<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Network Access Protection (NAP) : FAQ</title><link>http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx</link><description>Tags: FAQ</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Selecting PEAP-TLS and other PEAP methods in Windows Vista and Windows Server 2008</title><link>http://blogs.technet.com/nap/archive/2008/09/29/selecting-peap-tls-and-other-peap-methods-in-windows-vista-and-windows-server-2008.aspx</link><pubDate>Tue, 30 Sep 2008 02:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3130099</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/nap/comments/3130099.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3130099</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Windows Vista and Windows Server 2008 support the Protected Extensible Authentication Protocol (PEAP) and the Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2) and Transport Layer Security (TLS) authentication methods for PEAP. PEAP can be used in Windows Vista and Windows Server 2008 for remote access VPN connections, 802.1X-authenticated wired connections, and for wireless connections that use the 802.1X, WPA-Enterprise, or WPA2-Enterprise security types. By default, PEAP uses PEAP-MS-CHAP v2.&amp;nbsp;The use of&amp;nbsp;PEAP and a PEAP authentication method is required for the 802.1X and VPN NAP enforcement methods.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;For VPN and wireless connections in the Network Connections folder, the list of installed PEAP methods is displayed as a normal drop-down list box from the properties of the Microsoft: Protected EAP (PEAP) network authentication method. There is a different procedure when selecting PEAP types from the following locations:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Authentication&lt;/B&gt; tab of a wired network connection in the Network Connections folder.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Security&lt;/B&gt; tab of a Wired Network (IEEE 802.3) Policies policy in Group Policy.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Security&lt;/B&gt; tab of a Wireless Network (IEEE 802.11) Policies policy in Group Policy.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;To select PEAP-TLS or additional PEAP authentication methods from these locations, you must first obtain the properties of the Microsoft: Protected EAP (PEAP) network authentication method. In the &lt;B style="mso-bidi-font-weight: normal"&gt;Protected EAP Properties&lt;/B&gt; dialog box, you must click the down arrow for &lt;B style="mso-bidi-font-weight: normal"&gt;Select Authentication Method&lt;/B&gt;, and then click the small up and down arrows just below the larger down arrow to display the installed PEAP authentication methods. Here is an example.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;IMG title="Example of selecting different PEAP methods" style="WIDTH: 383px; HEIGHT: 550px" height=550 alt="Example of selecting different PEAP methods" src="http://napteam.members.winisp.net/peap.jpg" width=383 mce_src="http://napteam.members.winisp.net/peap.jpg"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;After the desired PEAP authentication type is displayed, click on its name to select it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;For example, the following procedure selects the PEAP-TLS authentication method:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Number style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;In &lt;B style="mso-bidi-font-weight: normal"&gt;Select Authentication Method&lt;/B&gt;, click the down arrow.&lt;/P&gt;
&lt;P class=Number style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;For PEAP-TLS, in the drop down list, directly below the down arrow, click the small down arrow to display &lt;B style="mso-bidi-font-weight: normal"&gt;Smart Card or other certificate&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Smart Card or other certificate&lt;/B&gt;. &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3130099" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/configuration/default.aspx">configuration</category></item><item><title>My review of Information Week’s “Rolling Review: Microsoft NAP”</title><link>http://blogs.technet.com/nap/archive/2008/09/26/my-review-of-information-week-s-rolling-review-microsoft-nap.aspx</link><pubDate>Fri, 26 Sep 2008 21:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3129119</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/nap/comments/3129119.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3129119</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Greetings, keepers of the NAP flame!&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;On August 2, Information Week published an article titled “&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;A href="http://www.informationweek.com/news/security/NAC/showArticle.jhtml?articleID=209900645&amp;amp;pgno=1&amp;amp;queryText=&amp;amp;isPrev=" mce_href="http://www.informationweek.com/news/security/NAC/showArticle.jhtml?articleID=209900645&amp;amp;pgno=1&amp;amp;queryText=&amp;amp;isPrev="&gt;Rolling Review: Microsoft NAP&lt;/A&gt;.” I would like to comment on it on behalf of the NAP product team and add technical clarity where I can.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;1. Opening paragraph:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;“it's to Microsoft (NSDQ: MSFT)'s credit that early on the company moved away from trying to develop a proprietary system. Instead, it built a framework; developed a set of APIs for third-party integration; and, most important, aligned itself with the most widely accepted standards body in the NAC space, the Trusted Computing Group.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;We heartily agree with this statement. We decided to create NAP as a platform in conjunction with industry standards, rather than provide a proprietary solution that attempts to address every kind of system health check and every kind of enforcement method. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;2. 4&lt;SUP&gt;th&lt;/SUP&gt; paragraph&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;“the Cisco NAC agent provides the administrator with the ability to scan for specific registry keys or other system values, and make policy decisions based on those values. The NAP agent does not.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;The built-in Windows Security Health Agent (WSHA) does not provide these abilities. The NAP Agent service running on a NAP client can host multiple system health agents (SHAs) and third-party vendors can supply additional SHAs to extend the set of health checks. The more accurate statement for the last sentence in this quote is: “The NAP agent with the built-in WSHA does not.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;3. Explanation of DHCP enforcement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“Clients that fail a health check are provided with an IP address and subnet mask, but no default gateway. However, these clients are provided with host routes to remediation servers, where updates can be downloaded and installed automatically or manually.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Clients that fail system health evaluation are allocated an IPv4 address with a subnet mask of 255.255.255.255, which means that they will not be able to reach other locations on their subnet.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;Whether updates are downloaded and installed automatically or manually is a function of the SHAs and related system software that is running on the NAP client. With the correct logic within the SHA and access to remediation servers, SHAs can automatically install and configure components and updates. &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;4. Explanation of IPsec enforcement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“If a system that lacks a valid health certificate tries to connect to a network that requires one for access, the connection will be dropped.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;IPsec enforcement is combination of health certificates and IPsec policy that requires protected communication&amp;nbsp;with health certificates for authentication. The enforcement is done end-to-end between two communicating nodes, rather than at a connection point to the network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;5. Explanation of VPN enforcement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“VPN enforcement is most easily achieved through the use of Microsoft's Routing and Remote Access server, but third-party VPNs can be made to work with NAP.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The exact details and requirements for using a third-party VPN server or concentrator with NAP and the VPN enforcement method is something that I am investigating. I will publish the results in a future NAP blog post.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;6. Explanation of 802.1X enforcement&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“When a system attempts to log on, the NAP client packages its Statement of Health and logon credentials into an EAP authentication request.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Actually, there are separate EAP authentication methods and message exchanges for authentication and the passing of system health information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;7. Factors for system health&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“Out of the box, you can check for the status of Windows firewall and antivirus/anti-spyware software, as well as Windows Updates and the update policy.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The built-in WSHA monitors the services and components of the Windows Security Center (WSC), which provides system health checks for the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Whether a host-based firewall that is registered with the WSC is enabled. This includes the built-in Windows Firewall and third-party firewall products.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Whether an antivirus application that is registered with WSC is enabled and up to date. This includes third-party antivirus products.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Whether an antispyware application that is registered with WSC is enabled and up to date. This includes the built-in Windows Defender for Windows Vista and third-party antispyware products.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Whether automatic updating is enabled.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Whether security updates of a specified level have been installed, the time interval within which the client must check for new security updates, and the sources of the updates (Windows Update or Windows Server Update Services).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;8. How strict your policies are&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;“Microsoft recommends a phased implementation where NAP is initially deployed in a reporting-only mode. Once you're comfortable that enforcing health standards won't grind business to a halt, you can move gradually to an auto-remediated enforcement policy.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;NAP can be used to determine the overall system health compliance of your network (reporting mode) and to enforce system health requirements by restricting the access of noncompliant computers (full enforcement mode). Depending on the needs of your organization, either of these modes are acceptable destinations for a NAP deployment. Additionally, autoremediation can be enabled for either deployment mode.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;9. The “Two Microsoft NAP Deployment Scenarios” figure&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Two points of technical clarification:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For DHCP enforcement, the NAP client requests an IPv4 address, not access. Therefore, the labels on the arrows between the NAP client and the DHCP server should be “Address requested” and “Address granted.”&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;The interaction between NPS and Active Directory for DHCP enforcement is only to verify security group membership. For 802.1X enforcement, NPS uses Active Directory to also validate the credentials of the 802.1X client.