in this range will not be tested or
displayed. For example, include servers, printers, VoIP phones or
other devices that you do not want to be tested in this list.
■
Ranges to enforce – This property is valid for only DHCP mode. It
modifies the iptables NFQUEUE rule such that only the networks set
to be enforced will ever get quarantine addresses.
NOTE:
There is one caveat to note with ranges to monitor and ranges to ignore; if
endpoints have IP addresses outside of the ranges to monitor and ranges to
ignore, and if the ES is capable of controlling network access for those
endpoints, the endpoints can still be quarantined by consequence of the NAC
policy rules for Operating Systems and Inactive endpoints.
NOTE:
Entries made to either Ranges to Monitor or Ranges to Enforce will take effect
for newly discovered endpoints only; Previous entries discovered will not be
removed from the display. To permanently remove these entries, run the
resetTestData.py script from the command line. The script clears all existing
endpoints and endpoint test data from the display.
To specify ranges to monitor:
Home window>>System configuration>>Select an Enforcement
Cluster>>Advanced menu option
In the
Endpoint detection
area, enter the range of addresses to monitor in the
IP addresses to monitor
text field. Separate ranges with a hyphen or use CIDR
notation.
To specify ranges to ignore:
Содержание ProCurve NAC 800
Страница 1: ...HP ProCurve Network Access Controller 800 Users Guide ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Release 1 1 Users Guide ...
Страница 32: ...Introduction Technical Support 1 14 Technical Support Technical support is available through www procurve com ...
Страница 43: ...2 1 2 Clusters and Servers Chapter Contents Overview 2 2 Installation Examples 2 3 ...
Страница 71: ...System Configuration Management Server 3 23 Figure 3 9 System Configuration Management Server ...
Страница 80: ...System Configuration User Accounts 3 32 Figure 3 12 System Configuration User Accounts ...
Страница 88: ...System Configuration User Roles 3 40 Figure 3 16 System Configuration User Roles ...
Страница 100: ...System Configuration Quarantining General 3 52 1 Select a cluster Figure 3 23 System Configuration Quarantining ...
Страница 171: ...System Configuration Cluster Setting Defaults 3 123 Figure 3 55 System Configuration Agentless Credentials ...
Страница 180: ... This page intentionally left blank ...
Страница 208: ... This page intentionally left blank ...
Страница 234: ...End user Access Mac OS X Endpoint Settings 5 26 Figure 5 14 Mac System Preferences ...
Страница 288: ... This page intentionally left blank ...
Страница 302: ... This page intentionally left blank ...
Страница 303: ...8 1 8 High Availability and Load Balancing Chapter Contents High Availability 8 2 Load Balancing 8 6 ...
Страница 306: ...High Availability and Load Balancing High Availability 8 4 Figure 8 2 DHCP Installation ...
Страница 307: ...High Availability and Load Balancing High Availability 8 5 Figure 8 3 802 1X Installation ...
Страница 309: ...9 1 9 Inline Quarantine Method Chapter Contents Inline 9 2 ...
Страница 312: ... This page intentionally left blank ...
Страница 315: ...DHCP Quarantine Method Overview 10 3 Figure 10 1 DHCP Installation ...
Страница 318: ... This page intentionally left blank ...
Страница 323: ...802 1X Quarantine Method NAC 800 and 802 1X 11 5 Figure 11 2 NAC 800 802 1X Enforcement ...
Страница 324: ...802 1X Quarantine Method NAC 800 and 802 1X 11 6 Figure 11 3 802 1X Communications ...
Страница 380: ... This page intentionally left blank ...
Страница 418: ... This page intentionally left blank ...
Страница 425: ...Reports Viewing Report Details 14 7 Figure 14 3 Test Details Report ...
Страница 459: ...System Administration Creating and Replacing SSL Certificates 15 31 10 Save and exit the file ...
Страница 468: ... This page intentionally left blank ...
Страница 480: ... This page intentionally left blank ...
Страница 526: ...Tests Help Security Settings Windows B 34 http www pcworld com article id 112138 article html ...
Страница 532: ... This page intentionally left blank ...
Страница 535: ...Important Browser Settings Pop up Windows C 3 1 Clear the Block Popup Windows check box 2 Close the Content window ...
Страница 562: ... This page intentionally left blank ...
Страница 590: ... This page intentionally left blank ...