Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Question of LAN Enforcer Implement

Updated: 21 May 2010 | 5 comments
noble's picture
0 0 Votes
Login to vote

i will deploy SNAC as lan enforce mode,but some question are confused.
1.if i use lan enforcer,i need change NAC client to PEAP authentication.but my DC is Win server 2003,and client is win XP Sp2,what is the best practise setting PEAP authentication properties of all NAC client.
2.if i enable MAB in the enforcer,the device whose mac address in MAB DB will enforcing to which vlan.

Comments

Vikram Kumar-SAV to SEP's picture
04
Jul
2009
0 Votes 0
Login to vote

How a LAN Enforcer appliance works

How a LAN Enforcer appliance works

 http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008120314023148

Protected EAP (PEAP) Support Added to Windows XP SP1 and Windows Server 2003

http://support.microsoft.com/kb/325725



figo's picture
04
Jul
2009
0 Votes 0
Login to vote

For the second question,

For the second question, could you tell which product version are your running?


noble's picture
05
Jul
2009
0 Votes 0
Login to vote

reply to figo

SEPM version is 4000.2295,and Lan Enforcer version is 4000.

figo's picture
06
Jul
2009
0 Votes 0
Login to vote

Mab Authentication

Thanks, noble.

The MAB behaviour for this version will be:  VLAN be switched according to Action Table in SEPM,  Condition will be: HI: UNAVAILABLE; EAP:PASS; PRO:UNAVAILABLE.

You need to properly configure action table in SEPM first.

Please tell if you need further help.

Figo

noble's picture
05
Jul
2009
0 Votes 0
Login to vote

replay to Vikram Kumar

hi

the docs is not useful for me,because i am confuse what is the best way to setting all snac client peap properties of wired NIC.

whether i should do setting one by one or deploying using some batches?