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;10. “Out for a Spin” section&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;A. “That's because DHCP in Windows 2008 is NAP-aware and includes the additional user classes and scope options necessary to dynamically black-hole clients that fail health checks.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;I would replace the term “black hole” with “restrict the access of”. The term “black hole” in my mind implies no access, whereas typical NAP deployments contain remediation servers that noncompliant clients must access to correct their system health.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;B. “Only Windows XP SP3 and Vista have built-in NAP clients”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Windows Server 2008 also has a built-in NAP client, although it does not include the WSHA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;C. “we had to configure a group policy to get clients to start up the service automatically and participate in DHCP enforcement.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The location of the Group Policy setting to automatically start the NAP Agent service is Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Network Access Protection Agent. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;D. “To our surprise, these non-NAP-capable PCs were quarantined, as though they had failed a health check.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;This behavior is based on the default settings of the Define NAP Health Policy page of the Configure NAP wizard. To prevent non-NAP capable computers from having their access limited, select &lt;B style="mso-bidi-font-weight: normal"&gt;Allow full network access to NAP-ineligible client computers&lt;/B&gt; on the Define NAP Health Policy page.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;11. Bottom line paragraph&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;A. “NAP is a great value for organizations that have yet to invest in NAC”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;We agree! :&amp;gt; NAP deployments require NAP infrastructure servers that are running Windows Server 2008 and client computers running a version of Windows that includes a NAP client. For most organizations, this means upgrading your user computers to Windows Vista or Windows XP with Service Pack 3.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;B. “Microsoft Network Access Protection is difficult to configure, even for simple enforcement methods.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The areas of configuration for NAP consist of the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;NAP clients: Specific NAP enforcement clients must be enabled and, in the case of Windows XP with SP3, the NAP Agent service must be configured to start automatically. Both of these elements of configuration can be done with Group Policy or a script.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;NAP enforcement points: Depending on the NAP enforcement method, you must enable and configure NAP or restricted access functionality.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;NAP health policy servers: The set of policies for a given enforcement method can be automatically created with the Configure NAP wizard in the Network Policy Server snap-in.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Although we respectfully disagree with their blanket statement about NAP configuration, especially relative to other NAC solutions in the marketplace, we agree that there is room for improvement to investigate in future updates for NAP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;C. “We'd like to see a more intuitive auto-install process for an antivirus or anti-spyware client as part of the auto-remediation process”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;As described previously, automatic installation of system health software is a function of the SHA, not the NAP platform. The WSHA does not perform this function, but third-party SHAs can.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3129119" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/industry/default.aspx">industry</category></item><item><title>What is the NAP client doing?</title><link>http://blogs.technet.com/nap/archive/2008/09/05/what-is-the-nap-client-doing.aspx</link><pubDate>Sat, 06 Sep 2008 02:13:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3120045</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3120045.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3120045</wfw:commentRss><description>&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;Greetings, &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;Guardians of NAPness!&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt; &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Here is an interesting question about&amp;nbsp;NAP client behavior that was posed by a fellow NAP fan: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;How does a NAP client communicate a change in health state and get reevaluated and what sort of ongoing traffic is there between the NAP client and the NAP health policy server?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;If you have seen a typical demonstration of NAP autoremediation, the demonstrator intentionally turns off the Windows Firewall on a compliant NAP client. Within seconds, a Network Access Protection message appears in the notification area of the desktop indicating that the computer no longer meets the system health requirements of the network, and then another message appears stating that the computer now meets the system health requirements of the network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;The natural questions that arise from seeing this demo are the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;How does the NAP client know that the firewall was turned off?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;How does the NAP client indicate its new health state to the rest of the NAP infrastructure, get re-evaluated, and receive remediation instructions to turn on the firewall?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;After turning on the firewall, how does the NAP client get re-evaluated and gain full access to the network?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.25in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo2; tab-stops: list .25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Does the demonstrator realize that he has a tuft of hair towards the back of his head that is sticking straight out, acting for all intents and purposes like a rooftop radio antenna?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;I will answer questions 1 through 3 below. As for question 4, I am afraid this issue is beyond the capabilities of the NAP platform at this time and can only suggest a stiff hair gel for a short-term workaround, scissors for a longer term solution, or laser-based hair removal for a permanent solution (or, in my case, a laser is not required; only a few more years are needed!). :&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;The summary answer to questions 1 through 3 is that System Health Agents (SHAs) monitor the configuration state of their associated components and system services for changes that affect system health. When a change occurs, the SHA indicates an updated Statement of Health (SoH) to the NAP Client service, which creates a new System SoH (SSoH) and uses its NAP enforcement clients (ECs) to send the new SSoH to their corresponding NAP enforcement points. The NAP enforcement points then send the SSoH to the NAP health policy server for evaluation. At this point, the process for remediation and reevaluation occurs in the same way as if a noncompliant NAP client started up on the network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Note that the NAP client sends the new SSoH to the NAP health policy server when the configuration change occurs. There is no ongoing, interval-based polling or connection-based data flowing between the NAP client and the NAP health policy server. When indicating a change in health state, the amount of traffic on the wire is the same as the NAP-based traffic when the computer starts up on the network. The traffic on the wire between the NAP enforcement point and the NAP health policy server is typically a handful of RADIUS messages; two messages for each round trip to the NAP health policy server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Let’s apply this explanation to the demonstration: When the Windows Firewall is turned off, the Windows Security Health Agent (WSHA) notices the configuration change, creates a new SoH (with the Windows Firewall state set to disabled), and indicates it to the NAP Client service. The NAP Client service creates and sends a new SSoH containing the updated WSHA SoH to its enforcement point, who forwards it on the NAP health policy server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;The next question that arises from this explanation is the following: OK, smart guy, how exactly does the NAP client indicate the new SSoH to the NAP enforcement point, who forwards it to&amp;nbsp;the NAP health policy server?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;I am glad that you asked…&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;The exact method of indicating the new SSoH depends on the NAP enforcement method. Here is how it is done:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For IPsec enforcement, the NAP client computer deletes its current health certificate and contacts its HRA&amp;nbsp;to obtain&amp;nbsp;a new health certificate. In the ensuing process, the NAP client sends the SSoH to the HRA over HTTP or HTTPS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For 802.1X enforcement, the NAP client computer initiates 802.1X reauthentication on its existing wired or wireless connection. In the ensuing authentication process, the NAP client sends the SSoH in a PEAP-TLV message.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For VPN enforcement, the NAP client computer restarts PPP-based authentication on its existing remote access VPN connection. In the ensuing authentication process, the NAP client sends the SSoH in a PEAP-TLV message.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For DHCP enforcement, the NAP client computer attempts to renew its current DHCP-based IPv4 address configuration. The NAP client sends the SSoH in the DHCPRequest message.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Are there any more questions? It’s Friday. Can I go home now? :&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3120045" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item><item><title>NPS/NAP Logging - BSU.EDU style!</title><link>http://blogs.technet.com/nap/archive/2008/07/08/nps-nap-logging-bsu-edu-style.aspx</link><pubDate>Tue, 08 Jul 2008 17:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3085569</guid><dc:creator>JeffSigman</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/nap/comments/3085569.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3085569</wfw:commentRss><description>&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Hey NAP fans, I’m Alex Chalmers from &lt;/FONT&gt;&lt;A href="http://www.bsu.edu/" target=_blank mce_href="http://www.bsu.edu"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;Ball State University&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt; with a guest post about NPS logging.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;If you made it to one of &lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx"&gt;&lt;FONT color=#0000cc&gt;Jeff’s TechEd IT Pro presentations&lt;/FONT&gt;&lt;/A&gt;, you’ll remember me discussing our NAP implementation and some of the challenges that we’ve faced along the way.&amp;nbsp; Gathering accounting data across the NPS implementation for reporting is one of the largest we’ve faced so far.&amp;nbsp; With multiple NPS servers around our campus for redundancy, trying to trace a session from login to logout can be tough without some type of centralization.&amp;nbsp; There are a few possible solutions, but there are several gotchas to be aware of.