Extreme Networks Sentriant AG Software User's Manual page 378

Hide thumbs Also See for Sentriant AG:
Table of Contents

Advertisement

Enforcement Server Processes and Threads
Table 19: Enforcement Server Processes and Threads
Process
input chain sapq
nac-es
named
nmbd
ntpd
p0f
378
Enforcement
Description
mode
DHCP
Determines whether an
endpoint should be
granted access to the
onboard DHCP server.
All
The core management
process for endpoint
enforcement, this process
coordinates the functions
of the entire system.
DHCP and
Provides domain name
802.1X
services (DNS) to
endpoints in quarantined
networks. Used to force
endpoints to access the
end-user screens or to
grant them access via the
ES's default gateway.
802.1X with
Responds to NetBIOS
NTLM
name lookup requests and
authentication
assists in joining the ES
to the domain.
All
Provides clock
synchronization between
ESs and the MS, which
ensures messages sent to
other ESs or the MS are
properly synchronized and
system logging is
effective.
All
Helps determine the
operating system of
endpoints, which in turn,
helps determine which
endpoints are testable.
Criticality
Failure implications
High
If the
nac-es
process is also
down, all endpoints are granted
network access. Otherwise,
endpoints that should be
quarantined will not receive
quarantine DHCP leases and,
therefore, will not be granted
access to the network.
High
If the enforcement cluster (EC)
has other enforcement servers
(ESs), the other ESs will take
over endpoint enforcement,
one of the primary benefits of
multi-server clustering: high
availability.
If the ES is not in a cluster or
is the last functioning ES in a
cluster, all endpoints will be
granted network access.
High
If this prcoess is down,
endpoints are unable to
perform DNS lookups from the
quarantine network, essentially
disabling access to any
network. In addition, endpoints
are not redirected to the end-
user screens.
High
If this process is down, switch
proxy requests are blocked at
the ES, and endpoints will be
unable to authenticate on the
network.
Medium
If this process is down for a
short time, the effect is likely
to be minimal. If it is down for
long periods, anomolous
failures might occur within the
system.
Low
Out of multiple methods, this
process is the least significant
method used to determine
endpoint operating systems.
Therefore, the impact is
minimal if this process is
down.
Sentriant AG Software Users Guide, Version 5.3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentriant ag 5.3

Table of Contents