Chapter 7: Quarantined Networks; Endpoint Quarantine Precedence - Extreme Networks Sentriant AG Software User's Manual

Version 5.2
Hide thumbs Also See for Sentriant AG:
Table of Contents

Advertisement

7
Quarantined Networks
This chapter describes the following general Sentriant AG quarantine information:
"Endpoint Quarantine Precedence" on page 233
"Using Ports in Accessible Services and Endpoints" on page 234
"Always Granting Access to an Endpoint" on page 236
"Always Quarantining an Endpoint" on page 237
"New Users" on page 237
"Shared Resources" on page 238
"Untestable Endpoints and DHCP Mode" on page 238

Endpoint Quarantine Precedence

Endpoints are quarantined in the following hierarchical order:
1 Access mode (normal operation or allow all)
2 Temporarily quarantine for/Temporarily grant access for radio buttons
3 Endpoint testing exceptions (always grant access, always quarantine)
4 Post-connect (external quarantine request)
5 NAC policies
NOTE
In DHCP mode, if an endpoint with an unsupported OS already has a DHCP-assigned IP address, Sentriant AG
cannot affect this endpoint in any way until the lease on the existing IP address for that endpoint expires. If an
endpoint with an unsupported OS has a static IP address, Sentriant AG cannot affect this endpoint in any way. In
both of these cases, the System Monitor window may show the quarantined icon next to these endpoints; however, if
you hover your mouse over the post-connect service icon, the actual status shows that the endpoint should be
quarantined, but the quarantine action was unsuccessful.
The following describes the process in more detail:
Access mode (1) overrides the items below it in the previous list (2, 3, 4, and 5). Use the Access
mode radio buttons (System monitor>>select a cluster>>Quarantining) to act globally on all
endpoints in an Enforcement cluster.
The Temporarily quarantine for/Temporarily grant access for radio buttons (Endpoint
activity>>select an endpoint check box>>Change access) override the items below them in the list
(3, 4, and 5).
Use Temporarily quarantine for to temporarily quarantine endpoints that:
Sentriant AG Software Users Guide, Version 5.2
233

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentriant ag 5.2

Table of Contents