Step by Step Guide: Demonstrate DHCP NAP Enforcement in A Test Lab
Step by Step Guide: Demonstrate DHCP NAP Enforcement in A Test Lab
Abstract
Network Access Protection (NAP is a new policy enforce!ent technolo"y in the #indows $ista% and #indows &er'er% 2008 and #indows (P with &er'ice Pack ) operatin" syste!s* (NAP can also be deployed on co!puters runnin" #indows &er'er 2008 +2, #indows -, #indows &er'er 20.2, and #indows 8 * NAP pro'ides co!ponents and an application pro"ra!!in" interface (AP/ set that help ad!inistrators enforce co!pliance with health re0uire!ents for network access and co!!unication* 1his paper contains an introduction to NAP and instructions for settin" up a test lab to deploy NAP with the 23CP enforce!ent !ethod*
Copyrig t !nformation
1his docu!ent is pro'ided for infor!ational purposes only and Microsoft !akes no warranties, either e4press or i!plied, in this docu!ent* /nfor!ation in this docu!ent, includin" 5+6 and other /nternet #eb site references, is sub7ect to chan"e without notice* 1he entire risk of the use or the results fro! the use of this docu!ent re!ains with the user* 5nless otherwise noted, the e4a!ple co!panies, or"ani8ations, products, do!ain na!es, e9!ail addresses, lo"os, people, places, and e'ents depicted herein are fictitious, and no association with any real co!pany, or"ani8ation, product, do!ain na!e, e9!ail address, lo"o, person, place, or e'ent is intended or should be inferred* Co!plyin" with all applicable copyri"ht laws is the responsibility of the user* #ithout li!itin" the ri"hts under copyri"ht, no part of this docu!ent !ay be reproduced, stored in or introduced into a retrie'al syste!, or trans!itted in any for! or by any !eans (electronic, !echanical, photocopyin", recordin", or otherwise , or for any purpose, without the e4press written per!ission of Microsoft Corporation* Microsoft !ay ha'e patents, patent applications, trade!arks, copyri"hts, or other intellectual property ri"hts co'erin" sub7ect !atter in this docu!ent* :4cept as e4pressly pro'ided in any written license a"ree!ent fro! Microsoft, the furnishin" of this docu!ent does not "i'e you any license to these patents, trade!arks, copyri"hts, or other intellectual property* ; 2008 Microsoft Corporation* All ri"hts reser'ed* Microsoft, M&92<&, #indows, #indows N1, and #indows &er'er are either re"istered trade!arks or trade!arks of Microsoft Corporation in the 5nited &tates and=or other countries* All other trade!arks are property of their respecti'e owners*
Contents
&tep >y &tep ?uide: 2e!onstrate 23CP NAP :nforce!ent in a 1est 6ab************************************. Abstract************************************************************************************************************************************ . Copyri"ht /nfor!ation********************************************************************************************************************** 2 Contents****************************************************************************************************************************************** ) &tep9by9&tep ?uide: 2e!onstrate 23CP NAP :nforce!ent in a 1est 6ab************************************@ /n this "uide********************************************************************************************************************************* @ &cenario o'er'iew*********************************************************************************************************************** A NAP enforce!ent processes**************************************************************************************************** A Policy 'alidation******************************************************************************************************************** A NAP enforce!ent and network restriction*****************************************************************************A +e!ediation************************************************************************************************************************** <n"oin" !onitorin" to ensure co!pliance****************************************************************************23CP NAP enforce!ent o'er'iew********************************************************************************************** 3ardware and software re0uire!ents****************************************************************************************** 8 &teps for confi"urin" the test lab************************************************************************************************* 8 Confi"ure 2C.