NAP IPSEC enforcement and IPSEC domain isolation?
hi,
i'm puzzled different technologies available. ipsec domain isolation can used ensure domain members can talk each other (for example), while ipsec nap enforcement can used ensure "healthy" computers can talk each other (for example).
are the 2 technologies compatible? can specify policy want domain members , "healthy" computers able talk each other?
i haven't yet tried out both technologies in lab , therefore i'm not familiar management interface, webcasts , lab instructions, not clear if possible specify.
aivo jürgenson
you can create ipsec policies require certificates authentication.
you can set health registration authority (for nap) issue health certificates domain members.
thus, healthy domain members able communicate other healthy domain members, have proper credential (certificate) so.
-chris
chris.edson@online.microsoft.com *
sdet, network access protection
* remove "online" make address valid.
** posting provided "as is" no warranties, , confers no rights.
Windows Server > Network Access Protection
Comments
Post a Comment