- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: IDM with NAP, "unknow" status problem
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-10-2009 05:46 AM
тАО12-10-2009 05:46 AM
IDM with NAP, "unknow" status problem
I'am making deployment of HP Procurve Manager with IDM and NAP for one of my client.
I am using 802.1x authorization mechanisms and NAP based on Windows Server 2008 wich acts as Radius Server in this case.
I have made standard configuration steps (according to Microsoft NAP - Step by step and Hp documents):
- created realm
- sync AD groups & users form Domain Controler
- installed IDM agent on Win Server 2008 and connected with IDM
- created policy 802.1x with NAP on Windows Serv 2008 with appropriate wizard
- created Access Profiles for Access Profiles Groups in IDM
- deployed access profiles to the realm
- created policy group on Dimain Controler's AD for client station for automatic NAP configuration
- configured switch with IDM Secure Access Wizard
I have problem with NAP status for some hosts in the LAN:
IDM gets Endpoint Security status as UNKNOW although :
- NAP agent service on the station is activated
- NAP enforcement client for EAP is started
- NAP status is ok (complaint)
I have checked a lot of things but I haven't found any reason.
Please help
best regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2009 12:00 AM
тАО12-11-2009 12:00 AM
Re: IDM with NAP, "unknow" status problem
- MS-Quarantine-State=0x1=Quarantined
AND
- Not-Quarantine-Capable=0x1=Endpoint does not send SoH
This may be caused by one of the following:
- Client does not support NAP
- NAP Agent is not started on client
- The ├в Enable Quarantine checks├в check-box is not marked under LAN properties/Protected EAP Properties
---
An "any" IDM Endpoint Integrity status occur if the check-box called ├в RADIUS client is NAP capable├в is not marked on the NPS server on the RADIUS clients settings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2009 03:58 AM
тАО12-11-2009 03:58 AM
Re: IDM with NAP, "unknow" status problem
Thanks a lot, really,
I have lost a lot of time finding solutions.
You really helped me.
The problem was with Enable Quarantine checks in LAN Connection settings under EAP. I have overlooked this setting and it wasn't mentioned in the Microsoft and HP documentation.
Do you know is it possible to set this settings in Active Directory to automate turning it on by creating Group Policy or something like this?
Thanks once more
best regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2009 01:11 PM
тАО12-11-2009 01:11 PM
Re: IDM with NAP, "unknow" status problem
For configuring 802.1X including the NAP settings through GPO for the wired LAN interface the Windows Domain must either be a native Windows 2008 domain or you need to do an AD schema extention on your 2003 domain.
Below is a good blog from Microsoft which as pretty valuable information on this topic, especially the last entry.
Have fun.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-11-2009 01:14 PM
тАО12-11-2009 01:14 PM
Re: IDM with NAP, "unknow" status problem
http://social.technet.microsoft.com/Forums/en/winserverNAP/thread/8df1735b-1022-4455-b3f2-2c7545ff47e1