***************************************************************************************************************************** B /nstall the operatin" syste! on 2C.***************************************************************************************** B Confi"ure 1CP=/P on 2C.****************************************************************************************************** .0 Confi"ure 2C. as a do!ain controller and 2N& ser'er*********************************************************.0 Create a user account in Acti'e 2irectory*******************************************************************************.. Add user. to the 2o!ain Ad!ins "roup*********************************************************************************.. Create a security "roup for NAP client co!puters******************************************************************.. Confi"ure NP&.************************************************************************************************************************* .2 /nstall #indows &er'er 2008 or #indows &er'er 2008 +2****************************************************.2 Confi"ure 1CP=/P properties on NP&.***********************************************************************************.2 Coin NP&. to the contoso*co! do!ain**********************************************************************************.) 5ser Account Control************************************************************************************************************* .) /nstall the NP& and 23CP ser'er roles**********************************************************************************.D /nstall the ?roup Policy Mana"e!ent feature*************************************************************************.D Confi"ure NP& as a NAP health policy ser'er************************************************************************.@ Confi"ure NAP with a wi8ard**********************************************************************************************.A Confi"ure &3$s****************************************************************************************************************** .8 Confi"ure 23CP on NP&.***************************************************************************************************** .B <pen the 23CP console***************************************************************************************************** .B :nable NAP settin"s for the scope*************************************************************************************.B Confi"ure the default user class****************************************************************************************** .B Confi"ure the default NAP class***************************************************************************************** 20
Confi"ure NAP client settin"s in ?roup Policy************************************************************************20 Confi"ure security filters for the NAP client settin"s ?P<***************************************************2. Confi"ure C6/:N1.******************************************************************************************************************* 22 /nstall #indows $ista on C6/:N1.***************************************************************************************** 22 Confi"ure 1CP=/P on C6/:N1.***********************************************************************************************22 1est network connecti'ity for C6/:N1.***********************************************************************************2) Confi"ure 2C. as a re!ediation ser'er*********************************************************************************2) +enew /P addressin" on C6/:N1.