Installation Overview - Novell ZENWORKS NETWORK ACCESS CONTROL 5.0 - 09-22-2008 User Manual

Table of Contents

Advertisement

The following connection and communication actions apply:
If the connection between the DHCP server and the Novell ZENworks Network Access
Control server is lost and re-established, the existing ACL on the DHCP server is discarded and
Novell ZENworks Network Access Control re-transmits the entire ACL.
If the DHCP server cannot communicate with Novell ZENworks Network Access Control at
any time, the DHCP server goes in to an allow all or deny all state, depending on the
failopen parameter setting in the config.xml file (true = allow all, false = deny all).
Novell ZENworks Network Access Control attempts to connect to known DHCP servers on
start-up, and continuously attempts to connect at regular intervals indefinitely.
The following sections contain more information:
Section 15.1, "Installation Overview," on page 318
Section 15.2, "DHCP Plug-in and the Novell ZENworks Network Access Control User
Interface," on page 320

15.1 Installation Overview

When Novell ZENworks Network Access Control does not sit inline with the DHCP server, you
need to set up a remote host for Device Activity Capture (DAC) to allow Novell ZENworks
Network Access Control to listen on the network. This is done by installing a small program on the
DHCP server or other remote (non-Novell ZENworks Network Access Control) host, which then
sends relevant endpoint device information back to Novell ZENworks Network Access Control.
NOTE: Windows Server 2003 is the only server supported for this release.
To install the DHCP plug-in:
1 The DHCP plug-in requires that you first configure your system with RDAC as described in
Section 13.1, "Creating a DAC Host," on page
2 On the Novell ZENworks Network Access Control MS, enter the following commands and
follow the on-screen instructions:
2a /usr/local/nac/bin/MakeDHCPCert
This command generates a file named server.pem in the current directory. This file
contains a key and certificate signed by the CA. The DHCP plug-in responds to SSL
connections from Novell ZENworks Network Access Control by providing this
certificate.
2b Copy the server.pem file (from the directory where it was created in
the C:\WINDOWS\system32\dhcp directory.
2c After copying the server.pem file from the Novell ZENworks Network Access
Control server, delete the file from its temporary location on the Novell ZENworks
Network Access Control server
318 Novell ZENworks Network Access Control Users Guide
295.
Step 2a
above) to

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zenworks network access control 5.0

Table of Contents