152
Novell ZENworks Network Access Control Users Guide
no
vd
ocx
(e
n)
24
Ma
rch 20
09
Table 4-1
Troubleshooting Quarantined Endpoints
Enforcement Mode
How endpoints are quarantined and
redirected to Novell ZENworks Network
Access Control
How quarantined endpoints reach
accessible devices
DHCP
mode
Endpoint
enforcement
DHCP server (Novell ZENworks
Network Access Control) gives the
endpoint:
Quarantine range IP address (*)
255.255.255.255 netmask
(effectively blocks outgoing traffic
from the endpoint)
No default gateway
Novell ZENworks Network Access
Control server's IP as DNS server
(will resolve everything except
accessible devices
to the Novell
ZENworks Network Access
Control IP address)
The switch is configured with
additional IP helper addresses to
forward broadcast DHCP
requests to ESs as well as
production DHCP servers.
DHCP server (Novell ZENworks
Network Access Control) also sends:
A static route to the Novell
ZENworks Network Access
Control server IP via a gateway
(*)
Static routes to any IP addresses
defined in
Accessible
services
Novell ZENworks Network Access
Control DNS
— Novell ZENworks
Network Access Control will add any
names
listed in
Accessible
services
to the
named.conf
file so
the endpoint will be able to resolve the
names (to get the real IP). Unless there
are corresponding static routes, the
endpoint will not be able to access
them directly.
Novell ZENworks Network Access
Control Web Proxy
— The Novell
ZENworks Network Access Control
server also advertises a Web proxy
server for endpoints that autodetect
Web proxies. This proxy will redirect all
Web requests through Novell
ZENworks Network Access Control,
and traffic destined for
names
in
Accessible services
will be
proxied through Novell ZENworks
Network Access Control.
NOTE:
Windows update does not
honor autoproxy. Workarounds include:
Adding Windows update
hostnames AND IP addresses to
Accessible services
, or
Manually setting Novell
ZENworks Network Access
Control as the proxy (this would
require reversing this setting it
once a system was out of
quarantine).
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...