*****************************************************************************************2D Coin C6/:N1. to the Contoso*co! do!ain****************************************************************************2@ Add C6/:N1. to the NAP client co!puters security "roup*****************************************************2@ :nable +un on the &tart !enu***********************************************************************************************2A $erify ?roup Policy settin"s*************************************************************************************************** 2A $erifyin" NAP functionality********************************************************************************************************* 2A $erification of NAP auto9re!ediation**************************************************************************************2A $erification of health policy enforce!ent********************************************************************************28 Confi"ure #&3$ to re0uire an anti'irus application***********************************************************28 +elease and renew the /P address on C6/:N1.****************************************************************2B $iew the client restriction state********************************************************************************************2B Allow C6/:N1. to beco!e co!pliant**********************************************************************************)0 &ee Also************************************************************************************************************************************ ). Appendi4*************************************************************************************************************************************** ). &et 5AC beha'ior of the ele'ation pro!pt for ad!inistrators****************************************************). +e'iew NAP client e'ents********************************************************************************************************** ). +e'iew NAP ser'er e'ents******************************************************************************************************** )2
!mportant
1he step9by9step instructions in this paper will show you how to deploy a NAP 23CP enforce!ent test lab so that you can better understand how 23CP enforce!ent works*
!n t is guide
1his paper contains an introduction to NAP and instructions for settin" up a test lab and deployin" NAP with the 23CP enforce!ent !ethod usin" two ser'er co!puters and one client co!puter* 1he test lab lets you create and enforce client health re0uire!ents usin" NAP and 23CP* 1he followin" instructions are for confi"urin" a test lab usin" the !ini!u! nu!ber of co!puters* /ndi'idual co!puters are needed to separate the ser'ices pro'ided on the network and to clearly show the desired functionality* 1his confi"uration is neither desi"ned to reflect best practices nor does it reflect a desired or reco!!ended confi"uration for a production network* 1he confi"uration, includin" /P addresses and all other confi"uration para!eters, is desi"ned only to work on a separate test lab network*
5
Scenario o#er#ie$
/n this test lab, NAP enforce!ent for 23CP network access control is deployed with a ser'er runnin" #indows &er'er 2008 or #indows &er'er 2008 +2 that has 23CP and the Network Policy &er'er (NP& ser'ice installed, and a client co!puter runnin" #indows $ista or #indows with the NAP a"ent ser'ice runnin" and 23CP enforce!ent client co!ponent enabled* A co!puter runnin" #indows &er'er% 200) is also used in the test lab as a do!ain controller and 2N& ser'er* 1he test lab will de!onstrate how NAP9capable client co!puters are pro'ided network access based on their co!pliance with network health re0uire!ents*
Po%icy #a%idation
&yste! health 'alidators (&3$s are used by NP& to analy8e the health status of client co!puters* &3$s are incorporated into network polices that deter!ine actions to be taken based on client health status, such as the "rantin" of full network access or the restrictin" of network access* 3ealth status is !onitored by client9side NAP co!ponents called syste! health a"ents (&3As * NAP uses &3As and &3$s to !onitor, enforce, and re!ediate client co!puter confi"urations* #indows &ecurity 3ealth A"ent (#&3A and #indows &ecurity 3ealth $alidator (#&3$ are included with the #indows $ista, #indows &er'er 2008, #indows -, and #indows &er'er 2008 +2 operatin" syste!s, and enforce the followin" settin"s for NAP9capable co!puters: 1he client co!puter has firewall software installed and enabled* 1he client co!puter has anti'irus software installed and runnin"* 1he client co!puter has current anti'irus updates installed* 1he client co!puter has antispyware software installed and runnin"* 1he client co!puter has current antispyware updates installed* Microsoft 5pdate &er'ices is enabled on the client co!puter*
