Always Quarantining An Endpoint; New Users; Shared Resources - Novell ZENWORKS NETWORK ACCESS CONTROL 5.0 - 09-22-2008 User Manual

Table of Contents

Advertisement

IMPORTANT: Please read
page 222
so that you fully understand the ramifications of allowing untested endpoints on your
network.

7.4 Always Quarantining an Endpoint

To always quarantine a an endpoint without testing (cluster default):
Home window>>System configuration>>Exceptions
1 In the Blacklist area:
1a In the Endpoints area, enter one or more MAC addresses, IP addresses, or NetBIOS
names separated by carriage returns.
1b In the Windows domains area, enter one or more domain names separated by carriage
returns.
2 Click ok.
IMPORTANT: If you enter the same endpoint for both options in the Endpoint testing exceptions
area, the Allow access without testing option is used.

7.5 New Users

The process Novell ZENworks Network Access Control follows for allowing end-users to connect
is:
Inline mode — An IP address is assigned to the endpoint outside of Novell ZENworks
Network Access Control. When the end-user attempts to connect to the network, Novell
ZENworks Network Access Control either blocks access or allows access by adding the
endpoint IP address to the internal firewall.
DHCP mode — New end-users boot their computers. The boot process looks for an IP address
and, because they are new end-users and no information is known about the endpoints, a
temporary quarantined IP address is assigned. The end-users log in on the Windows login
screen. The end-users start IE and Novell ZENworks Network Access Control attempts to test
the endpoint. The endpoints either retain the quarantined IP address, or are assigned a non-
quarantined network IP address based on the testing result.
802.1X mode — An endpoint attempts to connect to the network. The end-user's identity is
verified via an authentication server. If the endpoint is not authenticated, it is quarantined
(allowed access to a limited VLAN). If the endpoint is authenticated, it is tested by Novell
ZENworks Network Access Control. If the endpoint fails the Novell ZENworks Network
Access Control testing, it is quarantined (allowed access to a limited VLAN). If the endpoint
passes the Novell ZENworks Network Access Control testing, it is allowed access to the
network (VLAN).

7.6 Shared Resources

If the end-users typically make connections to shared services and endpoints during the boot
process, these shares are unable to connect while the endpoint has the quarantined IP address, unless
the services and endpoints are listed in the Accessible services and endpoints area (see
Section 7.7, "Untestable Endpoints and DHCP Mode," on
Quarantined Networks 221

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zenworks network access control 5.0

Table of Contents