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;A natural reaction to the challenge might be to point to using SQL logging using a single, central data source for all of the NPS servers.&amp;nbsp; It isn’t a bad solution for a small/medium sized site and is relatively simple to manage.&amp;nbsp; But there is a pretty large problem with using this scenario when using RADIUS authentication (like with NAP)… if logging the event fails during authentication, the authentication will fail (refer to the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6E4357F7-4070-4902-95F1-3AD411D963B2&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6E4357F7-4070-4902-95F1-3AD411D963B2&amp;amp;displaylang=en"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;Deploying SQL Server Logging with Windows Server 2003 IAS Guide&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;, as it is still relevant).&amp;nbsp; This means that if the central database server is ever down or otherwise unreachable, end users can no longer authenticate (or re-authenticate) to the network.&amp;nbsp; At my site where we use 802.1X enforcement with session timeouts it would probably cause a flurry of helpdesk calls, depending on the length of the outage, and guarantee &lt;EM&gt;persona non grata&lt;/EM&gt; status for me with my client services staff for a few days.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;In trying to work out an alternative solution, other options were rejected for various reasons.&amp;nbsp; Logging to a flat file didn’t solve any problems; it has the same problems of the current design with the added issue of trying to get the data into a reporting format.&amp;nbsp; Trying to use SQL replication was out as we would have had to license SQL Server Standard or Enterprise for all of our NPS servers, as SQL Server Express can’t act as a publisher.&amp;nbsp; Running independent SQL Server Express instances on each NPS system on its own could have worked, but you are limited to a 4GB database and still have to manually centralize the logging.&amp;nbsp; Luckily, as we were looking at this last option some very knowledgeable people suggested we look at using SQL &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/ms166043.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/ms166043.aspx"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;Service Broker&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="WIDTH: 438px; HEIGHT: 252px" height=252 src="http://napteam.members.winisp.net/bsu_logging.jpg" width=438 mce_src="http://napteam.members.winisp.net/bsu_logging.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Service Broker is a communications framework built into SQL Server 2005, and unlike replication in this case it could be used to send data from a SQL Server Express instance to a central data warehouse.&amp;nbsp; The framework design is nearly tailor-made to be used in this situation.&amp;nbsp; In its most basic sense, it enables two entities to send messages to each other while ensuring the messages are reliably received only once and in the same order they were sent.&amp;nbsp; Reliable delivery, even across system restarts and network outages, and delivery without repetition are the two keys for this particular implementation.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;I’ve created a set of &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/npslogging_scripts.zip" target=_blank mce_href="http://napteam.members.winisp.net/npslogging_scripts.zip"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;SQL scripts&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt; that will help you to create the necessary objects for a basic, but functional, solution.&amp;nbsp; But before we can get to implementing anything, we need some prerequisites.&amp;nbsp; You will need to &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/express/sql/download/default.aspx" target=_blank mce_href="http://www.microsoft.com/express/sql/download/default.aspx"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;download&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt; and install SQL Server Express and Management Studio Express on each of your NPS servers.&amp;nbsp; You will also need to have a server capable of storing your aggregate logging data running SQL Server 2005 Standard or Enterprise edition.&amp;nbsp; Unfortunately, Service Broker will not communicate between to Express edition server instances.&amp;nbsp; Each server must be addressable by DNS name.&amp;nbsp; Configuring Service Broker on an instance will open a TCP port for communication, which will need access through any firewalls if present.&amp;nbsp; The de facto default port is 4022, but it can be changed if needed.&amp;nbsp; You will also need to have some paths pre-created for each server’s database and transaction logs, as well as a working directory to store certificate and key backups for disaster recovery purposes.&amp;nbsp; Once you have these prerequisites complete, you can move on to running the scripts.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;These scripts are sample code and assume that objects do not exist.&amp;nbsp; Please take the time to analyze what is going on in each of them, and run through the scenario at least once in a test environment to be certain that the configuration is exactly what you want before moving into production.&amp;nbsp; The script files use the Template Parameter feature of Management Studio Express to allow you to tune certain items in the scripts to fit your environment.&amp;nbsp; Before running the scripts, please fill in the template information by selecting Query-&amp;gt;Specify Values for Template Parameters… from the menu bar.&amp;nbsp; Inside the script zip file, I have included a worksheet with the parameters used in each script to help you prepare.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Starting on the central SQL server, the first script to run is the ConfigureConsolidationServer.sql script.&amp;nbsp; This will configure the Service Broker endpoints, create the consolidated accounting database, and create the basic broker service that each NPS server will connect to.&amp;nbsp; While you should be able to execute the whole script in one batch after configuring the template parameters, I would suggest running it one section of code at a time to see the steps in action.&amp;nbsp; When the script completes, you should have several files in the working directory you specified as a parameter.&amp;nbsp; While you should store each of the files securely for disaster recovery purposes, you will need to copy the two certificates to each NPS server before running the next script.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Once the central server is configured, we can move to each NPS server.&amp;nbsp; Open ConfigureNPSServer.sql in Management Studio Express and configure the necessary parameters.&amp;nbsp; The certificates that you copied over in the previous step should reside in the working directory specified here.&amp;nbsp; Those certificates will be used to identify and secure the remote broker service to the NPS system.&amp;nbsp; This script will generate two similar certificates used to identify the NPS server to the central SQL server.&amp;nbsp; You will need to copy them over before proceeding.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Now that servers have a baseline configuration, running the ConnectNPSServer.sql script on the central SQL server will authorize the NPS server to communicate on the Service Broker service.&amp;nbsp; In a multi-server NPS configuration, you will need to run a version of ConnectNPSServer.sql for each NPS server in the environment.&amp;nbsp; Once the scripts have run successfully, you should configure your NPS logging to log to the local SQL server instance.&amp;nbsp; You will know if the scripts work by examining the RADIUS_Events_XML table on the central SQL server.&amp;nbsp; If events are being stored, the configuration is successful.&amp;nbsp; If you are getting data stored locally, but not to the central server, check that the addresses you’ve used in the scripts are valid and that all the ports are listening as expected.&amp;nbsp; The majority of issues that I've run into with this configuration have been caused by either a bad address or a firewall blocking the Service Broker port that was configured for each server.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;The magic of this configuration happens in two stored procedures: Report_Event on the NPS server and Collect_Events on the central SQL server.&amp;nbsp; Report_Event is called whenever NPS logs an event.&amp;nbsp; NPS sends an XML fragment to the stored procedure, which is then assigned a timestamp and GUID and stored in a local table.&amp;nbsp; Additionally, the stored procedure transmits the data, including the additional timestamp and GUID, via Service Broker to the central SQL server.&amp;nbsp; Collect_Events is called whenever data is logged to the central SQL server's Service Broker queue.&amp;nbsp; It contains the logic to receive messages via the Broker service.&amp;nbsp; The raw XML data is then stored in the RADIUS_Events_XML table, along with the previously assigned GUID and event timestamp.&amp;nbsp; All of the remaining script code is used to create the infrastructure to allow these two procedures to work effectively.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;Since I've said that these scripts are sample code, what could be improved upon for your environment?&amp;nbsp; The first item I would look at is managing the local logs stored on the NPS server.&amp;nbsp; These are stored there only as a safeguard until you can be certain that the data is accessible on the central system.&amp;nbsp; You could deal with this issue in many ways, including not bothering with the local cache.&amp;nbsp; The second major thing to look at is the data format on the central server.&amp;nbsp; While centralizing the data is the main goal of this post, working directly with the XML data for reporting isn't necessarily the most elegant of solutions.&amp;nbsp; You will probably want to either extend the Collect_Events procedure or create a scheduled job that will process the RADIUS_Events_XML table and transform the data into table form.&amp;nbsp; Depending on the data that you're most interested in, you may find that a given event will have multiple entries for a given attribute (SHA SoH data is one) so you might need multiple tables with relationships.&amp;nbsp; Key them off the event GUID assigned in the Report_Event procedure so that you can track an event's data where ever it may reside.&amp;nbsp; The last item that I would look at directly is whether there is any organizational data that you might need to store at or near the time of the event.&amp;nbsp; If your user population has somewhat frequent name changes, as an example, you may want to extend the data to include not only the username of the account used to login but the user object's AD GUID, SID, or some other unique identifier so that you can track a user's activities over a period of time without needing a list of usernames.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;As you can see, this solution provides quite a bit of flexibility to design a system that will work for your needs.&amp;nbsp; The downside to the solution is it does require a fair amount of knowledge about SQL Server to pull data from the logs and design queries that can later be used in a reporting solution, using Reporting Services or some other mechanism.&amp;nbsp; The scripts I've implemented are really only the backbone of the solution, providing the necessary infrastructure and "glue" to allow the servers to communicate effectively.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;I know that you will most likely have questions about our deployment or how these scripts function beyond the small novel of a post I have here.&amp;nbsp; I'll happily answer any question in the comments of this post, or you are most welcome to send me &lt;/FONT&gt;&lt;A href="mailto:alex@alexbchalmers.com?subject=NPS%20Logging%20Solution" target=_blank mce_href="mailto:alex@alexbchalmers.com?subject=NPS%20Logging%20Solution"&gt;&lt;FONT face="trebuchet ms,geneva" color=#0000cc size=3&gt;email&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;.