/n addition, if NAP9capable client co!puters are runnin" #indows 5pdate A"ent, NAP can 'erify that the !ost recent software security updates are installed based on one of four possible 'alues that !atch security se'erity ratin"s fro! the Microsoft &ecurity +esponse Center (M&+C * 1his test lab will use the #&3A and #&3$ to re0uire that client co!puters ha'e turned on #indows Firewall, and ha'e an anti'irus application installed*
A%%o$ fu%% net$or& access* 1his is the default settin"* Clients that !atch the policy conditions are dee!ed co!pliant with network health re0uire!ents, and are "ranted unrestricted access to the network if the connection re0uest is authenticated and authori8ed* 1he health co!pliance status of NAP9capable client co!puters is lo""ed* A%%o$ %imited access* Client co!puters that !atch the policy conditions are dee!ed nonco!pliant with network health re0uire!ents, and are placed on the restricted network* A%%o$ fu%% net$or& access for a %imited time* Clients that !atch the policy conditions are te!porarily "ranted full network access* NAP enforce!ent is delayed until the specified date and ti!e* Eou will create two network policies in this test lab* A co!pliant policy will "rant full network access to an intranet network se"!ent* A nonco!pliant policy will de!onstrate network restriction by issuin" a 1CP=/P confi"uration to the client co!puter that places it on a restricted network*
'emediation
Nonco!pliant client co!puters that are placed on a restricted network !i"ht under"o re!ediation* +e!ediation is the process of updatin" a client co!puter so that it !eets current health re0uire!ents* /f additional resources are re0uired for a nonco!pliant co!puter to update its health state, these resources !ust be pro'ided on the restricted network* For e4a!ple, a restricted network !i"ht contain a File 1ransfer Protocol (F1P ser'er that pro'ides current 'irus si"natures so that nonco!pliant client co!puters can update their outdated si"natures* Eou can use NAP settin"s in NP& network policies to confi"ure auto!atic re!ediation so that NAP client co!ponents auto!atically atte!pt to update the client co!puter when it is nonco!pliant* 1his test lab includes a de!onstration of auto!atic re!ediation* 1he Enab%e auto"remediation of c%ient computers settin" will be enabled in the nonco!pliant network policy, which will cause #indows Firewall to be turned on without user inter'ention*
Note network /2 .B2*.A8*0*0=2D is used for the intranet* 1he do!ain controller is na!ed 2C. and is the pri!ary do!ain controller for the do!ain na!ed Contoso*co!* 1he !e!ber ser'er is na!ed NP&. and is confi"ured as a 23CP ser'er and a network policy ser'er* 1he client is na!ed C6/:N1. and is confi"ured for auto!atic addressin" throu"h 23CP* 1he followin" fi"ure shows the confi"uration of the test en'iron!ent*
Note
2C. is a ser'er co!puter runnin" the #indows &er'er 200) &tandard :dition operatin" syste!* 2C. is confi"ured as a do!ain controller with Acti'e 2irectory and the pri!ary 2N& ser'er for the intranet subnet* 2* Confi"ure NP&.* NP&. is a ser'er co!puter runnin" #indows &er'er 2008 or #indows &er'er 2008 +2* NP&. is confi"ured with the Network Policy &er'er (NP& ser'ice, which functions as a NAP health policy ser'er and a +e!ote Authentication 2ial9in 5ser &er'ice (+A2/5& ser'er* NP&. will also be confi"ured with the 23CP ser'ice and function as a NAP enforce!ent ser'er* )* Confi"ure C6/:N1.* C6/:N1. is a client co!puter runnin" #indows $ista or #indows -* C6/:N1. will be confi"ured as a 23CP client and a NAP client* Eou !ust be lo""ed on as a !e!ber of the 2o!ain Ad!ins "roup or a !e!ber of the Ad!inistrators "roup on each co!puter to co!plete the tasks described in this "uide* /f you cannot co!plete a task while you are lo""ed on with an account that is a !e!ber of the Ad!inistrators "roup, try perfor!in" the task while you are lo""ed on with an account that is a !e!ber of the 2o!ain Ad!ins "roup* After the NAP co!ponents are confi"ured, this "uide will pro'ide steps for a de!onstration of NAP enforce!ent and auto9re!ediation* 1he followin" sections pro'ide details about how to perfor! these tasks*
Configure DC*
