Re: NAC, network access control?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"fairchild" <echovoice@xxxxxxxxx> wrote in message
news:1185435220.924275.176260@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
can ISA 2004/2006 do network access control, NAC?

Network Access Control just simply means to "control access to the network".
Yes, ISA does that,..even if it doesn't do the things you list.

i want to be able to filter machines,

Yes.
If machines have static IP#s then it can allow/deny based on the IP#.

only allow windows based machines,

No. ISA does no know or care what OS runs on the machine.

force the first internet explorer window to the simple
registration page

No. That is a Kiosk system,..like Hotels and Internet Cafes use.
ISA authenticates against User Accounts that are either local to the ISA or
are in Active Directory,..that is a lot more deep and a lot more secure than
a "registration page".

and fingerprint the machine,

ISA does have a VPN Quarentine section for VPN connections. I have no idea
if that is what you are asking.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


.



Relevant Pages

  • Re: Unable to browse shared folders on DC
    ... Windows IP Configuration ... Connection-specific DNS Suffix. ... So you're using ISA, ... EventID 1517 can be cleaned up by installing the UPHClean on all machines, ...
    (microsoft.public.windows.server.active_directory)
  • Re: SBS 2003 Premium and ISA 2004
    ... factor connecting such machines to your internal LAN when they are on-site. ... have the ISA client installed on them [which with ISA 2004 is clever enough ... and change SBS internet Access policy from SBS Internet ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA and hardware firewall
    ... If you can not present a mandate from your cats that you can speak for them, ... ISA has never been hacked. ... can put certain machines in the DMZ between the two firewalls,..but you ... But then if those machines need to contact the LAN or the ...
    (microsoft.public.isa.configuration)
  • Re: VLANS, subnets
    ... machines in there. ... The clients in VLAN1 all have ISA fw clients, ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa)
  • Re: Active directory authentication
    ... I can get ISA to do everything except AD authentication. ... >>trying to complete a client logon to an Active Directory ... >>to join machines to the domain from behind ISA Server. ...
    (microsoft.public.isa)