Solved

Blocking non domain computers with Fixed IP

Posted on 2012-12-31
4
28 Views
Last Modified: 2016-04-05
Hi All,

I have implemented NAP using IPsec with HRA and it seems to be working fine for computers failing health check for both domain and non domain computers. But when the computers use Static IP address, the whole thing gets bypassed.

Any ideas with regards to this would be welcome.

regards,

Arun.
0
Comment
Question by:arunaci
4 Comments
 

Accepted Solution

by:
loaganathan earned 200 total points
Comment Utility
If you choose a NAP enforcement method, then all domain computers will need to be running the NAP agent service. Computers that are not running this service can't be evaluated for domain membership because the FQDN for the computer is sent as part of the NAP packet (the statement of health). The exception to this is 802.1X with NAP where the SoH isn't needed to evaluate domain membership.

For example, you could use NAP with DHCP enforcement, which is the simplest to configure. You would then create a policy that requires a computer to be a member of "domain computers" to be granted access. Other computers will be denied access. However, a non-domain computer can still configure a static IP address if they guess the correct range and gain access this way.

If you deploy IPsec enforcement you will need a certificate infrastructure (a PKI). In this case, non-domain computers will not be given a certificate and computers without certificates can be blocked with IPsec policies.

The other method you can use is 802.1X. You can also use NAP here, but it isn't necessary. Just create a policy that evaluates computers based on domain membership. An 802.1X access request contains the computer's domain so it isn't necessary here to run NAP agent
0
 

Author Comment

by:arunaci
Comment Utility
If you deploy IPsec enforcement you will need a certificate infrastructure (a PKI). In this case, non-domain computers will not be given a certificate and computers without certificates can be blocked with IPsec policies.

The other method you can use is 802.1X. You can also use NAP here, but it isn't necessary. Just create a policy that evaluates computers based on domain membership. An 802.1X access request contains the computer's domain so it isn't necessary here to run NAP agent

Shall try this and get back

Thank u for pointing me in a direction

Regards,

Arun
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Join & Write a Comment

Defense in depth is one of the most important security principles that no one disagrees with, it simply states that IT security must be handled at different layers without neglecting any of them relying on other or others.  If I tried to clarify the…
Read about achieving the basic levels of HRIS security in the workplace.
This video discusses moving either the default database or any database to a new volume.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now