Quarantined Networks
221
no
vd
ocx
(e
n)
24
Ma
rch 20
09
IMPORTANT:
Please read
Section 7.7, “Untestable Endpoints and DHCP Mode,” on
page 222
so that you fully understand the ramifications of allowing untested endpoints on your
network.
7.4 Always Quarantining an Endpoint
To always quarantine a an endpoint without testing (cluster default):
Home window>>System configuration>>Exceptions
1
In the
Blacklist
area:
1a
In the
Endpoints
area, enter one or more MAC addresses, IP addresses, or NetBIOS
names separated by carriage returns.
1b
In the
Windows domains
area, enter one or more domain names separated by carriage
returns.
2
Click
ok
.
IMPORTANT:
If you enter the same endpoint for both options in the Endpoint testing exceptions
area, the Allow access without testing option is used.
7.5 New Users
The process Novell ZENworks Network Access Control follows for allowing end-users to connect
is:
Inline mode
— An IP address is assigned to the endpoint outside of Novell ZENworks
Network Access Control. When the end-user attempts to connect to the network, Novell
ZENworks Network Access Control either blocks access or allows access by adding the
endpoint IP address to the internal firewall.
DHCP mode
— New end-users boot their computers. The boot process looks for an IP address
and, because they are new end-users and no information is known about the endpoints, a
temporary quarantined IP address is assigned. The end-users log in on the Windows login
screen. The end-users start IE and Novell ZENworks Network Access Control attempts to test
the endpoint. The endpoints either retain the quarantined IP address, or are assigned a non-
quarantined network IP address based on the testing result.
802.1X mode
— An endpoint attempts to connect to the network. The end-user’s identity is
verified via an authentication server. If the endpoint is not authenticated, it is quarantined
(allowed access to a limited VLAN). If the endpoint is authenticated, it is tested by Novell
ZENworks Network Access Control. If the endpoint fails the Novell ZENworks Network
Access Control testing, it is quarantined (allowed access to a limited VLAN). If the endpoint
passes the Novell ZENworks Network Access Control testing, it is allowed access to the
network (VLAN).
7.6 Shared Resources
If the end-users typically make connections to shared services and endpoints during the boot
process, these shares are unable to connect while the endpoint has the quarantined IP address, unless
the services and endpoints are listed in the Accessible services and endpoints area (see
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...