![Novell ZENworks Network Access Control 5.0 Скачать руководство пользователя страница 155](http://html1.mh-extra.com/html/novell/zenworks-network-access-control-5-0/zenworks-network-access-control-5-0_user-manual_1711968155.webp)
Endpoint Activity
155
no
vd
ocx
(e
n)
24
Ma
rch 20
09
802.1X
DHCP server (MS DHCP server, and
so on) gives the endpoint:
Quarantine range IP address
Appropriate netmask for
quarantine subnet
Appropriate default gateway
Novell ZENworks Network Access
Control server's IP as DNS server
(will resolve everything except
Accessible services
to the
Novell ZENworks Network Access
Control IP address)
Very low DHCP lease time (~3
minutes)
ACLs on network devices must be
configured to limit where endpoints on
the quarantine VLAN can go.
Iptables prerouting chains rewrite traffic
coming from quarantine subnets (as
defined in the user interface) and
destined for Novell ZENworks Network
Access Control (due to Novell
ZENworks Network Access Control
DNS) so that:
Novell ZENworks Network Access
Control:80 --> Novell ZENworks
Network Access Control:88
Novell ZENworks Network Access
Control:443 --> Novell ZENworks
Network Access Control:89
Traffic coming from non-quarantine
ranges will not be rewritten, so that
users can get to the Novell ZENworks
Network Access Control user interface
on port 443.
Novell ZENworks Network Access
Control DNS
— As in endpoint
enforcement (for access to names in
Accessible services
)
ACLs on the switch
prevent
quarantined systems from talking to
production systems, but allow for the
following specific traffic:
Quarantine --> Novell ZENworks
Network Access Control (OK)
Production -?-> Quarantine
(Maybe*)
Quarantine -|-> Production (NO)
Quarantine -?-> Internet
(Maybe**)
NOTES:
(*) The gateway does not have to be in the broadcast domain (which is good, since the netmask
gives the endpoint on real broadcast domain), as long as it is in the same (Layer 2) subnet—the
router will get you there.
(**) Allowing access to the Internet is up to the customer, but is necessary for access to any
IP
addresses
in
Accessible services
(
System configuration>>Cluster setting defaults
area>>Accessible services
).
Enforcement Mode
How endpoints are quarantined and
redirected to Novell ZENworks Network
Access Control
How quarantined endpoints reach
accessible devices
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...