318
Novell ZENworks Network Access Control Users Guide
no
vd
ocx
(e
n)
24
Ma
rch 20
09
The following connection and communication actions apply:
If the connection between the DHCP server and the Novell ZENworks Network Access
Control server is lost and re-established, the existing ACL on the DHCP server is discarded and
Novell ZENworks Network Access Control re-transmits the entire ACL.
If the DHCP server cannot communicate with Novell ZENworks Network Access Control at
any time, the DHCP server goes in to an
allow all
or
deny all
state, depending on the
failopen
parameter setting in the
config.xml
file (true = allow all, false = deny all).
Novell ZENworks Network Access Control attempts to connect to known DHCP servers on
start-up, and continuously attempts to connect at regular intervals indefinitely.
The following sections contain more information:
Section 15.1, “Installation Overview,” on page 318
Section 15.2, “DHCP Plug-in and the Novell ZENworks Network Access Control User
Interface,” on page 320
15.1 Installation Overview
When Novell ZENworks Network Access Control does not sit inline with the DHCP server, you
need to set up a remote host for Device Activity Capture (DAC) to allow Novell ZENworks
Network Access Control to listen on the network. This is done by installing a small program on the
DHCP server or other remote (non-Novell ZENworks Network Access Control) host, which then
sends relevant endpoint device information back to Novell ZENworks Network Access Control.
NOTE:
Windows Server 2003 is the only server supported for this release.
To install the DHCP plug-in:
1
The DHCP plug-in requires that you first configure your system with RDAC as described in
Section 13.1, “Creating a DAC Host,” on page 295
.
2
On the Novell ZENworks Network Access Control MS, enter the following commands and
follow the on-screen instructions:
2a
/usr/local/nac/bin/MakeDHCPCert
This command generates a file named
server.pem
in the current directory. This file
contains a key and certificate signed by the CA. The DHCP plug-in responds to SSL
connections from Novell ZENworks Network Access Control by providing this
certificate.
2b
Copy the
server.pem
file (from the directory where it was created in
Step 2a
above) to
the
C:\WINDOWS\system32\dhcp
directory.
2c
After copying the
server.pem
file from the Novell ZENworks Network Access
Control server, delete the file from its temporary location on the Novell ZENworks
Network Access Control server
Содержание ZENworks Network Access Control 5.0
Страница 4: ...4 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 14: ...14 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Glossary 525 ...
Страница 136: ...136 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 156: ...156 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 216: ...216 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 224: ...224 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 226: ...226 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 Figure 8 1 Inline Installations ...
Страница 227: ...High Availability and Load Balancing 227 novdocx en 24 March 2009 Figure 8 2 DHCP Installation ...
Страница 234: ...234 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 294: ...294 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 310: ...310 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 328: ...328 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 378: ...378 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 384: ...384 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 392: ...392 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 436: ...436 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 442: ...442 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 450: ...450 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 460: ...460 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 524: ...524 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...
Страница 534: ...534 Novell ZENworks Network Access Control Users Guide novdocx en 24 March 2009 ...