Table of Contents
Deploying Network Access Quarantine Control, Part 2 is easier to understand when the core ideas are paired with practical examples. The sections below explain the topic clearly, highlight useful steps, and point out details that can prevent common errors.
I stepped qua cách làm việc truy cập của quarantine mạng (NAQC) works and đã cung cấp chi tiết điều khiển instructions. In the second and final installment, I'll continue the procedure by finishing the deployment, then discuss how ISA Server 2004's entrance to the marketplace changes the fields of NAQC and how quarantining is implemented within the ISA Server itself.
Let's start thì bạn còn tắt.
Distributing the Profile to Remote Users
Configuring the Quarantine Policy
If it is configured to use the Windows authentication provider, then RRAS uses Active Directory or an NT 4 domain (remember, the RRAS machine needs only to run Windows Server 2003; it doesn't need to belong to an Active Directory-based domain ) để xác định người dùng và xem ở các tài khoản tài khoản của bạn. Nếu RRAS là cấu hình để sử dụng RADIUS, có thể máy RADIUS phải là một Server 2003 machine running IAS. Incidentally, IAS also uses Active Directory or xác thực NT thành công cần dùng và xem ở các tài khoản tài khoản.
Configuring RRAS
-
Open the RRAS Manager.
-
In the left-pane, right-click Remote Access Policies, and then select New Remote Access Policy from the context menu. Click Next trong các tập tin introductory.
-
The Policy Configuration Method page appears. Hãy nhập Quarantined VPN kết nối xa cho tên của này policy, shown shown Figure 4. Click Next when you're finished.
Figure 4: The Policy Configuration Method screen -
The Access Method page appears. Select VPN, and then click Next.
-
On người dùng hoặc truy cập Access Group, select Group, và Then click Add.
-
Bạn sẽ được trả lại để sử dụng người dùng hoặc truy cập Group Group, và sẽ tìm thấy nhóm này đã được đăng nhập trong danh sách danh sách, như được hiển thị Figure 5. Click Next if it looks correct.
Figure 5: Người dùng hayGroup Access screen. -
The Authentication Methods page appears. Để giữ thông báo này mới, sử dụng MS - CHAP v2 xác thực giao thức, mà được chọn bởi mặc định. Click Next.
-
Chỉ mục của tập tin Encryption của chế độ, xác định thiết lập Strongest đã đặt là chỉ tùy chọn chỉ. This is shown in Figure 6. Then, click Next.
Figure 6: the Policy Encryption Level screen -
Lỗi kết thúc từ thủ thuật bởi clicking Finish.
Configure attributes to be quarantined
Nếu bạn cần thực hiện cấu hình các thuộc tính sẽ được được assign đến sự lệnh quarantined.
-
Back in RRAS Manager, right-click on the new Quarantined VPN remote access policy, and select Properties from the context menu.
-
Navigate to the Advanced tab, and click Add to include another attribute in the list.
-
The Add Attribute dialog box is displayed, as depicted in Figure 7.
Figure 7: The Add Attribute dialog box -
Click MS-Quarantine-Session-Timeout, and then click Add.
-
Click Add. In the Attribute list, click MS-Quarantine-IPFilter, and then click Add again. Hãy xem IP Filter Attribute Information screen, as shown in Figure 8.
Figure 8: The IP Filter Attribute Information dialog box -
Hãy xem nút Thông tin khóa nhập, mà hiển thị các trong Inbound Filters box.
-
Click New để thêm bộ lọc đầu. The Add IP Filter dialog box is displayed. In the Protocol field, TCP select. In the Destination port field, enter 7250. Click OK.
-
Now, back to screen Screen Inbound, select the Permit only the packets listed below truy cập radio button. Your screen should look like Figure 9.
Figure 9: Tập tin in chế độ đã tải về -
Click New and add an filter input for a quarantine resource, such as a Web server, where your profile installer is located. Specify the IP address appropriate for tài nguyên trong phần Destination Network của Thêm IP Filter screen, as shown in Figure 10.
Figure 10: The Add IP Filter box, adding a quarantined Web resource -
Finally, click OK on the Inbound Filters dialog box to save danh sách bộ lọc.
-
On the Edit Dial-in Profile dialog box, click OK to save the changes to the profile settings.
-
Then, để lưu các thay đổi để chính sách, click OK once more.
