Windows Server 2008 Network Access Protection (NAP) Technical Overview.

Slides:



Advertisements
Similar presentations
Active Directory Fundamentals
Advertisements

Selecting the Right Network Access Protection (NAP) Architecture Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Advanced SQL Server 2005 Reporting Services. New Data Sources in SSRS 2005 Reporting Services Data Extensions Working with SSAS and SSIS Data End-User.
Tech·Ed North America /6/2017 9:33 AM
Network Access Protection & Network Admission Control March 10, 2005 Teerapol Tuanpusa Network Consultant Cisco Systems Thailand Jirat Boomuang Technology.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Welcome ITPROEXC-113. Pablo Vernocchi MVP Exchange Server Leandro Amore MVP Directory Services Disaster.
May 30 th – 31 st, 2006 Sheraton Ottawa. Network Access Protection Gene Ferioli Program Manager Customer Advisory Team Microsoft Corporation.
Network Isolation Using Group Policy and IPSec Paula Kiernan Senior Consultant Ward Solutions.
Copyright line. Network Access Protection EXAM OBJECTIVES  Working with NAP.
1 Objectives Configure Network Access Services in Windows Server 2008 RADIUS 1.
Agenda Introduction Network Access Protection platform architecture
A Technical Overview of Microsoft Forefront Client Security (FCS) Howard Chow Microsoft MVP.
Providing 802.1X Enforcement For Network Access Protection Mudit Goel Development Manager Windows Enterprise Networking Microsoft Corporation.
Network Access Protection Platform Architecture Joseph Davies Technical writer Windows Networking and Device Technologies Microsoft Corporation.
Microsoft Software Assurance for Academic Licensing Programs.
Jayson Ferron CIO Interactive Security Training WSV206.
Getting Ready for Network Access Protection Jeff Alexander Technology Advisor Microsoft.
Sreenivas Addagatla - Development Lead Lambert Green - Test Lead Microsoft Corporation.
Windows Network Policy Server Fundamentals Ranjana Jain MCSE, MCT, RHCE, CISSP, CIW Security Analyst IT Pro Evangelist Microsoft India
Making Identity and Access Management Real – The Early Days Brian Lauge Pedersen Senior Technology Specialist.
Excel Services Overview. Broad sharing of spreadsheets Business intelligence capabilities Excel services architecture What Will We Cover?
Microsoft Cloud Services Training and Certification Presented by Name Goes Here, Title.
TNT Welcome to this TechNet Event We would like to bring your attention to the key elements of the TechNet programme; the central information and.
Unit Eight IT CAREER CERTIFICATION 1.Passage One. Microsoft Certifications.
An MSDN Subscription acts as a lifeline for software developers, testers, architects, IT professionals, database engineers, and others. It provides priority.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 9 Network Policy and Access Services in Windows Server 2008.
Chapter 6 Configuring, Monitoring & Troubleshooting IPsec
PKI Enhancement in Windows Vista® and Windows Server 2008.
Clinic Security and Policy Enforcement in Windows Server 2008.
Small Business Server 2003 Technical Overview Part 1.
Damian Leibaschoff Support Escalation Engineer Microsoft Becky Ochs Program Manager Microsoft.
1 Week #7 Network Access Protection Overview of Network Access Protection How NAP Works Configuring NAP Monitoring and Troubleshooting NAP.
Selecting the Right Network Access Protection Architecture
TechNet Connection Krittiya Eamsiri Product Manager Microsoft Thailand.
70-411: Administering Windows Server 2012
Implementing Network Access Protection
Module 9: Configuring IPsec. Module Overview Overview of IPsec Configuring Connection Security Rules Configuring IPsec NAP Enforcement.
Module 8: Configuring Network Access Protection
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
Managing Windows Server 2003 and Active Directory Best Practices ธนินทร์ น้อยรังษี Tanin Noirungsee Technology Specialist Microsoft (Thailand)
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
Welcome Windows Server 2008 安全功能 -NAP. Network Access Protection in Windows Server 2008.
Configuring Network Access Protection
1 Week #5 Routing and NAT Network Overview Configuring Routing Configuring Network Address Translation Troubleshooting Routing and Remote Access.
TNT ISA Server 2004 Technical Overview What we will cover:  Improvements over ISA Server 2000  Exploring the new user interface  Configuring.
May 30 th – 31 st, 2007 Chateau Laurier Ottawa. Securing Your Network – End to End Connectivity Pat Fetty Senior Program Manager Windows Customer Advisory.
NAC-NAP Interoperability
Understand Server Protection LESSON Security Fundamentals.
© 2008 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED,
Security Configuration Wizard Keith D Miller Microsoft European Support Readiness Manager.
Implementing Server Security on Windows 2000 and Windows Server 2003 Fabrizio Grossi.
Welcome. Welcome to this TechNet Event URL for on-line feedback is in your reminder No Planned Fire Drills Please turn your Mobile Phones off To.
1 Objectives Wireless Access IPSec Discuss Network Access Protection Install Network Access Protection.
Module 6: Network Policies and Access Protection.
Module 5: Network Policies and Access Protection
Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd.
Asif Jinnah Field Desktop Services Enabling a Flexible Workforce, an insider’s view.
Managing Network Access Protection. Introduction to NAP Issues  Although corporate networks are highly secured, no control over the configuration of.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor.
Click to edit Master title style TechNet goes virtual ©2009 Microsoft Corporation. All Rights Reserved. TechNet goes virtual NAP and NPS in Windows Server.
Click to edit Master title style TechNet goes virtual ©2009 Microsoft Corporation. All Rights Reserved. TechNet goes virtual Windows Server 2008 R2 Remote.
D-Link Wireless AP with NAP 802.1x solution
Implementing Network Access Protection
Imaging and Deployment
Forefront Security ISA
MCSA VCE
Deriving more value from your Windows investment
MS-900 MS-101 Dumps PDF 2019
NAP / PWG Discussion August 17, 2009.
Presentation transcript:

