Novell ZENWORKS NETWORK ACCESS CONTROL 5.0 - 09-22-2008 User Manual page 155

Table of Contents

Advertisement

How endpoints are quarantined and
Enforcement Mode
redirected to Novell ZENworks Network
Access Control
802.1X
DHCP server (MS DHCP server, and
so on) gives the endpoint:
ACLs on network devices must be
configured to limit where endpoints on
the quarantine VLAN can go.
Iptables prerouting chains rewrite traffic
coming from quarantine subnets (as
defined in the user interface) and
destined for Novell ZENworks Network
Access Control (due to Novell
ZENworks Network Access Control
DNS) so that:
Novell ZENworks Network Access
Control:80 --> Novell ZENworks
Network Access Control:88
Novell ZENworks Network Access
Control:443 --> Novell ZENworks
Network Access Control:89
Traffic coming from non-quarantine
ranges will not be rewritten, so that
users can get to the Novell ZENworks
Network Access Control user interface
on port 443.
NOTES:
(*) The gateway does not have to be in the broadcast domain (which is good, since the netmask
gives the endpoint on real broadcast domain), as long as it is in the same (Layer 2) subnet—the
router will get you there.
(**) Allowing access to the Internet is up to the customer, but is necessary for access to any IP
addresses in Accessible services (System configuration>>Cluster setting defaults
area>>Accessible services).
Quarantine range IP address
Appropriate netmask for
quarantine subnet
Appropriate default gateway
Novell ZENworks Network Access
Control server's IP as DNS server
(will resolve everything except
Accessible services to the
Novell ZENworks Network Access
Control IP address)
Very low DHCP lease time (~3
minutes)
How quarantined endpoints reach
accessible devices
Novell ZENworks Network Access
Control DNS — As in endpoint
enforcement (for access to names in
Accessible services)
ACLs on the switch prevent
quarantined systems from talking to
production systems, but allow for the
following specific traffic:
Quarantine --> Novell ZENworks
Network Access Control (OK)
Production -?-> Quarantine
(Maybe*)
Quarantine -|-> Production (NO)
Quarantine -?-> Internet
(Maybe**)
Endpoint Activity 155

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zenworks network access control 5.0

Table of Contents