&amp;nbsp; If you have ideas, suggestions, or tips on how you've implemented something please share them as well!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="trebuchet ms,geneva" size=3&gt;- Alex B Chalmers&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3085569" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Deployments/default.aspx">Deployments</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/NPS/default.aspx">NPS</category></item><item><title>NAP Infrastructure Planning and Design (IPD) Guide Now Available!</title><link>http://blogs.technet.com/nap/archive/2008/06/27/nap-infrastructure-planning-and-design-ipd-guide-now-available.aspx</link><pubDate>Sat, 28 Jun 2008 04:19:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3079753</guid><dc:creator>JeffSigman</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3079753.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3079753</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN style="COLOR: #5f497a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 191"&gt;Would you like help selecting the best NAP enforcement method to accomplish your goals? Well, you’re in luck. The fine folks on the&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt; &lt;A class="" href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx"&gt;Solution Accelerators&lt;/A&gt; &lt;SPAN style="COLOR: #5f497a; mso-themecolor: accent4; mso-themeshade: 191"&gt;team have created guidance on just that topic!&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN style="COLOR: #5f497a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 191"&gt;The document is entitled “&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://download.microsoft.com/download/5/b/c/5bc966bc-47d8-41df-95f2-fa9a2d816258/Selecting%20the%20Right%20NAP%20Architecture.zip" target=_blank mce_href="http://download.microsoft.com/download/5/b/c/5bc966bc-47d8-41df-95f2-fa9a2d816258/Selecting%20the%20Right%20NAP%20Architecture.zip"&gt;Selecting the Right NAP Architecture&lt;/A&gt;”. &lt;SPAN style="COLOR: #5f497a; mso-themecolor: accent4; mso-themeshade: 191"&gt;Here is the main page which lists the available&lt;/SPAN&gt; &lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD3921FB-8224-4681-9064-075FDF042B0C&amp;amp;SAMI_Campaign_Name=IPD062708RTM_IPDDL&amp;amp;displaylang=en" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD3921FB-8224-4681-9064-075FDF042B0C&amp;amp;SAMI_Campaign_Name=IPD062708RTM_IPDDL&amp;amp;displaylang=en"&gt;Infrastructure Planning and Design&lt;/A&gt; &lt;SPAN style="COLOR: #5f497a; mso-themecolor: accent4; mso-themeshade: 191"&gt;Guides.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx"&gt;&lt;FONT size=3&gt;Solution Accelerators&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; &lt;SPAN style="COLOR: #5f497a; mso-themecolor: accent4; mso-themeshade: 191"&gt;are free, scenario-based guides and automations designed to help IT professionals who are proactively planning, deploying, and operating IT systems using Microsoft products and technologies.&lt;/SPAN&gt; &lt;/FONT&gt;&lt;A class="" href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/solutionaccelerators/default.aspx"&gt;&lt;FONT size=3&gt;Solution Accelerator&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; &lt;SPAN style="COLOR: #5f497a; mso-themecolor: accent4; mso-themeshade: 191"&gt;scenarios focus on security and compliance, management and infrastructure, and communication and collaboration.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #5f497a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 191"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #5f497a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 191"&gt;&lt;FONT size=3&gt;NAP the WORLD baby,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #5f497a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 191"&gt;&lt;FONT size=3&gt;Jeff&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3079753" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item><item><title>NAP 802.1X Configuration Walkthrough – Part 3</title><link>http://blogs.technet.com/nap/archive/2008/06/22/nap-802-1x-configuration-walkthrough-part-3.aspx</link><pubDate>Sun, 22 Jun 2008 21:02:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3076164</guid><dc:creator>JeffSigman</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/nap/comments/3076164.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3076164</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;This is a continuation from &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Part 1&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt; and &lt;/FONT&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/20/nap-802-1x-configuration-walkthrough-part-2.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/20/nap-802-1x-configuration-walkthrough-part-2.aspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Part 2&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt"&gt;
&lt;P class=MsoNormal style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; MARGIN: 0in 0in 10pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .75pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Step 3 – NAP Clients, it’s just too easy&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;NAP can be configured from the command-line, the MMC (except on XP SP3) and of course Group Policy (GP). Since this is a workgroup scenario, I am going to skip GP – but the principles below are the same.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;A class="" href="http://napteam.members.winisp.net/23%20services.jpg" target=_blank mce_href="http://napteam.members.winisp.net/23%20services.jpg"&gt;&lt;FONT size=3&gt;Start the services snap-in&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; and locate &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/24%20services%20-%20NAP.jpg" target=_blank mce_href="http://napteam.members.winisp.net/24%20services%20-%20NAP.jpg"&gt;&lt;FONT size=3&gt;these two services&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; – “Network Access Protection Agent” (NAPAgent) and “Wired AutoConfig” (dot3svc).&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Start &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/25%20services%20-%20NAP%20-%20start.jpg" target=_blank mce_href="http://napteam.members.winisp.net/25%20services%20-%20NAP%20-%20start.jpg"&gt;&lt;FONT size=3&gt;NAPAgent&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; and &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/26%20services%20-%20DOT3%20-%20start.jpg" target=_blank mce_href="http://napteam.members.winisp.net/26%20services%20-%20DOT3%20-%20start.jpg"&gt;&lt;FONT size=3&gt;Dot3svc&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;; set both to “Automatic” startup.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;sc config NAPAgent start= auto&lt;BR&gt;net start NAPAgent&lt;BR&gt;sc config Dot3Svc start= auto&lt;BR&gt;net start Dot3Svc&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Start the &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/27%20NAP%20cfg.jpg" target=_blank mce_href="http://napteam.members.winisp.net/27%20NAP%20cfg.jpg"&gt;&lt;FONT size=3&gt;NAP Client Configuration snap-in&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;; click on the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/28%20NAP%20cfg%20-%20qec.jpg" target=_blank mce_href="http://napteam.members.winisp.net/28%20NAP%20cfg%20-%20qec.jpg"&gt;&lt;FONT size=3&gt;Enforcement Clients&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” link.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Enable the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/29%20NAP%20cfg%20-%20qec%20-%20eap.jpg" target=_blank mce_href="http://napteam.members.winisp.net/29%20NAP%20cfg%20-%20qec%20-%20eap.jpg"&gt;&lt;FONT size=3&gt;EAP Quarantine Enforcement Client&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” by double-clicking on it and selecting “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/30%20NAP%20cfg%20-%20qec%20-%20eap%20enable.jpg" target=_blank mce_href="http://napteam.members.winisp.net/30%20NAP%20cfg%20-%20qec%20-%20eap%20enable.jpg"&gt;&lt;FONT size=3&gt;Enable this enforcement client&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;”.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;netsh NAP client set enforcement ID = "79623" ADMIN = "ENABLE"&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Click on the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/31%20NAP%20cfg%20-%20UI.jpg" target=_blank mce_href="http://napteam.members.winisp.net/31%20NAP%20cfg%20-%20UI.jpg"&gt;&lt;FONT size=3&gt;User Interface Settings&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” link; double-click on the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/32%20NAP%20cfg%20-%20UI%20settings.jpg" target=_blank mce_href="http://napteam.members.winisp.net/32%20NAP%20cfg%20-%20UI%20settings.jpg"&gt;&lt;FONT size=3&gt;User Interface Settings&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” entry to &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/33%20NAP%20cfg%20-%20UI%20settings%20text.jpg" target=_blank mce_href="http://napteam.members.winisp.net/33%20NAP%20cfg%20-%20UI%20settings%20text.jpg"&gt;&lt;FONT size=3&gt;configure text to be displayed&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; to users when NAP is unable to (or in progress of) auto-remediate a problem on the computer.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;netsh NAP client set userinterface TITLE = "I regret to inform you that you have been NAP'd!!" TEXT = "Please logoff and go home, do not collect $200"&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;You may &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/34%20NAP%20cfg%20-%20export.jpg" target=_blank mce_href="http://napteam.members.winisp.net/34%20NAP%20cfg%20-%20export.jpg"&gt;&lt;FONT size=3&gt;export / import&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; these settings if you wish.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;netsh NAP client export FILENAME = "c:\NapCfg.xml"&lt;BR&gt;netsh NAP client import FILENAME = "&lt;A class="" href="http://napteam.members.winisp.net/NapCfg.xml" target=_blank mce_href="http://napteam.members.winisp.net/NapCfg.xml"&gt;c:\NapCfg.xml&lt;/A&gt;"&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Start the &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/35%20ncpa.jpg" target=_blank mce_href="http://napteam.members.winisp.net/35%20ncpa.jpg"&gt;&lt;FONT size=3&gt;Network Connections folder&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;; right-click on your network interface and select “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/36%20ncpa%20-%20props.jpg" target=_blank mce_href="http://napteam.members.winisp.net/36%20ncpa%20-%20props.jpg"&gt;&lt;FONT size=3&gt;Properties&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Since you started the “Dot3Svc”, you will now see the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/37%20ncpa%20-%20auth.jpg" target=_blank mce_href="http://napteam.members.winisp.net/37%20ncpa%20-%20auth.jpg"&gt;&lt;FONT size=3&gt;Authentication&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” tab; Enable 802.1X and caching; Make sure PEAP is selected; Clicks “Settings”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;In the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/38%20ncpa%20-%20peap.jpg" target=_blank mce_href="http://napteam.members.winisp.net/38%20ncpa%20-%20peap.jpg"&gt;&lt;FONT size=3&gt;Protected EAP Properties&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” dialog, un-check “Validate server certificate”; Select MS-CHAPv2; Check “Enable Quarantine checks”; Click “Configure”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;In the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/39%20ncpa%20-%20mschapv2.jpg" target=_blank mce_href="http://napteam.members.winisp.net/39%20ncpa%20-%20mschapv2.jpg"&gt;&lt;FONT size=3&gt;EAP MSCHAPv2 Properties&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” dialog, un-check the auto-use credentials setting – this is because we are in a workgroup – if you were in a domain you would want to leave this enabled so the domain user would automatically use his domain credentials.