Windows Server 2008 Network Access Protection (NAP) Technical Overview

Introducing Network Access Protection Network Access Protection Architecture Reviewing NAP Enforcement Options What Will We Cover?

Level 300 Familiarity with DHCP Knowledge of IPsec Familiarity with RRAS and VPN Helpful Experience

Introducing Network Access Protection Using NAP with DHCP Using NAP with VPN Using NAP with IPsec Agenda

Network Access Protection Solution Policy Validation Network Restriction Remediation Ongoing Compliance Polices, Procedures, and Awareness Data Application Host Internal Network Perimeter

Network Access Protection – Notes Policy Validation Network Restriction Remediation Ongoing Compliance Polices, Procedures, and Awareness Data Application Host Internal Network Perimeter

NAP Architecture Overview Network Policy Server Quarantine Server (QS) Client Quarantine Agent (QA) Health policyUpdates Health Statements Network Access Requests System Health Servers Remediation Servers Health Certificate Network Access Devices and Servers System Health Agent (SHA) MS and 3rd Parties System Health Validator Enforcement Client (EC) (DHCP, IPSec, 802.1X, VPN)

NAP Architecture Overview – Notes Network Policy Server Quarantine Server (QS) Client Quarantine Agent (QA) Health policyUpdates Health Statements Network Access Requests System Health Servers Remediation Servers Health Certificate Network Access Devices and Servers System Health Agent (SHA) MS and 3rd Parties System Health Validator Enforcement Client (EC) (DHCP, IPSec, 802.1X, VPN)

Network Layer Protection with NAP Requesting access. Here’s my new health status. MS NPS Client 802.1x Switch Remediation Servers May I have access? Here’s my current health status. Should this client be restricted based on its health? Ongoing policy updates to Network Policy Server You are given restricted access until fix-up. Can I have updates? Here you go. According to policy, the client is not up to date. Quarantine client, request it to update. Restricted Network Client is granted access to full intranet. System Health Servers According to policy, the client is up to date. Grant access.

