Step By Step Guide: Demonstrate VPN NAP Enforcement in a Test Lab

25 views
Skip to first unread message

مهندس الشبكات

unread,
Mar 29, 2011, 10:14:52 PM3/29/11
to مهندس الشبكات
Network Access Protection (NAP) is a new technology introduced in
Windows Vista® and Windows Server® 2008. (NAP can also be deployed on
computers running Windows Server 2008 R2 and Windows 7). NAP includes
client and server components that allow you to create and enforce
health requirement policies that define the required software and
system configurations for computers that connect to your network. NAP
enforces health requirements by inspecting and assessing the health of
client computers, limiting network access when client computers are
deemed noncompliant, and remediating noncompliant client computers for
unlimited network access. NAP enforces health requirements on client
computers that are attempting to connect to a network. NAP also
provides ongoing health compliance enforcement while a compliant
client computer is connected to a network.
In addition, NAP provides an application programming interface (API)
set that allows non-Microsoft software vendors to integrate their
solutions into the NAP framework.
NAP enforcement occurs at the moment client computers attempt to
access the network through network access servers, such as a virtual
private network (VPN) server running Routing and Remote Access, or
when clients attempt to communicate with other network resources. The
way in which NAP is enforced depends on the enforcement method you
choose.
NAP enforces health requirements for the following:
• Internet Protocol security (IPsec)-protected communications
• Institute of Electrical and Electronics Engineers (IEEE) 802.1X-
authenticated connections
• VPN connections
• Dynamic Host Configuration Protocol (DHCP) configuration
• Terminal Services Gateway (TS Gateway)
The step-by-step instructions in this paper will show you how to
deploy a NAP VPN enforcement test lab so that you can better
understand how VPN enforcement works.

مهندس الشبكات

unread,
Mar 29, 2011, 10:19:01 PM3/29/11
to مهندس الشبكات
NAP enforcement and network restriction
NAP enforcement settings allow you to limit network access of
noncompliant clients to a restricted network, to defer restriction to
a later date, or to merely monitor and log the health status of NAP-
capable client computers. The following settings are available:
• Allow full network access. This is the default setting. Clients that
match the policy conditions are granted unrestricted access to the
network if the connection request is authenticated and authorized. The
health compliance status of NAP-capable client computers is logged.
• Allow limited access. Client computers that match the policy
conditions are placed on the restricted network.
• Allow full network access for a limited time. Clients that match the
policy conditions are temporarily granted full network access. NAP
enforcement is delayed until the specified date and time.
You will create two network policies in this test lab. A compliant
policy will grant full network access to an intranet network segment.
A noncompliant policy will demonstrate network restriction by applying
IP filters to the VPN tunnel interface that only allow client access
to a single remediation server.
Reply all
Reply to author
Forward
0 new messages