Ahmed Hussein Online

Network access protection (NAP) a practical point of view (Part2)

 

in part one we explained the essentials of network access protection

Now on the health server please start the health and click on configure nap

clip_image002

On the wizard we select the DHCP

clip_image004

Lets give it a name

clip_image006

Next we specify the DHCP servers that we will use as RADUIS client – we click on add

clip_image008

Give the server a name and select a share secret the shard secret is a kind of password so both server can trust each other so write it down

clip_image010

Now the server has been added we proceed to the next step

clip_image012

Skip the next we will select our scopes from the DHCP server

clip_image014

Next we select the machine group we created

clip_image016

clip_image018

Next we create a remediation servers group click new group

clip_image020

We give the group a name and I add a servers to it (don’t forget to add active directory servers to the list )

clip_image022

have group added (note : you can create a web page that will help users )

clip_image024

Now make sure you select the following

Windows security health validator

Enable auto…

Allow full network access

clip_image026

And we done

clip_image028

Now lets review what’s created

Radius client

clip_image030

Connection request policy

clip_image032

Three network policies

clip_image034

Two health policy’s

clip_image036

Everything looks ok

The next step lets configure the windows security health validator and open default configuration ( instead of changing the default you can create new setting and change it in the health policies above )

clip_image038

This the the default

clip_image040

clip_image042

I will use only

· The firewall

· The antispyware

· The updates

My config will look like

clip_image044

clip_image046

No next step we move on to the DHCP server and open the NPS

Select remote RADIUS server group

clip_image048

We R-click and select new

clip_image050

We click add and type the server name or IP

clip_image052

Now the authentication/accounting tab

clip_image054

And we done

clip_image056

clip_image058

Now open policies / connection request policies /create new

clip_image060

Add day and time restriction

clip_image062

Select forward request to the following…..

clip_image064

And finish

clip_image066

Now we open the DHCP console

Go to you scope properties and enable NAP for that scope

clip_image068

Next we go to scope options

clip_image070

Go to advanced

clip_image072

Select default network access protection class

clip_image074

Next we enter all the options we need

The final results

clip_image076

Now the final step create the GPO so the the clients would receive the configuration

clip_image078

Give it a name

clip_image080

Under security filtering remove authenticated users and add the NAP client computers

clip_image082

We add the NAP computers group

clip_image084

Now we edit the policy

Go to

Computer Configuration/Policies/Windows Settings/Security Settings/System Services/ Network Access Protection Agent and set the startup type to automatic

clip_image086

Now go to Network Access Protection\NAP Client Configuration\Enforcement Clients

Enable DHCP Quarantine Enforcement Client

clip_image088

Next you can go to user interface settings

clip_image090

Last step to enable the security center

Computer Configuration\Policies\Administrative Templates\Windows Components\Security Center

clip_image092

And NAP configuration are good to go now

We add the needed machines to our group

clip_image094

Now on the client use Gpupdate /force and restart

Now lets test if the gpo applied or not by running

netsh nap client show grouppolicy

Under admin it should be enabled

clip_image096

Next we test to see if the agent are initialized or not by running

netsh nap client show state

initialized must be yes

clip_image098

Now things to test to make sure that everything working as it should

Try to stop the firewall ( it should start automatically )

Change the windows security health validator ( in my case I added the antivirus settings and since I don’t have AV on the machine the machine becomes limited )

clip_image100

clip_image102

Remember DHCP enforcement reevaluate the policy with each machine try to renew or obtain

 

now you have an agent on all of your machines that will keep trying to update the machines .now even for the pilot user ( the user that only plugin his laptop few hours a month ) he will get updated as soon as he plugs in Smile

Related Posts

Leave a Reply

*