2C. is a co!puter runnin" #indows &er'er 200) &tandard :dition with &P2, which pro'ides the followin" ser'ices: A do!ain controller for the Contoso*co! Acti'e 2irectory do!ain* A 2N& ser'er for the Contoso*co! 2N& do!ain* /nstall the operatin" syste!* Confi"ure 1CP=/P* /nstall Acti'e 2irectory and 2N&* Create a user account and "roup in Acti'e 2irectory* Create a NAP client co!puter security "roup*
.A* After the co!puter is restarted, lo" in to the C<N1<&< do!ain usin" the Ad!inistrator account*
To insta%% create 7indo$s a securitySer#er group 1443 for NAP or 7indo$s c%ient computers Ser#er 1443 '1
.* /n the Acti'e 2irectory 5sers and Co!puters console tree, ri"ht9click contoso,com, point to Ne$, and then click Group* 2* /n the Ne$ (b;ect " Group dialo" bo4, under Group name, type NAP c%ient computers* )* 5nder Group scope, choose G%oba%, under Group type, choose Security, and then click (6* D* Close the Acti'e 2irectory 5sers and Co!puters console*
Configure NPS*
For the test lab, NP&. will be runnin" #indows &er'er 2008 or #indows &er'er 2008 +2, and will host the NP& ser'ice, which pro'ides +A2/5& authentication, authori8ation, and accountin"* NP&. confi"uration consists of the followin" steps: /nstall the operatin" syste!* Confi"ure 1CP=/P* Coin the co!puter to the do!ain* /nstall the NP& and 23CP ser'er roles* /nstall the ?roup Policy Mana"e!ent feature* Confi"ure NP& as a NAP health policy ser'er* Confi"ure 23CP* Confi"ure NAP client settin"s in ?roup Policy*
To ;oin NPS* to t e contoso,com domain =ersion @ -TCP+!P#@., and then click Properties* A* &elect /se t e fo%%o$ing !P address* /n !P address, type *01,*23,4,1* /n Subnet mas&, type 155,155,155,4* -* &elect /se t e fo%%o$ing DNS ser#er addresses* /n Preferred DNS ser#er, type *01,*23,4,** 8* Click (6, and then click C%ose to close the Loca% Area Connection Properties dialo" bo4* B* Close the Net$or& Connections window* .0* 2o not close the Ser#er ?anager window* /t will be used in the ne4t procedure* ..* Ne4t, check network co!!unication between NP&. and 2C. by runnin" the ping co!!and fro! NP&.* .2* Click Start, click 'un, in (pen type cmd, and then press :N1:+* .)* /n the co!!and window, type ping DC** .D* $erify that the response reads G+eply fro! .B2*.A8*0*.*H .@* Close the co!!and window*
To insta%% t e NPS and DHCP ser#er ro%es 5AC appro'al* #hen pro!pted, always click Continue to authori8e these chan"es* Alternati'ely, see the Appendi4 of this "uide for instructions about how to set 5AC beha'ior of the ele'ation pro!pt for ad!inistrators*
14
To insta%% t e NPS ser#er ro%e .* /n &er'er Mana"er, under <eatures Summary, click Add <eatures* 2* &elect the Group Po%icy ?anagement check bo4, click Ne9t, and then click !nsta%%* )* $erify the installation was successful, and then click C%ose to close the Add <eatures 7i8ard dialo" bo4* D* Close &er'er Mana"er*
15
To configure NPS using t e NAP $i8ard re!ediation ser'er "roups* 1his test lab includes a de!onstration of the use of a re!ediation ser'er "roup to pro'ide do!ain ser'ices to a client with restricted network access*
16
D* <n the Se%ect Net$or& Connection ?et od for /se $it NAP pa"e, under Net$or& connection met od, select Dynamic Host Configuration Protoco% -DHCP., and then click Ne9t* @* <n the Specify NAP Enforcement Ser#ers 'unning DHCP pa"e, click Ne9t* >ecause this NAP health policy ser'er has 23CP installed locally, we do not need to add +A2/5& clients* A* <n the Specify DHCP Scopes pa"e, click Ne9t* 1he test lab will use only one 23CP scopeI therefore, no scope conditions are re0uired* -* <n the Configure /ser Groups and ?ac ine Groups pa"e, click Ne9t* Eou do not need to confi"ure "roups for this test lab* 8* <n the Specify a NAP 'emediation Ser#er Group and /'L , click Ne9t* +e!ediation ser'ers will be confi"ured later in this test lab* B* <n the Define NAP Hea%t Po%icy pa"e, 'erify that 7indo$s Security Hea%t
17
To configure SH=s in 7indo$s Ser#er 1443 =a%idator and Enab%e auto"remediation of c%ient computers check bo4es are selected, and then click Ne9t* .0* <n the Comp%eting NAP Enforcement Po%icy and 'AD!/S C%ient Configuration pa"e, click <inis * ..* 6ea'e the NP& console open for the followin" procedure*
Configure SH=s