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;After you “OK” all of those dialogs, the 802.1X client should now attempt to authenticate to the switch port; if not, simply enable/disable or unplug/plug the NIC; you should &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/40%20popup.jpg" target=_blank mce_href="http://napteam.members.winisp.net/40%20popup.jpg"&gt;&lt;FONT size=3&gt;get prompted for credentials&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;; type the &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/41%20creds.jpg" target=_blank mce_href="http://napteam.members.winisp.net/41%20creds.jpg"&gt;&lt;FONT size=3&gt;user / password&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;If everything works you should see something like &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/42%20ncpa%20-%20success.jpg" target=_blank mce_href="http://napteam.members.winisp.net/42%20ncpa%20-%20success.jpg"&gt;&lt;FONT size=3&gt;this&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;; any failures usually show “authentication failed”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Thankfully, you can also use the command-line to export/import these settings too.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;netsh lan export profile FOLDER = "c:\\"&lt;BR&gt;netsh lan add profile FILENAME = "&lt;A class="" href="http://napteam.members.winisp.net/LANProfile.xml" target=_blank mce_href="http://napteam.members.winisp.net/LANProfile.xml"&gt;c:\LANProfile.xml&lt;/A&gt;"&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Hopefully you now have&amp;nbsp;end-to-end NAP 802.1X working. If not, my next installment includes troubleshooting! :-&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Jeff&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3076164" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item><item><title>NAP 802.1X Configuration Walkthrough – Part 2</title><link>http://blogs.technet.com/nap/archive/2008/06/20/nap-802-1x-configuration-walkthrough-part-2.aspx</link><pubDate>Fri, 20 Jun 2008 19:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3075096</guid><dc:creator>JeffSigman</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.technet.com/nap/comments/3075096.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3075096</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;NAP 802.1X Configuration Walkthrough – Part 2&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;This is a continuation from &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Part 1&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt"&gt;
&lt;P class=MsoNormal style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; MARGIN: 0in 0in 10pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .75pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Step 2 – Windows Server 2008 NPS, the heart of NAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;I am going to take a slightly different approach than the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2007/04/26/updated-nap-step-by-step-guides-for-longhorn-beta-3.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2007/04/26/updated-nap-step-by-step-guides-for-longhorn-beta-3.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;802.1X step-by-step guide&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;. Feel free to follow either method, whatever gets it done for you!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;My configuration assumes a “WORKGROUP”, not domain joined. Again, for simplicity of building a demonstration, I prefer to remove the AD component.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Open “Server Manager”, just in case it didn’t open for you on logon. :-&amp;gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/01%20role%20-%20add.jpg" target=_blank mce_href="http://napteam.members.winisp.net/01%20role%20-%20add.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Add&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt; our NAP role – “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/02%20role%20-%20npas.jpg" target=_blank mce_href="http://napteam.members.winisp.net/02%20role%20-%20npas.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Network Policy and Access Services&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Add our role service – “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/03%20role%20service%20-%20nps.jpg" target=_blank mce_href="http://napteam.members.winisp.net/03%20role%20service%20-%20nps.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Network Policy Server (NPS)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;”.&lt;BR&gt;&lt;BR&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;*Tip*&lt;/I&gt;&lt;/B&gt; - if you also install the “Health Registration Authority (HRA)”, this is used only if you are doing NAP + IPsec, it may save you a bit of pain getting 802.1X to work. It has an option to create a “self-signed certificate” for the server. NPS / EAP require a server certificate to do 802.1X NAP.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;This is an important step, in case you are skipping the previous steps on installing the stuff. You should clear ALL EXISTING CONFIGURATION. Even on a default install, I clear it all out for my own sanity. Clean slate baby; easier to debug.&lt;BR&gt;&lt;BR&gt;The &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/04%20clear%20config.jpg" target=_blank mce_href="http://napteam.members.winisp.net/04%20clear%20config.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;four nodes to clear&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt; are 1.) RADIUS Clients 2.) Connection Request Policies 3.) Network Policies 4.) Health Policies.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Now that we have a clean configuration, let’s run the spiffy wizard. Click on the top “NPS” node within the tree-view. You should then see a “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/05%20config%20NAP.jpg" target=_blank mce_href="http://napteam.members.winisp.net/05%20config%20NAP.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Configure NAP&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;” link on the “Getting Started” page.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;The first page of the wizard is figuring out which scenario of NAP enforcement you want to configure. For this walkthrough, I am discussing “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/06%20config%20NAP%20-%20wired.jpg" target=_blank mce_href="http://napteam.members.winisp.net/06%20config%20NAP%20-%20wired.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;IEEE 802.1X (Wired)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;”.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Time to configure a RADIUS client (i.e. 802.1X switch). You will have to remember the IP address and shared secret that you configured on the switch itself in &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Part 1&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;. Click the “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/07%20config%20NAP%20-%20radius.jpg" target=_blank mce_href="http://napteam.members.winisp.net/07%20config%20NAP%20-%20radius.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Add&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;” button. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/08%20config%20NAP%20-%20radius%20props.jpg" target=_blank mce_href="http://napteam.members.winisp.net/08%20config%20NAP%20-%20radius%20props.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Fill in&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt; a nice friendly name for the switch (maybe a model# and physical location and such – it will be displayed in the logs later), the IP address of the switch (use the management VLAN 1 IP interface) and the shared secret.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Since this is a workgroup, the next page &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/09%20config%20NAP%20-%20ad%20stuff.jpg" target=_blank mce_href="http://napteam.members.winisp.net/09%20config%20NAP%20-%20ad%20stuff.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;can be skipped&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;. This is where you can specify what machines and users should be included in your NAP deployment. This is pretty cool in that you can roll out NAP at your own pace throughout a domain.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;As I mentioned in the *tip* above, NAP + 802.1X &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/10%20config%20NAP%20-%20cert.jpg" target=_blank mce_href="http://napteam.members.winisp.net/10%20config%20NAP%20-%20cert.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;needs a certificate on the server-side to function&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;. A self-signed cert is a quick and easy way to get this going for a workgroup.&lt;BR&gt;&lt;BR&gt;I am going to be discussing user-based NAP 802.1X – thus you only need to enable PEAP-MS-CHAPv2. If you were in an AD, you could deploy auto-enrolled machine certificates and get 802.1X machine authentication working. It is pretty slick.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Alrighty then, this is the fun bit – configuring the VLANs. It is relatively painless. This can sometimes vary depending on the switch. I will say that all seven of the switches I configured for RSA needed the same exact settings &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/11%20config%20NAP%20-%20vlan.jpg" target=_blank mce_href="http://napteam.members.winisp.net/11%20config%20NAP%20-%20vlan.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;in here&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;.&lt;BR&gt;&lt;BR&gt;The “Organization network VLAN” is what I am calling the Compliant VLAN. Obviously the “Restricted network VLAN” is the Non-Compliant VLAN.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/12%20config%20NAP%20-%20vlan%20-%20compliant.jpg" target=_blank mce_href="http://napteam.members.winisp.net/12%20config%20NAP%20-%20vlan%20-%20compliant.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Compliant VLAN settings&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;:&lt;BR&gt;Tunnel-Type&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;= Virtual LANs (VLAN)&lt;BR&gt;Tunnel-Medium-Type&lt;SPAN style="mso-tab-count: 1"&gt; &lt;/SPAN&gt;= 802 (includes all 802 media ...)&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Tunnel-Pvt-Group&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;= 2&lt;BR&gt;&lt;/B&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/13%20config%20NAP%20-%20vlan%20-%20noncompliant.jpg" target=_blank mce_href="http://napteam.members.winisp.net/13%20config%20NAP%20-%20vlan%20-%20noncompliant.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Non-Compliant VLAN settings&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;:&lt;BR&gt;Tunnel-Type&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;= Virtual LANs (VLAN)&lt;BR&gt;Tunnel-Medium-Type&lt;SPAN style="mso-tab-count: 1"&gt; &lt;/SPAN&gt;= 802 (includes all 802 media ...)&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Tunnel-Pvt-Group&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;= 3&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;The “Health” settings that are available to you without any additional software are around the Windows Security Center. In NAP, this component is called on the NAP client “Windows Security System Health Agent” – and on the NAP server “Windows Security System Health Validator”.&lt;BR&gt;&lt;BR&gt;You will notice &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A class="" href="http://napteam.members.winisp.net/14%20config%20NAP%20-%20WSHV.jpg" target=_blank mce_href="http://napteam.members.winisp.net/14%20config%20NAP%20-%20WSHV.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;in my screenshot&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt; that I have other stuff in there. These are plug-ins to NAP I was showing off at &lt;/FONT&gt;&lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx"&gt;&lt;FONT size=3&gt;TechEd 2008 Orlando&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;. You should be able to accept the defaults on this page and party on.