Managed Endpoints; Unmanaged Endpoints; Making Changes To The Firewall; Windows Endpoint Settings - Novell ZENWORKS NETWORK ACCESS CONTROL 5.0 - 09-22-2008 User Manual

Table of Contents

Advertisement

The following sections contain more information:
Section 5.4.1, "Managed Endpoints," on page 160
Section 5.4.2, "Unmanaged Endpoints," on page 160
Section 5.4.3, "Making Changes to the Firewall," on page 160

5.4.1 Managed Endpoints

Typically, a managed endpoint's firewall is controlled with the Domain Group Policy for Windows,
or a central policy manager for other firewalls. In this case, the network administrator opens up the
agent port or agentless ports only to the Novell ZENworks Network Access Control server using the
centralized policy.
If the Domain Group Policy is not used for Windows endpoints, the appropriate ports are opened
during the agent installation process by the Novell ZENworks Network Access Control installer.

5.4.2 Unmanaged Endpoints

For unmanaged endpoints, the NAC Agent and the ActiveX control test methods automatically open
the necessary ports for testing.
End-users connecting with Windows XP, but a non-SP2 firewall (such as Norton) must configure
that firewall to allow connection to Novell ZENworks Network Access Control on port 1500, or the
installation of the agent fails.

5.4.3 Making Changes to the Firewall

See the following sections for instructions:
Section 5.5, "Windows Endpoint Settings," on page 160
Section 5.6.2, "Allowing Novell ZENworks Network Access Control through the OS X
Firewall," on page 171

5.5 Windows Endpoint Settings

The following sections contain more information:
Section 5.5.1, "IE Internet Security Setting," on page 160
Section 5.5.2, "Agent-based Test Method," on page 161
Section 5.5.3, "Agentless Test Method," on page 161
Section 5.5.4, "ActiveX Test Method," on page 170

5.5.1 IE Internet Security Setting

If the end-user has their IE Internet security zone set to High, the endpoint is not testable. Using one
of the following options will allow the endpoint to be tested:
The end-user could change the Internet security to Medium (Tools>>Internet
options>>Security>>Custom level>>Reset to Medium).
160 Novell ZENworks Network Access Control Users Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zenworks network access control 5.0

Table of Contents