3.10 Quarantining, General

The Quarantining menu option allows you to configure the following by cluster:

The following sections contain more information:

3.10.1 Selecting the Quarantine Method

To select the quarantine method:

Home window>>System configuration>>Quarantining

Figure 3-20 System Configuration, Quarantining

  1. Select a cluster.

  2. In the Quarantine method area, select one of the following quarantine methods:

    • 802.1X — When using the 802.1X quarantine method, Novell ZENworks Network Access Control must sit in a place on the network where it can communicate with your RADIUS server, which communicates with your switch or router, which performs the quarantining.

    • DHCP — When configured with a DHCP quarantine area, Novell ZENworks Network Access Control must sit inline with your DHCP server. All endpoints requesting a DHCP IP address are issued a temporary address on a quarantine subnetwork. Once the endpoint is allowed access, the IP address is renewed, and the main DHCP server assigns an address to the main LAN. With a multiple subnetwork or VLAN network, one quarantine area must be configured for each subnetwork. See Section 13.0, Remote Device Activity Capture for information on using multiple DHCP servers.

    • Inline — When using the inline quarantine method, Novell ZENworks Network Access Control must be placed on the network where all traffic to be quarantined passes through Novell ZENworks Network Access Control. It must be inline with an endpoint like a VPN.

  3. Click ok.

3.10.2 Selecting the Access Mode

To select the access mode:

Home window>>System configuration>>Quarantining

  1. Select one of the following in the Access mode area:

    • normal — Either allows or quarantines endpoints depending on the setup of the enforcement sever.

    • allow all — Endpoints are tested; however, they are always given access to the production network.

NOTE:If you are setting up a cluster for the first time, and you have not yet added an ES, select allow all until you have finished configuring Novell ZENworks Network Access Control.