Matching Windows Domain Policies To Nac Policies; Setting The Access Mode - Novell ZENWORKS NETWORK ACCESS CONTROL 5.0 - 09-22-2008 User Manual

Table of Contents

Advertisement

When the end-user logs in, they will be able to authenticate from quarantine even if credentials are
not cached:
-> lookup the _kerberos and _ldap service location
<- receive dc01.mycompany.com& dc02.mycompany.com
-> lookup the dc01 IP address
<- receive the dc IP address forwarded through Novell ZENworks Network Access Control
named to the real DNS server (since dc01.mycompany.com is in the accessible services list).
-> authenticate

16.5.2 Matching Windows Domain Policies to NAC Policies

Using a Windows domain might affect the end-user's ability to change their system configuration to
pass the tests. For example, in a corporate environment, each machine gets their domain information
from the domain controller, and the user is not allowed to change any of the related settings, such as
receiving automatic updates and other IE security settings.
The Novell ZENworks Network Access Control administrator needs to make sure the global policy
on their network matches the NAC policy defined, or skip the test.
For example, if the global network policy is to not allow Windows automatic updates, any user
attempting to connect through the High security NAC policy fails the test, and is not able to
change their endpoint settings to pass the test.
For example, to change the NAC policy to not run the Windows automatic update
test:
Home window>>NAC policies
1 Select the NAC policy that tests the domain's endpoints.
2 Select the Tests menu option.
3 Clear the Windows automatic updates check box.
4 Click ok.

16.5.3 Setting the Access Mode

The access mode selection is a quick way to select enforcement (normal mode) for all traffic into an
Enforcement cluster, or open it up for trial-use purposes (allow all).
To change the access mode:
Home window>>System monitor>>Select an Enforcement cluster
1 Select one of the following from the Access mode area:
normal — Access is regulated by the NAC policies
allow all — All requests for access are granted, but endpoints are still tested
2 Click ok.
334 Novell ZENworks Network Access Control Users Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zenworks network access control 5.0

Table of Contents