NAC and changing IP address

Answered Question
Nov 3rd, 2009
User Badges:

Hi All,

we are using NAC OOB, L3, Real IP gateway with AD-SSO. when users log in to the PC, PC is supposed to change the IP address after authentication with windows user account. But based on security policy, users don't allow to change IP address, so changing IP address will be failed. is there any workaround for this matter? should we change our security policy and let users to have right to change IP address?

in this case, what security in GPO we have to modify to give them permission to do "ipconfig /renew" command right?

any suggestion would be very appreciated.

thanks

Alex


Correct Answer by Faisal Sehbai about 7 years 6 months ago

You need to install the stub first with admin rights. Then once the user logs in with his own rights (non-admin) and he needs to do anything administratively (like change IP), the agent requests the stub to do it and it works.


Check the link I sent out. It has much more details :)


HTH,

Faisal

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (3 ratings)
Loading.
Faisal Sehbai Tue, 11/03/2009 - 11:32
User Badges:
  • Gold, 750 points or more

Alex,


Install the stub first for the agents, and then let the users install the agent with their own rights. This way when the agent needs to do something with admin rights, it will ask the stub.


Details: http://tinyurl.com/yfodvn9


HTH,

Faisal

alex goshtaei Tue, 11/03/2009 - 13:08
User Badges:

Hi Faisal,

what do you mean admin right? which admin is inside stub? windows admin?

thanks again for your fast reply.

Alex


Correct Answer
Faisal Sehbai Tue, 11/03/2009 - 13:12
User Badges:
  • Gold, 750 points or more

You need to install the stub first with admin rights. Then once the user logs in with his own rights (non-admin) and he needs to do anything administratively (like change IP), the agent requests the stub to do it and it works.


Check the link I sent out. It has much more details :)


HTH,

Faisal

lnemec Thu, 11/12/2009 - 00:46
User Badges:

Hi Faisal,

as i know, stub installation is not included/supported in NAC 4.7. How to solve this issue with IP address renew?

Ladislav.

Faisal Sehbai Thu, 11/12/2009 - 07:32
User Badges:
  • Gold, 750 points or more

Ladislav,


4.6 and above install a service with the agent. The role of stub is now played with that service.


HTH,

Faisal

Actions

This Discussion