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;A class="" href="http://napteam.members.winisp.net/15%20config%20NAP%20-%20finish.jpg" target=_blank mce_href="http://napteam.members.winisp.net/15%20config%20NAP%20-%20finish.jpg"&gt;&lt;FONT size=3&gt;The wizard is done&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;!&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;You should verify that the wizard added the configuration in the following nodes - 1.) &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/16%20configured%20-%20RADIUS.jpg" target=_blank mce_href="http://napteam.members.winisp.net/16%20configured%20-%20RADIUS.jpg"&gt;&lt;FONT size=3&gt;RADIUS Clients&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; 2.) &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/17%20configured%20-%20CRP.jpg" target=_blank mce_href="http://napteam.members.winisp.net/17%20configured%20-%20CRP.jpg"&gt;&lt;FONT size=3&gt;Connection Request Policies&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; 3.) &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/18%20configured%20-%20RAP.jpg" target=_blank mce_href="http://napteam.members.winisp.net/18%20configured%20-%20RAP.jpg"&gt;&lt;FONT size=3&gt;Network Policies&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; 4.) &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/19%20configured%20-%20Health.jpg" target=_blank mce_href="http://napteam.members.winisp.net/19%20configured%20-%20Health.jpg"&gt;&lt;FONT size=3&gt;Health Policies&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;.&lt;BR style="mso-special-character: line-break"&gt;&lt;BR style="mso-special-character: line-break"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Navigate to the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/20%20configured%20-%20WSHV.jpg" target=_blank mce_href="http://napteam.members.winisp.net/20%20configured%20-%20WSHV.jpg"&gt;&lt;FONT size=3&gt;System Health Validators&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” node in the tree and double-click the “Windows Security Health Validator”. Click the “&lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/21%20WSHV.jpg" target=_blank mce_href="http://napteam.members.winisp.net/21%20WSHV.jpg"&gt;&lt;FONT size=3&gt;Configure&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;” button. I recommend starting small and &lt;/FONT&gt;&lt;A class="" href="http://napteam.members.winisp.net/22%20WSHV%20-%20Vista.jpg" target=_blank mce_href="http://napteam.members.winisp.net/22%20WSHV%20-%20Vista.jpg"&gt;&lt;FONT size=3&gt;just check for the Windows Firewall&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; at first.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Nicely done! On to the client in the next installment!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Jeff&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3075096" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/NPS/default.aspx">NPS</category></item><item><title>NAP 802.1X Configuration Walkthrough – Part 1</title><link>http://blogs.technet.com/nap/archive/2008/06/19/nap-802-1x-configuration-walkthrough.aspx</link><pubDate>Thu, 19 Jun 2008 20:08:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3074516</guid><dc:creator>JeffSigman</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.technet.com/nap/comments/3074516.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3074516</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;I just got back from &lt;A class="" href="http://blogs.technet.com/nap/search.aspx?q=teched&amp;amp;p=1" target=_blank mce_href="http://blogs.technet.com/nap/search.aspx?q=teched&amp;amp;p=1"&gt;TechEd 2008 North America (Orlando)&lt;/A&gt; where I presented &lt;A class="" href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/06/09/nap-ing-teched-orlando-2008.aspx"&gt;two “breakout” sessions on NAP&lt;/A&gt;. It went off with a bang and most people really loved the sessions / demos. I have blogged a &lt;A class="" href="http://blogs.technet.com/jeffsigman/archive/2008/04/14/nap-world-tour-rocks-rsa-2008-san-francisco.aspx" target=_blank mce_href="http://blogs.technet.com/jeffsigman/archive/2008/04/14/nap-world-tour-rocks-rsa-2008-san-francisco.aspx"&gt;couple times in the past&lt;/A&gt; that I would document exactly how I made it all work and now I want to come through on that promise.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Back in April of this year I created a cool &lt;A class="" href="http://blogs.technet.com/nap/archive/2008/04/15/video-nap-world-tour-rsa-2008-san-francisco.aspx" target=_blank mce_href="http://blogs.technet.com/nap/archive/2008/04/15/video-nap-world-tour-rsa-2008-san-francisco.aspx"&gt;802.1X NAP Interoperability Showcase for the RSA show&lt;/A&gt; – it was two mobile racks (guitar racks actually) full of vendor 802.1X wired gear. I had devices from Cisco, D-Link, Enterasys, Extreme, Foundry, HP ProCurve and Nortel. I got it all working flawlessly with NAP / NPS / Server 2008! It was quite a thing to get working being a guy who deals chiefly in Windows OS’s (and not much networking hardware). After getting it all working I felt some serious love for the scenario – it is definitely my favorite flavor of the 6 NAP enforcement methods we support (DHCP, IPsec, 802.1X, VPN, TSG and Cisco NAC).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Before I head to Windows configuration, we need to talk GEAR. Here are the devices I got working in the showcase rack. I included links to my configuration files from the first five (I need to dig up the other guys too):&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://napteam.members.winisp.net/HP%20ProCurve%202626.txt" target=_blank mce_href="http://napteam.members.winisp.net/HP%20ProCurve%202626.txt"&gt;&lt;FONT size=3&gt;HP ProCurve 2626&lt;/FONT&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #403152; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://napteam.members.winisp.net/Cisco%20Catalyst%203550.txt" target=_blank mce_href="http://napteam.members.winisp.net/Cisco%20Catalyst%203550.txt"&gt;&lt;FONT size=3&gt;Cisco Catalyst 3550&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://napteam.members.winisp.net/D-Link%20xStack%20DES-3828.txt" target=_blank mce_href="http://napteam.members.winisp.net/D-Link%20xStack%20DES-3828.txt"&gt;&lt;FONT size=3&gt;D-Link xStack DES-3828&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://napteam.members.winisp.net/Extreme%20Summit%20X450-24t.txt" target=_blank mce_href="http://napteam.members.winisp.net/Extreme%20Summit%20X450-24t.txt"&gt;&lt;FONT size=3&gt;Extreme Summit X450-24t&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;5.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A class="" href="http://napteam.members.winisp.net/Foundry%20FastIron%20Edge%204802-POE.txt" target=_blank mce_href="http://napteam.members.winisp.net/Foundry%20FastIron%20Edge%204802-POE.txt"&gt;&lt;FONT size=3&gt;Foundry FastIron Edge 4802-POE&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;6.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Enterasys 2G4072-52&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;7.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Nortel BayStack 5520-24T-PWR&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;I also saved off a copy of the&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt; &lt;A class="" href="http://napteam.members.winisp.net/NPS%20Config%2003-25-2008.xml" target=_blank mce_href="http://napteam.members.winisp.net/NPS%20Config%2003-25-2008.xml"&gt;Network Policy Server (NPS) XML configuration file&lt;/A&gt; &lt;SPAN style="COLOR: #403152; mso-themecolor: accent4; mso-themeshade: 128"&gt;if you want to refer to it. Use caution when using these files. I don’t want you to frakk your switch! For the purposes of this walkthrough, I am going to discuss the specifics of the HP ProCurve 2626. It is a switch that is near and dear to my heart as it is the first one I ever got working. :-&amp;gt; Some things may vary on your brand / model.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt"&gt;
&lt;P class=MsoNormal style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; MARGIN: 0in 0in 10pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .75pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Step 1 – Configure that switch baby&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;This step caused me some serious pain for a number of reasons. I was handed 7 switches with NO power cables, NO terminal cables NOR any instruction manuals. Whoa ho! “Good luck” was something I was thinking at the time. I hope you aren’t in the same boat here. :-&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;The ProCurve wasn’t bad at all once I found a female-to-female DB9 cable (i.e. Radio Shack). Being a Microsoft guy, I felt obligated to use Hyper Terminal (some Linux guys later informed me about &lt;A class="" href="http://en.wikipedia.org/wiki/PuTTY" target=_blank mce_href="http://en.wikipedia.org/wiki/PuTTY"&gt;PuTTY&lt;/A&gt;, which is pretty cool). Since Hypertrm disappeared from Vista (huh?!?), I went to my XP SP3 box and copied the required files to my memory stick (hypertrm.chm, hypertrm.dll, hypertrm.exe, hypertrm.hlp).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;To get connected to the ProCurve I used &lt;A class="" href="http://napteam.members.winisp.net/hypertrm1.jpg" target=_blank mce_href="http://napteam.members.winisp.net/hypertrm1.jpg"&gt;8-N-1&lt;/A&gt; @ 115,200 with Xon/Xoff and &lt;A class="" href="http://napteam.members.winisp.net/hypertrm2.jpg" target=_blank mce_href="http://napteam.members.winisp.net/hypertrm2.jpg"&gt;VT100 emulation&lt;/A&gt;. Boy, this brought me back to my modem days. After hitting “connect” and enter a couple times, you should be presented with &lt;A class="" href="http://napteam.members.winisp.net/hypertrm3.jpg" target=_blank mce_href="http://napteam.members.winisp.net/hypertrm3.jpg"&gt;this&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;By the way, you can use HP’s web based configuration interface for some stuff, like configuring VLANs, but it isn’t able to handle RADIUS configuration – which made me move right over to terminal for everything.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;&lt;A class="" href="http://napteam.members.winisp.net/802.1X%20diagram.jpg" target=_blank mce_href="http://napteam.members.winisp.net/802.1X diagram.jpg"&gt;Here is a simple diagram&lt;/A&gt; of what every switch looked like. 3 VLANs total:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;VLAN 1: Management VLAN. Each of the seven switches had an IP address on the 10.x network. This is so they could do two things – authenticate to the NPS via RADIUS + relay the DHCP/BOOTP traffic to the DHCP server running on Windows Server 2008.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;VLAN 2: Compliant VLAN. AKA – the “healthy network”. Clients on this network are compliant with your policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: Symbol; mso-themecolor: accent4; mso-themeshade: 128; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;VLAN 3: Non-Compliant VLAN – AKA – the “unhealthy network”. Clients on this network are not compliant with your policy. They should not be able to contact clients in Compliant VLAN. It is also advisable to restrict what they can reach on the Management VLAN – only resources required to get them fixed up as well as infrastructure (e.g. AD).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;Let’s take a look at the &lt;A class="" href="http://napteam.members.winisp.net/HP%20ProCurve%202626.txt" target=_blank mce_href="http://napteam.members.winisp.net/HP%20ProCurve%202626.txt"&gt;ProCurve configuration I am using&lt;/A&gt;:&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 9pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;Startup configuration:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;; J4900B Configuration Editor; Created on release #H.10.45&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;hostname "HP ProCurve 2626"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;ip routing&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "Management"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;untagged 2,4,6,8-26&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 10.0.0.2 255.0.