Dns/Windows Domain Authentication And Quarantined Endpoints - Extreme Networks AG200 User Manual

Version 5.0
Table of Contents

Advertisement

NOTE
It is strongly recommended that if you are going to allow untested endpoints on your network, you set extremely
short lease times (use hours rather than days) on your DHCP server.
This process results in the following condition for an untested endpoint:
When new end-users log in for the first time, are tested, and are allowed access, there is up to a three-
minute delay between the time the Sentriant AG server determines that they are allowed access and the
point at which they are actually allowed access, potentially causing concern to the end-user. This
uncertainty is due to the three-minute lease on the temporary quarantined IP address assigned during
the initial login process. Once the lease expires (in at most, three minutes), a new IP address (the non-
quarantined IP address) can be assigned and access is actually granted.
To define access settings for non-supported operating systems, see "Defining Non-supported OS Access
Settings" on page 196.
DNS/Windows Domain Authentication and Quarantined
Endpoints
In order to satisfy the following scenarios:
A guest user gets redirected
A user is redirected if their home page is the Intranet
The only host that is resolved is the domain controller (DC); and no other intranet hosts are resolved.
Windows domain authentication can take place from quarantine with minimal configuration
Perform the following steps:
1 Configure the domain suffixes in the quarantine areas to a placeholder, such as the following:
quarantine.bad
2 Enter the full domain controller hostnames in the System configuration>>Accessible services area
(for example, dc01.mycompany.com, dc02.mycompany.com ).
3 Ensure that each ES has a valid, fully qualified domain name (FQDN) and that the domain portion
matches the domain for the registered windows domain.
4 Ensure that each ES is configured with one or more valid DNS servers that can fully resolve (both A
and PTR records) each ES.
Sentriant AG Users' Guide, Version 5.0
Quarantined Networks
213

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentriant ag

Table of Contents