Configuring NAP with DHCP

In this document we will show how to assign IP addresses with our DHCP servers to computers that we are interested in, based on certain conditions such as belonging to an AD group, if they have an antivirus installed, If you have the S.O.. up-to-date… we may indicate whether we are interested in giving you an IP address of our areas or denying you access to the network,

windows-2012-nap-dhcp-01-Bujarra

The first thing will be to add the server role “Network Policy and Access Services”,

 

windows-2012-nap-dhcp-02-Bujarra

We will select only the role service “Network Policy Server” and continue with the installation wizard.

 

windows-2012-nap-dhcp-03-Bujarra

Open the Admin console “Network Policy Server” and we can manually configure NAP policies or through a wizard. Inside the NPS server we will start by clicking “Configure NAP”,

 

windows-2012-nap-dhcp-04-Bujarra

 

In the network connection method we will select “Dynamic Host Configuration Protocol (DHCP) and we give him a directive name, “Following”,

 

 

windows-2012-nap-dhcp-05-Bujarra

We will not add RAIUS clients, “Following”,

 

windows-2012-nap-dhcp-06-Bujarra

If we are interested, we can manually add the DHCP scopes of our DHCP servers, In this case, we will apply the directive to all areas, “Following”,

 

windows-2012-nap-dhcp-07-Bujarra

We can add a group of computers that we have previously created to grant only IP addresses to the members of that group, We could directly use the “Domain Computers” to restore access to an IP from our DHCP server only to the computers in our Active Directory, “Following”,

 

windows-2012-nap-dhcp-08-Bujarra

If we have update servers we can indicate them here, “Following”,

 

windows-2012-nap-dhcp-09-Bujarra

We mark a validator that we will apply to this directive, to require extra conditions on equipment, as it can be if they have Antivirus installed, Updated the team… We may also self-correct these conditions if they are not met by the equipment, and we will indicate if we want to give them access if they comply or not, “Following”,

 

windows-2012-nap-dhcp-10-bujarra

We confirm that everything is correct & “End”,

 

windows-2012-nap-dhcp-12-bujarra

We will create a GPO that we will apply to all the teams we are interested in, Where we will start the service “Network Access Protection Agent” automatically in “Equipment Setup” > “Policies” > “Windows Settings” > “Security Settings” > “System Services”

 

windows-2012-nap-dhcp-13-bujarra

And we enable the 'DHCP Quarantine Application Client'’ in “Equipment Setup” > “Policies” > “Windows Settings” > “Security Settings” > “Network Access Protection” > “NAP Client Configuration” > “Compliance Customers”.

 

windows-2012-nap-dhcp-14-bujarra

Optionally, we can edit the configuration of the default Windows security maintenance validator or create a custom one indicating if we require clients to have the firewall enabled, antivirus, Antispyware, Windows updates. In addition to configuring in the policy whether we want to meet all the conditions or only some of them.

 

windows-2012-nap-dhcp-11-bujarra

And finally we will enable in our DHCP server ranges the “Network Access Protection”! and with this we will have a little more secure our network of customers, where only computers that meet all the conditions that interest us will access an IP!

Recommended Posts

Author

nheobug@bujarra.com
Autor del blog Bujarra.com Cualquier necesidad que tengas, Do not hesitate to contact me, I will try to help you whenever I can, Sharing is living ;) . Enjoy documents!!!

What's New in XenDesktop 7

7 of July de 2013