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;no untagged 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "Compliant"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 20.0.0.1 255.255.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip helper-address 10.0.0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "NonCompliant"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;untagged 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 30.0.0.1 255.255.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip helper-address 10.0.0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa authentication port-access eap-radius authorized&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;radius-server host 10.0.0.1 key secret&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;primary-vlan 3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access authenticator 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access authenticator active&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;BR&gt;&lt;FONT size=3&gt;Since I have multiple IP segments, I needed to enable IP Routing on the switch. This line makes that happen:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: 'Courier New'"&gt;ip routing&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;BR&gt;&lt;FONT size=3&gt;Here are the VLANs. The names are self-evident. I only wanted 4 ports available for clients to authenticate with 802.1X (ports 1,3,5,7). I am not using 802.1X’s notion of port tagging the Ethernet frames, which I won’t go into here. I was going for simplicity, so I treated all seven of the switches like a completely separate network (non-routable between each switch).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "Management"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;untagged 2,4,6,8-26&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 10.0.0.2 255.0.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;no untagged 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 2&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "Compliant"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 20.0.0.1 255.255.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip helper-address 10.0.0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;vlan 3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;name "NonCompliant"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;untagged 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip address 30.0.0.1 255.255.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;ip helper-address 10.0.0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;exit&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;BR&gt;&lt;FONT size=3&gt;We need to enable 802.1X on a port by port basis, as well as tell the switch how we intend to authenticate these ports. This is where we point the switch at the Windows Server 2008 machine running Network Policy Server (NPS). The shared secret I am using in this example is complex – it is “secret”. :-&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa authentication port-access eap-radius authorized&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;radius-server host 10.0.0.1 key secret&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;primary-vlan 3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access authenticator 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access authenticator active&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNoSpacing style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; FONT-FAMILY: 'Courier New'; mso-themecolor: text1"&gt;aaa port-access 1,3,5,7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;BR&gt;&lt;FONT size=3&gt;Make sure you commit the configuration to memory!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; TEXT-INDENT: 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: #403152; LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; mso-themecolor: accent4; mso-themeshade: 128"&gt;HP ProCurve 2626# write memory&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt"&gt;
&lt;P class=MsoNormal style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; MARGIN: 0in 0in 10pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .75pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Got more coming at you tomorrow! Stay tuned.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #403152; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent4; mso-themeshade: 128"&gt;&lt;FONT size=3&gt;Jeff&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3074516" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/NPS/default.aspx">NPS</category></item><item><title>How ‘bout some NAP perspective from the field</title><link>http://blogs.technet.com/nap/archive/2008/05/12/how-bout-some-nap-perspective-from-the-field.aspx</link><pubDate>Tue, 13 May 2008 08:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3054362</guid><dc:creator>JeffSigman</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/3054362.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3054362</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;Hello NAP Bloggers! My name is Mark Foust, a Windows Server Networking Technical Specialist working down in Tampa Florida (USA). I wanted to share a bit of my perspective on the world of &lt;B style="mso-bidi-font-weight: normal"&gt;{&lt;/B&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #e36c0a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent6; mso-themeshade: 191"&gt;NAP&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;}&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;7 things you may not have considered about NAP&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP enforces &lt;I&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;minimum&lt;/SPAN&gt;&lt;/I&gt; consistency levels, not maximum security&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP should be looked at as a mechanism to enforce the &lt;I&gt;minimum&lt;/I&gt; machine / device requirements, not maximum levels. NAP is not meant as a lockdown mechanism, rather an &lt;I style="mso-bidi-font-style: normal"&gt;&lt;U&gt;enabler&lt;/U&gt;&lt;/I&gt; of IT by automating minimum security levels during connection (as well as on-going compliance). NAP is not a holistic security template, nor a point of control for managing the patch levels for every device. NAP is enforced at entry points in your infrastructure DHCP, VPN, IPSEC and 802.1X entry points. As with every technology there will be &lt;I&gt;some&lt;/I&gt; devices that need exceptions….see #6&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP doesn’t care much about your user login&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;Assuming you are in the same forest/domain as your workstation---a somewhat safe assumption. NAP is typically device / machine based and not user based; an important distinction as it is the hardware device object, in Active Directory, that requires the Group Policy objects to be applied, not users. Note that Group Policy is applied in a L&amp;gt;S&amp;gt;D&amp;gt;OU fashion---Local, Site, Domain and OU. In that order and last writer wins any conflicts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;The exception to this is 802.1X + NAP – you are able to do machine AND user authentication at the hardware layer and can create user based NAP policies. Also notable is that NAP functions in a “workgroup” and doesn’t require a domain at all!&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP’s greatest initial advantage is &lt;I style="mso-bidi-font-style: normal"&gt;REPORTING&lt;/I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;You may not have considered this, but enforcing something as simple as a single AV engine or update may have unintended consequences on your network. For example, what if you found out that 17% of your users were not running standard up-to-date AV signatures? NAP would/could lock out 17% of your company for failing to comply. You’d probably find a lot of lab machines, vendor laptops (guests), virtual machines and line of business (LOB) devices that may have been granted such AV exceptions in the past. Be careful. You will want to initially only &lt;I&gt;report&lt;/I&gt; on each policy violation. This is going to give you information you’ve long needed to report on LOB compliancy, vendors and a cadre of other statistical variances that you have probably not considered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP should &lt;I&gt;not&lt;/I&gt; be viewed as a forklift type of upgrade or enforcement mechanism. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;You must exercise caution when implementing restrictive policies on an enterprise. Reasonable preparation before enforcement should include testing, piloting, communication to your end-user community, and training of help desk to assist in remediation of issues that occur. Also, a good back-out plan should be in place should there be too restrictive a setting enforce or errors. Proper lab testing and production pilot testing involving sample groups is always a best practice. Allow for time to do administrative knowledge transfer---should the main NAP administrators be away for a couple days. In other words, don’t wait for an implementation issue to bite you before you plan.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;5.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP will highlight your weak operational issues.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;This is a &lt;I&gt;good&lt;/I&gt; thing. If you’ve not spent much time considering how you remediate the automation types of issues that NAP will remediate, you are going to get a chance. If you’ve felt like you’ve not had much executive support to enforce patching / update minimums in the past, NAP will help push that conversation. The key word here is &lt;I&gt;automation&lt;/I&gt; to remediate patching / updating types of issues. This will help you enforce security maturity across your enterprise. With NAP, it becomes harder to &lt;I&gt;exclude&lt;/I&gt; the guilty client workstations / device---a very different way to govern for you. Every enterprise has silos and fiefdoms. NAP helps bridge this gap with a constant, consistent, enterprise-wide, minimum enforcement mechanism. You are not the bad guy anymore. When someone comes to you mad that you patched their machine, you are able to defer patching enforcement discussions to a &lt;I&gt;higher&lt;/I&gt; power---NAP in the cloud. :-&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;6.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;You will need to make &lt;I&gt;some&lt;/I&gt; exceptions for NAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP provides a mechanism to support your administrative needs to ensure everyone is at least on a minimum patch / security level. This may not play well with certain applications that only support a standard like n-2 or an old legacy Server 2003 SP1 machine. Realize that this constant enforcement of updating does not replace your testing needs around application compatibility testing. You may find that NAP will cause you to mature your OU structure. Application Servers may get their own OU now---which is a best practice for Active Directory Security anyway….to break your servers down into roles and possibly applications as sub-sets of those roles, then apply more/less restrictive policies on those servers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoListParagraph style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128; mso-fareast-font-family: 'Trebuchet MS'; mso-bidi-font-family: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;7.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP will become a foundational part of your infrastructure&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 1in"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;NAP is not just a simplistic feature; it is a service running on your OS [for Windows Server 2008, Vista RTM/SP1, and XP SP3]. This service will bring stability, security, maturity through automation to your enterprise. &lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/infrastructure/default.aspx"&gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT color=#0000ff&gt;Your homework: Figure out why this is so important at a high level&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;BR&gt;NAP the world baby!