NAP enforcement and network restriction
NAP enforcement settings allow you to limit network access of
noncompliant clients to a restricted network, to defer restriction to
a later date, or to merely monitor and log the health status of NAP-
capable client computers. The following settings are available:
• Allow full network access. This is the default setting. Clients that
match the policy conditions are granted unrestricted access to the
network if the connection request is authenticated and authorized. The
health compliance status of NAP-capable client computers is logged.
• Allow limited access. Client computers that match the policy
conditions are placed on the restricted network.
• Allow full network access for a limited time. Clients that match the
policy conditions are temporarily granted full network access. NAP
enforcement is delayed until the specified date and time.
You will create two network policies in this test lab. A compliant
policy will grant full network access to an intranet network segment.
A noncompliant policy will demonstrate network restriction by applying
IP filters to the VPN tunnel interface that only allow client access
to a single remediation server.