Creating Exceptions to the Rule
Extending Functionality with ISA Server 2004
Quarantine Control cho ISA Server 2004 được làm việc với Routing và remote Access service, như được xác định đã hết hạn trong này article. The main difference is in the fact that with ISA Server, you can require that a client attempt to log in is assigned to the Quarantined VPN Clients network in ISA, with an associated firewall policy that is very stringent, until the Connection Manager is running on the desktop passes một thông báo để ISA đã biết người dùng được kiểm tra integrity. Like the plain vanilla NAQC technique, ISA quarantining does not rely on Connection Manager profiles and yêu cầu một cơ sở dữ liệu script để thực hiện là tùy chọn cho bạn môi trường.
ISA Server quarantining hỗ a more robust timeout feature, either, allowing clients to Remain in the Quarantined VPN Clients network for a specific number of seconds all before being disconnected, and It also hỗ an exception list, đó cho phép you to Identify users (via hoặc Active Directory or a RADIUS server) that should not be quarantined no matter what.
Các thông báo nghe về quarant được đã được nâng cấp được xác định cho hỗ trợ ISA Server và có sẵn trong các ISA Server 2004 Resource Kit, mà có thể được lấy từ Microsoft site.
To enable quarantining with ISA Server:
-
Open ISA Server Management.
-
On the left pane, expand the node that corresponds to your computer, and then click Virtual Private Networks (VPN).
-
In the right pane, navigate to the Tasks tab, and then click Enable VPN Client Access.
-
Now, expand the Configuration node and select Networks.
-
In the middle pane, click the Networks tab.
-
Double-click on Quarantined VPN Clients network to open the properties box for the network.
-
Navigate to the Quarantine tab. Đây là hiển thị trong Figure 11.
-
Click the 'Enable quarantine control' checkbox to allow quarantining to take place. Cảnh báo sẽ hiện thời hiện thời để thực hiện, bạn thực hiện khi thực hiện là hoạt động, và không có cấu hình không hợp lệ, các bạn sẽ được xác định quarantined.
-
Hãy chọn tùy chọn quarantine với RADIUS server Policies (tùy chọn first) or ISA Server policies (the second option).
-
Hãy nhập một lần thời
-
Click OK, and then Apply in the Management Server ISA console, to apply the changes.
Figure 11: Quarantined VPN Clients in ISA Server 2004
Bạn có thể xử lý các chế độ truy cập truy cập cho Quarantined VPN hệ thống các tập tin mà theo sau:
-
Allow truy cập truyền chuyển tới LDAP máy phục vụ trên máy ảnh nội bộ.
-
Allow traffic to được gửi qua cho các điều kiện domain.
-
Allow DNS, DHCP, and WINS traffic to be passed to a hardened set of DNS servers, có thể trên một perimeter network.
-
Allow traffic to a hardened, web server that contains software antivirus, signature and detection engine updates.
Conclusion
This guide, I've discussed quarantining using services included in Windows Server 2003 and its associated resource and feature packs, and I've also touched on the extended quarantine functionality within ISA Server. Nếu bạn sử dụng các cơ sở dữ liệu sẽ được hỗ trợ hoặc gỡ bỏ sự kết nối đã chia sẻ với máy ảnh khi bạn kết nối để kết nối.

About the author
Jonathan Hassell is an author and consultant specializing in Windows administration and security. He is the author of Managing Windows Server 2003 and RADIUS, both published by O'Reilly & Associates, and Hardening Windows, published by Apress. He also holds the periodic public seminars; see www.hardeningwin.com for details. He được ghi được cho Windows &.NET Thông báo và WindowsITSecurity.COM and là một contributor to PC Pro, leading computer magazine in the United Kingdom.
FAQ
What should you know about distributing the Profile to Remote Users Configuring the Quarantine Policy?
If it is configured to use the Windows authentication provider, then RRAS uses Active Directory or an NT 4 domain (remember, the RRAS machine needs only to run Windows Server 2003; it doesn't need to belong to an Active Directory-based domain ) để xác định.
What should you know about configure attributes to be quarantined?
Nếu bạn cần thực hiện cấu hình các thuộc tính sẽ được được assign đến sự lệnh quarantined.
What should you know about creating Exceptions to the Rule Extending Functionality with ISA Server 2004?
Quarantine Control cho ISA Server 2004 được làm việc với Routing và remote Access service, như được xác định đã hết hạn trong này article. The main difference is in the fact that with ISA Server, you can require that a client attempt to log in is assigned to.
Reader Comments 0
Sign in with email or Google to join the discussion.