&3$s define confi"uration re0uire!ents for co!puters that atte!pt to connect to your network* For the test lab, the #&3$ will be confi"ured to re0uire only that #indows Firewall is enabled* 5se one of the followin" procedures, dependin" on whether you are runnin" #indows &er'er 2008 or #indows &er'er 2008 +2* .* /n the Network Policy &er'er console tree, double9click Net$or& Access Protection, and then click System Hea%t =a%idators* 2* /n the details pane, under Name, double9click 7indo$s Security Hea%t =a%idator* )* /n the 7indo$s Security Hea%t =a%idator Properties dialo" bo4, click Configure* D* Clear all check bo4es e4cept A fire$a%% is enab%ed for a%% net$or& connections * &ee the followin" e4a!ple*
@* Click (6 to close the 7indo$s Security Hea%t =a%idator dialo" bo4, and then click
18
To configure defau%t system user ea%tc%ass #a%idators scope options in 7indo$s Ser#er 1443 '1 A* Close the Network Policy &er'er console*
.* /n the Network Policy &er'er console tree, open Net$or& Access Protection=System Hea%t =a%idators=7indo$s Security Hea%t =a%idator=Settings* 2* /n the details pane, under Name, double9click Defau%t Configuration* )* /n the 7indo$s Security Hea%t =a%idator dialo" bo4, in the left pane, select 7indo$s C+7indo$s =ista, and then under C oose po%icy settings for 7indo$s Security Hea%t =a%idator, clear all the check bo4es e4cept for A fire$a%% is enab%ed for a%% net$or& connections* D* Click (6 to close the 7indo$s Security Hea%t =a%idator dialo" bo4, and then close the Network Policy &er'er console*
To configure defau%t NAP c%ass scope options (ptions, and then click Configure (ptions* 2* <n the Ad#anced tab, 'erify that Defau%t /ser C%ass is chosen ne4t to /ser c%ass* )* &elect the 442 DNS Ser#ers check bo4, in !P Address, under Data entry, type *01,*23,4,*: and then click Add* D* &elect the 4*5 DNS Domain Name check bo4, in String #a%ue, under Data entry, type contoso,com, and then click (6* 1he contoso*co! do!ain is a full9access network assi"ned to co!pliant NAP clients* Note 1he 44> 'outer option is confi"ured in the default user class if a default "ateway is re0uired for client co!puters* >ecause all co!puters in the test lab are located on the sa!e subnet, this option is not re0uired*
20
To configure security NAP c%ient fi%ters settings for t in e NAP Group c%ient Po%icy settings GP( After these settin"s are confi"ured in the ?P<, security filters will be added to enforce the settin"s on co!puters you specify* 1he followin" section describes these steps in detail* .* <n NP&., click Start, click 'un, type gpme,msc, and then press :N1:+* 2* /n the Bro$se for a Group Po%icy (b;ect dialo" bo4, ne4t to Contoso,com, click the icon to create a new ?P<, type NAP c%ient settings for the na!e of the new ?P<, and then click (6* )* 1he ?roup Policy Mana"e!ent :ditor window will open* Na'i"ate to Computer Configuration+Po%icies+7indo$s Settings+Security Settings+System Ser#ices * D* /n the details pane, double9click Net$or& Access Protection Agent* @* /n the Net$or& Access Protection Agent Properties dialo" bo4, select the Define t is po%icy setting check bo4, choose Automatic, and then click (6* A* /n the console tree, open Net$or& Access ProtectionBNAP C%ient ConfigurationBEnforcement C%ients* -* /n the details pane, ri"ht9click DHCP Fuarantine Enforcement C%ient, and then click Enab%e* 8* /n the console tree, ri"ht9click NAP C%ient Configuration, and then click App%y* Note /f you are runnin" #indows &er'er 2008 +2, you can skip this step* B* /n the console tree, na'i"ate to Computer ConfigurationBPo%iciesBAdministrati#e Temp%atesB7indo$s ComponentsBSecurity Center* .0* /n the details pane, double9click Turn on Security Center -Domain PCs on%y., choose Enab%ed, and then click (6* ..* Close the Group Po%icy ?anagement Editor window* .2* /f you are pro!pted to apply settin"s, click Ges*
C6/:N1. will be added to the NAP client co!puters security "roup after it is 7oined to the do!ain*
Configure CL!ENT*
C6/:N1. is a co!puter runnin" #indows $ista or #indows - that you will use to de!onstrate how NAP can be used with 23CP to help protect a network fro! nonco!pliant client co!puters* C6/:N1. confi"uration is perfor!ed in the followin" steps: /nstall the operatin" syste!* Confi"ure 1CP=/P* $erify network connecti'ity* Coin the co!puter to the do!ain* Add C6/:N1. to the NAP client co!puters security "roup and restart the co!puter* :nable 'un on the Start !enu* $erify ?roup Policy settin"s*
