Imposition of a digital certificate to receive DHCP IP (NAP /NPS)
i'm doing project , project need block machine has not 1 of internal ca certificate receive ip dhcp server.
thought in nps nap create rules , impose same on corporate network.
have installed enterprise ca , created scopo dhcp, set nap , nps make charge?
marcus
hi marcus,
this not possible nap unless use ipsec enforcement or 802.1x enforcement. in ipsec enforcement scenario, certificate referring called exemption certificate. need add system health authentication eku certificate. dhcp server need placed in secure zone , need deploy ipsec policies.
http://technet.microsoft.com/en-us/library/dd125391(ws.10).aspx
to 802.1x authentication need enforce certificate authentication 802.1x , place dhcp server on vlan unreachable except authenticated computers.
-greg
Windows Server > Network Access Protection
Comments
Post a Comment