7.1 Endpoint Quarantine Precedence

Endpoints are quarantined in the following hierarchical order:

  1. Access mode (normal operation or allow all)

  2. Temporarily quarantine for/Temporarily grant access for radio buttons

  3. Endpoint testing exceptions (always grant access, always quarantine)

  4. Post-connect (external quarantine request)

  5. NAC policies

NOTE:In DHCP mode, if an endpoint with an unsupported OS already has a DHCP-assigned IP address, Novell ZENworks Network Access Control cannot affect this endpoint in any way until the lease on the existing IP address for that endpoint expires. If an endpoint with an unsupported OS has a static IP address, Novell ZENworks Network Access Control cannot affect this endpoint in any way. In both of these cases, the System Monitor window may show the quarantined icon next to these endpoints; however, if you hover your mouse over the post-connect service icon, the actual status shows that the endpoint should be quarantined, but the quarantine action was unsuccessful.

The following describes the process in more detail:

HINT:Use the Clear temporary access control status radio button to remove the temporary access or temporary quarantine state enabled by the Temporarily quarantine for/Temporarily grant access for radio buttons.

HINT:The change access button on the System Configuration>>Endpoint activity window is enabled only when the action is possible; for example, when an endpoint or endpoints are selected.