NAC and changing IP address

Answered Question
Nov 3rd, 2009

Hi All,

we are using NAC OOB, L3, Real IP gateway with AD-SSO. when users log in to the PC, PC is supposed to change the IP address after authentication with windows user account. But based on security policy, users don't allow to change IP address, so changing IP address will be failed. is there any workaround for this matter? should we change our security policy and let users to have right to change IP address?

in this case, what security in GPO we have to modify to give them permission to do "ipconfig /renew" command right?

any suggestion would be very appreciated.

thanks

Alex

I have this problem too.
0 votes
Correct Answer by Faisal Sehbai about 7 years 2 months ago

You need to install the stub first with admin rights. Then once the user logs in with his own rights (non-admin) and he needs to do anything administratively (like change IP), the agent requests the stub to do it and it works.

Check the link I sent out. It has much more details :)

HTH,

Faisal

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (3 ratings)
Loading.
Faisal Sehbai Tue, 11/03/2009 - 11:32

Alex,

Install the stub first for the agents, and then let the users install the agent with their own rights. This way when the agent needs to do something with admin rights, it will ask the stub.

Details: http://tinyurl.com/yfodvn9

HTH,

Faisal

alex goshtaei Tue, 11/03/2009 - 13:08

Hi Faisal,

what do you mean admin right? which admin is inside stub? windows admin?

thanks again for your fast reply.

Alex

Correct Answer
Faisal Sehbai Tue, 11/03/2009 - 13:12

You need to install the stub first with admin rights. Then once the user logs in with his own rights (non-admin) and he needs to do anything administratively (like change IP), the agent requests the stub to do it and it works.

Check the link I sent out. It has much more details :)

HTH,

Faisal

lnemec Thu, 11/12/2009 - 00:46

Hi Faisal,

as i know, stub installation is not included/supported in NAC 4.7. How to solve this issue with IP address renew?

Ladislav.

Faisal Sehbai Thu, 11/12/2009 - 07:32

Ladislav,

4.6 and above install a service with the agent. The role of stub is now played with that service.

HTH,

Faisal

Actions

This Discussion