System Configuration
107
no
vd
ocx
(e
n)
24
Ma
rch 20
09
3
Choose a DHCP quarantine option:
Router access control lists (ACLs)
— This option restricts the network access of non-
compliant endpoints by assigning DHCP settings on a quarantined network. The network,
gateway, and ACLs restricting traffic must be configured on your router, which is
accomplished by multinetting or adding a virtual interface to the router that acts as the
quarantine gateway IP address. The quarantine area DHCP settings must reflect this
configuration on your router. The subnets specified in each area must be unique; that is,
neither the quarantined nor the non-quarantined subnets in one area can be quarantined or
non-quarantined in another.
Static routes assigned on the endpoint
— This option restricts the network access of
non-compliant endpoints by vending DHCP settings with no gateway and a netmask of
255.255.255.255. Static routes and a Web proxy server built into Novell ZENworks
Network Access Control allow the endpoint access to specific networks, IP addresses, and
Web sites. These networks, IP addresses, and Web sites are configured in the accessible
endpoint list setting (
System Configuration>>Accessible Services
). The
quarantine areas can either be a subset of your existing DHCP scopes or a separate
network multinetted on your router.
For endpoints to see the outside Web sites listed in
Accessible Services
, the
browser being used on the endpoint must have the Auto-proxy setting turned on.
Furthermore for the Windows Update service to work, the endpoint will need manual
proxy settings pointing to TCP port 3128 on the Enforcement Server assigned to this
endpoint. See
Section 10.1.3, “Configuring Windows Update Service for XP SP2,” on
page 233
for more information about this problem.
TIP:
The quarantine areas can either be a subset of your existing DHCP scopes or a separate
network multinetted on your router. If this option is not selected, enforcement must occur using
ACLs on your router.
TIP:
To set up multiple quarantine areas, click Add a quarantine area, then enter the
information detailed in
Step 2 on page 106
for each additional quarantine area.
4
Click
ok
.
3.12.4 Sorting the DHCP Quarantine Area
To sort the quarantine area:
Home window>>System configuration>>Quarantining>>DHCP radio button
1
Click one of the following the column headings to sort the quarantine area by category:
subnet
dhcp ip range
gateway
non-quarantine subnets
domain suffix
d
(indicates the quarantine option selected in
Step 3 on page 107
)
2
The DHCP quarantine area sorts by the column name clicked.
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...