Host Layer Protection with NAP Accessing the network X Remediation Server NPS HRA May I have a health certificate? Here’s my SoH. Client ok? No. Needs fix-up. You don’t get a health certificate. Go fix up. I need updates. Here you go. Here’s your health certificate. Yes. Issue health certificate. Client No Policy Authentication Optional Authentication Required

NAP – Enforcement Options Restricted VLANFull access802.1X Healthy peers reject connection requests from unhealthy systems Can communicate with any trusted peer Complements layer 2 protection Works with existing servers and infrastructure Offers flexible isolation IPsec Restricted VLANFull accessVPN Restricted set of routesFull IP address given, full access DHCP Unhealthy ClientHealthy ClientEnforcement Infrastructure and API Setv Customer Choice IPsec-based Enforcement

Introducing Network Access Protection Using NAP with DHCP Using NAP with VPN Using NAP with IPsec Agenda

NAP with DHCP NPS Server Client DHCP ServerVPN ServerIEEE 802.1X Devices Remediation Servers Requesting access. Here’s my new health status. The client requests and receives updates I need to lease an IP address You are not within the Health Policy requirements Access granted. Here is your new IP address

Demonstration Environment

Demo Configuring NAP for DHCP Configure Health Policies Configure Network Policies Enable Client NAP Settings demonstration

Introducing Network Access Protection Using NAP with DHCP Using NAP with VPN Using NAP with IPsec Agenda

NAP with VPN and RRAS NPS Server Client VPN Server Remediation Servers RADIUS Messages PEAP Messages

Demo Configuring NAP for VPN Configure RRAS Settings Configure Connection Request Policy Configure Network Policies demonstration

Introducing Network Access Protection Using NAP with DHCP Using NAP with VPN Using NAP with IPsec Agenda

IPsec-based Communication Secure network Boundary network Restricted network IPsec Authenticated Unauthenticated

IPsec-based Communication – Notes Secure network Boundary network Restricted network IPsec Authenticated Unauthenticated

Demo Configuring NAP for IPsec Configure Exemption Group Configure Certificate Settings Configure Health Registration Authority demonstration

NAP provides policy-driven access control Customer choice—flexible, selectable enforcement Broad industry support Session Summary

Visit TechNet at: Visit the following site for additional information: For More Information

Course IDTitle 5934 Introducing Microsoft Windows Server Introducing Server Management in Microsoft Windows Server 2008 For training information and availability Training Resources

Self-study learning tool, free to anyone Determines skills gaps Provides learning plans Post your score, see how you rank Visit: Readiness with Skills Assessment

Become a Microsoft Certified Professional What are MCP certifications? Validation in performing critical IT functions Why certify? WW recognition of skills gained through experience More effective deployments with reduced costs What certifications are there for IT Pros? MCP, MCSE, MCSA, MCDST, MCDBA

TechNet Plus TechNet Plus is an essential premium web-enabled and live support resource that provides IT Professionals with fast and easy access to Microsoft experts, software and technical information, enhancing IT productivity, control and planning. Evaluate full versions of all Microsoft commercial software for evaluation— without time limits. This includes all client, server and Office applications. Try out all the latest betas before public release Keep your skills current with select Microsoft E-Learning courses free each quarter Evaluate full versions of all Microsoft commercial software for evaluation— without time limits. This includes all client, server and Office applications. Try out all the latest betas before public release Keep your skills current with select Microsoft E-Learning courses free each quarter Evaluate & Learn Plan & Deploy Support & Maintain Use the TechNet Library to plan for deployment using the Knowledge Base, resource kits, and technical training Use exclusive tools like System Center Capacity Planner to accurately plan for and deploy Exchange Server and System Center Operations Manager Stay informed with your free subscription to TechNet Magazine. Use the TechNet Library to plan for deployment using the Knowledge Base, resource kits, and technical training Use exclusive tools like System Center Capacity Planner to accurately plan for and deploy Exchange Server and System Center Operations Manager Stay informed with your free subscription to TechNet Magazine. 2 complimentary Professional Support incidents for use 24/7 (20% discount on additional incidents) Access over 100 managed newsgroups and get next business day response-- guaranteed Use the TechNet Library to maintain your IT environment with security updates, service packs and utilities 2 complimentary Professional Support incidents for use 24/7 (20% discount on additional incidents) Access over 100 managed newsgroups and get next business day response-- guaranteed Use the TechNet Library to maintain your IT environment with security updates, service packs and utilities Get all these resources and more with a TechNet Plus subscription. For more information visit: technet.microsoft.com/subscriptions