16.15 Working with Ranges

In Novell ZENworks Network Access Control implementations, particularly in trial installations where you are connecting and disconnecting cables to a number of different types of endpoints, you can filter the activity by specifying the following:

To specify ranges to monitor:

Home window>>System configuration>>Select an Enforcement Cluster>>Advanced menu option

In the Endpoint detection area, enter the range of addresses to monitor in the IP addresses to monitor text field. Separate ranges with a hyphen or use CIDR notation.

To specify ranges to ignore:

Home window>>System configuration>>Enforcement clusters & servers>>Select an Enforcement Cluster>>Advanced menu option

In the Endpoint detection area, enter the range of addresses to ignore in the IP addresses to ignore text field. Separate ranges with a hyphen or use CIDR notation.

To specify ranges to enforce:

Home window>>System configuration>>Quarantining menu option

  1. Select the DHCP radio button in the Quarantine method area.

  2. Select the Restrict enforcement of DHCP requests to quarantined or non-quarantined subnets radio button.

  3. Enter IP addresses in the DHCP relay IP addresses to enforce text box. Enter individual DHCP relay agent IP addresses, separated by carriage returns. These addresses are monitored in addition to the quarantined or non-quarantined subnets.

    NOTE:When using Extreme switches running ExtremeWare or ExtremeXOS prior to release 11.6, DHCP relay IP addresses to enforce will NOT work when the quarantine subnet is a subset of the production network. This is because Extreme switches forward the packets from the IP address closest to Novell ZENworks Network Access Control and not the IP address of the interface closest to the endpoint, so all the DHCPRelay packets will appear to come from a production network IP address.

    For example, the following scenario will not work:

    • Novell ZENworks Network Access Control IP: 10.241.88.20
    • Production Network: 10.241.90.0/24
    • Quarantine Network: 10.241.90.160/27 (161-189 for range)
    • Gateway IP: 10.241.90.190
    • Non-Quarantine Networks: 10.241.90.0/25, 10.241.90.128/27, 10.241.90.192/26