D* Click !nternet Protoco% =ersion @ -TCP+!P#@., and then click Properties* @* $erify that (btain an !P address automatica%%y and (btain DNS ser#er address automatica%%y are selected* A* Click (6, and then click C%ose to close the Loca% Area Connection Properties dialo" bo4* -* Close the Net$or& Connections and Net$or& and S aring Center windows*
To rene$ !P addressing on CL!ENT* Po%icies* )* /n the details pane, double9click NAP DHCP Non NAP"Capab%e* D* <n the Settings tab, under Net$or& Access Protection, click NAP Enforcement* @* 5nder 'emediation Ser#er Group and Troub%es ooting /'L , click Configure* A* /n the 'emediation Ser#ers and Troub%es ooting /'L dialo" bo4, under 'emediation Ser#er Group, click Ne$ Group* -* /n the Ne$ 'emediation Ser#er Group dialo" bo4, under Group Name, type Domain ser#ices, and then click Add* 8* /n the Add Ne$ Ser#er dialo" bo4, under <riend%y name, type DC** 5nder !P address or DNS name, type *01,*23,4,*, and then click (6 twice* B* $erify that the new re!ediation ser'er "roup is selected under 'emediation Ser#er Group, and then click (6 to close the 'emediation Ser#ers and Troub%es ooting /'L dialo" bo4* .0* Click (6 to close the NAP DHCP Non NAP"Capab%e Properties window* ..* /n the details pane, double9click NAP DHCP Noncomp%iant* .2* Click the Settings tab, click NAP Enforcement, and then, under 'emediation Ser#er Group and Troub%es ooting /'L, click Configure* Fro! the list under 'emediation Ser#er Group, select Domain ser#ices, and then click (6 twice* 2C. has now been enabled as a re!ediation ser'er for non9NAP9capable and nonco!pliant co!puters* .)* 6ea'e the Network Policy &er'er console open for the followin" procedure*
24
To #erify t at CL!ENT* is remediated automatica%%y $ en 7indo$s <ire$a%% is turned off .* <n C6/:N1., click Start, and then click Contro% Pane%* 2* Click Security, click Security Center, and then click 7indo$s <ire$a%%* )* /n the 7indo$s <ire$a%% dialo" bo4, click C ange settings* D* /n the 7indo$s <ire$a%% Settings dialo" bo4, click (ff -not recommended., and then click (6* @* /n #indows &ecurity Center, you will see that the status of #indows Firewall is displayed as (ff and is then displayed as (n* A* Eou !i"ht see a !essa"e in the notification area that indicates the co!puter does not !eet health re0uire!ents* 1his !essa"e is displayed because #indows Firewall has been turned off* Click this !essa"e for !ore infor!ation about the health status of C6/:N1.* &ee the followin" e4a!ple*
-* 1he NAP client will auto!atically turn #indows Firewall on to beco!e co!pliant with network health re0uire!ents* 1he followin" !essa"e will appear in the notification area: T is computer meets t e re)uirements of t is net$or& * &ee the followin" e4a!ple*
27
>ecause auto9re!ediation occurs rapidly, you !i"ht not see one or both of these !essa"es*
To re%ease and t en rene$ t e !P address on CL!ENT* Access Protection, then System Hea%t =a%idators* 2* 5nder Name, double9click 7indo$s Security Hea%t =a%idator* )* /n the 7indo$s Security Hea%t =a%idator Properties dialo" bo4, click Configure* D* /n the 7indo$s Security Hea%t =a%idator dialo" bo4, under =irus Protection, select the An anti#irus app%ication is on check bo4* @* Click (6, and then click (6 a"ain to close the 7indo$s Security Hea%t =a%idator Properties window*
29
To configure use a NetsNPS* command ea%t to re)uirements s o$ t e NAP to a%%o$ c%ientHs CL!ENT* ea%t state to become comp%iant
Eou !i"ht see a !essa"e in the notification area that indicates the co!puter does not !eet the corporate security re0uire!ents* =ie$ t e c%ientHs restriction state $it Nets Eou can also check the restriction state of the co!puter usin" a NAP Netsh co!!and* .* <n C6/:N1., at the co!!and pro!pt, type nets nap c%ient s o$ state, and then press :N1:+* 2* &croll up the co!!and window to display the C%ient state section* 1he 'estriction state should be H+estricted*H
To re#ie$ set /AC NAP be c%ient a#ior of e#ents t e e%e#ation in E#ent prompt =ie$er for administrators
See A%so
http:=="o*!icrosoft*co!=fwlink=J6ink/dK@ADD)
Appendi9
1his appendi4 will help you with troubleshootin" techni0ues and the settin" of optional features in #indows &er'er 2008 or #indows &er'er 2008 +2 and #indows $ista or #indows -*
To re#ie$ NAP ser#er e#ents in E#ent =ie$er A* Eou can also ri"ht9click an e'ent and then click E#ent Properties to open a new window for re'iewin" e'ents*
32