![Novell ZENworks Network Access Control 5.0 Скачать руководство пользователя страница 121](http://html1.mh-extra.com/html/novell/zenworks-network-access-control-5-0/zenworks-network-access-control-5-0_user-manual_1711968121.webp)
System Configuration
121
no
vd
ocx
(e
n)
24
Ma
rch 20
09
You do not need to enter the IP address of the Novell ZENworks Network Access Control
server here. If you do, it can cause redirection problems when end-users try to connect. You do
need to add any update server names, such as the ones that provide anti-virus and software
updates. Novell ZENworks Network Access Control ships with many of the default server
names pre-populated, such as
windowsupdate.com
.
2
Click
ok
.
The following table provides additional information about accessible services and endpoints.
Table 3-4
Accessible Services and Endpoints Tips
3.17.4 Exceptions
The Exceptions menu option allows you to define the following:
The endpoints and domains that are always allowed access (whitelist)
The endpoints and domains that are always quarantined (blacklist)
Topic
Tip
Modes and IP addresses
When using inline mode, enter IP addresses rather than domain
names.
When using DHCP mode, use domain names for sites the user needs
to access, such as update servers, and use IP addresses for
endpoints that sit behind Novell ZENworks Network Access Control,
such as authentication servers.
Ranges
Use a hyphen for a range of IP addresses (10.0.16.1-30) and a colon
for a range of ports (10.0.16.1:80:90).
DHCP server IP address
In inline mode, you might need to specify the DHCP server IP
address in this field.
Domain controller name
Regardless of where the Domain Controller (DC) is installed, you
must specify the DC name on the Quarantine tab in the Quarantine
area domain suffix field for each quarantine area defined.
DHCP server and Domain
controller
In DHCP mode, when your DHCP server and Domain Controller are
behind Novell ZENworks Network Access Control, you must specify
ports 88, 135 to 159, 389, 1025, 1026, and 3268 as part of the
address. If you do not specify a DHCP address, users are blocked. If
you specify only the IP address with no port, endpoints are not
quarantined, even for failed tests. If your domain controller is not
situated behind Novell ZENworks Network Access Control, you must
configure your router to allow routes from the quarantine area to your
domain controller on ports 88, 135-159, 389, 1025, 1026, and 3268.
Windows update server
In inline mode, if an endpoint is quarantined and needs to access the
Windows Update server, it is not able to unless you enter
207.46.0.0/16
here. This is because iptables needs an IP
address, and would not be able to resolve the default of
windowsupdate.com
.
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...