Appendix F: Enforcement Server Processes And Threads; Table 19: Enforcement Server Processes And Threads - Extreme Networks Sentriant AG Software User's Manual

Hide thumbs Also See for Sentriant AG:
Table of Contents

Advertisement

F
Enforcement Server Processes and Threads
The following table describes the processes and threads on an enforcement server (ES), along with the
implications of each process or thread failing:

Table 19: Enforcement Server Processes and Threads

Enforcement
Process
mode
client manager
All
dhcpd
DHCP
endpoint activity
All modes when
capture
RDAC is not in
use
forward chain
DHCP inline or
sapq
static route
mode
Sentriant AG Software Users Guide, Version 5.3
Description
Reads
test service
responses and delivers
the connection to a new
thread for further
processing.
Vends IP addresses to
endpoints which are
placed in the quarantine
network.
Captures information
about endpoint activity.
Notifies the
nac-es
process when new
endpoints attempt
network connections or
when existing endpoints
renew their DHCP leases.
Determines whether an
endpoint should be
granted access to the
production DHCP server.
Criticality
Failure implications
High
If this process is down, the
system cannot test endpoints
to determine their compliance
status:
Endpoints in quarantine
will not be able to gain
network access.
Endpoints assigned to a
NAC policy with a Trust
level of guilty until proven
innocent will be
quarantined once the retest
interval (defined by the
NAC policy's Retest
frequency) has expired.
nac-es
High
If the
process is also
down, all endpoints are granted
network access. Otherwise,
endpoints that should be
quarantined will not receive
quarantine DHCP leases and,
therefore, will not be granted
access to the network.
High
If this process is down, the
nac-es
process receives no
information about endpoint
activity outside any of the
internal networks. Therefore,
Sentriant AG will not see
endpoints unless they
specifically contact the ES to
gain network access.
High
If this process is down,
endpoints will not be able to
access the production DHCP
server and, therefore, will not
be able to move out of the
quarantine network and might
not have a DHCP lease at all.
377

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentriant ag 5.3

Table of Contents