&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;- Mark&lt;/SPAN&gt;&lt;SPAN style="COLOR: #244061; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent1; mso-themeshade: 128"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3054362" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item><item><title>NAP FAQ: Logging baby, logging</title><link>http://blogs.technet.com/nap/archive/2008/04/26/nap-faq-logging-baby-logging.aspx</link><pubDate>Sun, 27 Apr 2008 00:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3045548</guid><dc:creator>JeffSigman</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/3045548.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3045548</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #e36c0a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent6; mso-themeshade: 191"&gt;&lt;FONT size=3&gt;A colleague of mine pointed out an AMAZING blog post on the &lt;/FONT&gt;&lt;A class="" href="http://blogs.technet.com/wincat/" target=_blank mce_href="http://blogs.technet.com/wincat/"&gt;&lt;FONT color=#0000ff size=3&gt;Windows Server Customer Advisory Team (WinCAT)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; team blog - &lt;/FONT&gt;&lt;A class="" href="http://blogs.technet.com/wincat/archive/2007/10/29/the-definitive-guide-to-nap-logging.aspx" target=_blank mce_href="http://blogs.technet.com/wincat/archive/2007/10/29/the-definitive-guide-to-nap-logging.aspx"&gt;&lt;FONT size=3&gt;The Definitive Guide to NAP Logging&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;. This is a &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;U&gt;kick butt&lt;/U&gt;&lt;/I&gt;&lt;/B&gt; troubleshooting post! Very useful when trying to track down what is wrong between NAP Client and Server.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #e36c0a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent6; mso-themeshade: 191"&gt;&lt;FONT size=3&gt;Much thanks Pete Rivera (the author), &lt;/FONT&gt;&lt;A class="" href="http://blogs.technet.com/morello/" target=_blank mce_href="http://blogs.technet.com/morello/"&gt;&lt;FONT size=3&gt;John Morello&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&amp;nbsp;(the all-around cool guy) and Louis Hardy (for pointing it out to me)!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #e36c0a; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-themecolor: accent6; mso-themeshade: 191; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'"&gt;Cheers!&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt; LINE-HEIGHT: normal"&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #f79646; mso-themecolor: accent6; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;{&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN style="FONT-SIZE: 9pt; COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!" mce_href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!"&gt;&lt;SPAN style="mso-bidi-font-size: 11.0pt"&gt;Jeff Sigman&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #f79646; mso-themecolor: accent6; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;}{&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;Senior Program Manager &amp;amp; NAP Hero&lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #f79646; mso-themecolor: accent6; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;}{&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;Enterprise Security Group&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; COLOR: #f79646; mso-themecolor: accent6; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;}&lt;BR&gt;{&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;NAP&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt; &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://blogs.technet.com/nap" target=_blank mce_href="http://blogs.technet.com/nap"&gt;&lt;SPAN style="FONT-SIZE: 8pt; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;Blog&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;, &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://www.microsoft.com/technet/network/nap/napfaq.mspx" target=_blank mce_href="http://www.microsoft.com/technet/network/nap/napfaq.mspx"&gt;&lt;SPAN style="FONT-SIZE: 8pt; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;FAQ&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;, &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17" target=_blank mce_href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17"&gt;&lt;SPAN style="FONT-SIZE: 8pt; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;Forum&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;, &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://msdn2.microsoft.com/en-us/library/aa369712(VS.85).aspx" target=_blank mce_href="http://msdn2.microsoft.com/en-us/library/aa369712(VS.85).aspx"&gt;&lt;SPAN style="FONT-SIZE: 8pt; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;MSDN&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;, &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://microsoft.com/nap" target=_blank mce_href="http://microsoft.com/nap"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: #0033cc; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;Site&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 8pt; COLOR: #0070c0; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: Arial; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt; and &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-no-proof: yes"&gt;&lt;A href="http://blogs.technet.com/jeffsigman" target=_blank mce_href="http://blogs.technet.com/jeffsigman"&gt;&lt;SPAN style="FONT-SIZE: 8pt; mso-bidi-font-family: Arial; mso-bidi-font-size: 11.0pt"&gt;my bloÿg&lt;/SPAN&gt;&lt;/A&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="COLOR: #f79646; mso-themecolor: accent6"&gt;}&lt;/SPAN&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Trebuchet MS','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-bidi-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3045548" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item><item><title>NAP FAQ: Enforcing Security Updates (out-of-the-box)</title><link>http://blogs.technet.com/nap/archive/2008/04/24/nap-faq-enforcing-security-updates-out-of-the-box-2.aspx</link><pubDate>Fri, 25 Apr 2008 01:54:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3044553</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/nap/comments/3044553.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3044553</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Hey! My name is Mike Burk. I am a Program Manager on the Windows Security team. My team is responsible for the out-of-the-box NAP experience in Windows XP SP3, Vista and Server 2008. It is called the Windows Security Health Agent (client-side) and Validator (server-side). You will see it abbreviated as WSHA/WSHV in a lot of our documentation and on the web.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;We’ve been getting a lot of questions about how update enforcement using the WSHA/WSHV actually works. The first thing to keep in mind is that the WSHA/WSHV only enforces &lt;I style="mso-bidi-font-style: normal"&gt;&lt;U&gt;security updates&lt;/U&gt;&lt;/I&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;The easiest way to discuss update enforcement is to step through each part of the “Security Update Protection” section of the WSHV user interface. This is the dialog that appears within the Network Policy Server (NPS) console on Windows Server 2008:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;IMG style="WIDTH: 464px; HEIGHT: 338px" height=338 src="http://napteam.members.winisp.net/WSHV.jpg" width=464 align=middle mce_src="http://napteam.members.winisp.net/WSHV.jpg"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;1. “Restrict access…” checkbox&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;This activates the “Security Updates Protection” checks within the WSHA/WSHV (as well as the other controls in the section).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;2. Severity rating pull-down menu&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;This is the severity level assigned by the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/security/msrc/default.mspx" mce_href="http://www.microsoft.com/security/msrc/default.mspx"&gt;&lt;FONT size=3&gt;MSRC&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; for the update. If a client is missing security updates of the &lt;U&gt;specified&lt;/U&gt; severity or higher, it will be deemed non-compliant and given restricted network access. The default is “Important and above.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Note: “Low and above” and “All” actually mean the same thing. We are fixing this in future versions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;3. Number of hours since last scanned&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;This is the number of hours since the last time the client synched with its appropriate update server. This is only assessed when joining the network. If the time since last online scan exceeds this value, then the client will be deemed non-complaint. The default for this value is 22 hours, though it can be configured from 1 to 72 hours. Also, if automatic remediation is selected in the NAP policy, the WSHV will instruct the WSHA to do an online scan to ensure all new security updates are accounted for.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;4. Update sources&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;There are three sources for getting updates: &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/wsus/default.aspx" mce_href="http://technet.microsoft.com/en-us/wsus/default.aspx"&gt;&lt;FONT size=3&gt;Windows Server Update Services (WSUS)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;, &lt;/FONT&gt;&lt;A href="http://v4.windowsupdate.microsoft.com/en/default.asp" mce_href="http://v4.windowsupdate.microsoft.com/en/default.asp"&gt;&lt;FONT color=#0000ff size=3&gt;Windows Update (WU)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;, or &lt;/FONT&gt;&lt;A href="http://update.microsoft.com/" mce_href="http://update.microsoft.com/"&gt;&lt;FONT color=#0000ff size=3&gt;Microsoft Update (MU)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;. The WSHV is configurable to allow an administrator to accept updates from each of these on Vista SP1 and XP SP3. What this means is that a client reports its status with respect to the updates it knows about, and also where it gets its updates. If this is an acceptable source for updates, as configured in the WSHV, then the WSHV will accept that update status. Microsoft Update is accepted by default since it contains all updates. If an administrator wants to control which updates are approved for his network, then he should configure the clients for WSUS and check the WSUS box in the WSHV user interface.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Note: WSHA on Vista RTM (not SP1 or later) is only compatible with WSUS for update enforcement. This is the default on the WSHV for configuring policies for Vista clients.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Remediation&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;If the NAP policy is set for "Automatic Remediation", then the WSHA will automatically download and install the missing updates. The WSHA on the client will query the Windows Update Agent on the client for updates upon boot or upon joining the network, and every hour thereafter. If the Windows Update Agent reports that an update is missing, then the WSHA will generate a NAP message and the WSHV will enforce compliance per the NAP policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Note: The periodic scan interval is configurable via the ScanInterval value in the registry key HKLM\Software\Microsoft\MSSHA\.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;I hope this clarifies how the WSHA/WSHV helps to keep your clients updated with the latest security updates!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;FONT size=3&gt;Mike Burk&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS','sans-serif'"&gt;&lt;A href="mailto:miburk@microsoft.com" mce_href="mailto:miburk@microsoft.com"&gt;&lt;FONT color=#0000ff size=3&gt;miburk@microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3044553" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/NPS/default.aspx">NPS</category></item><item><title>Gotchas, FAQs, Best Practices, and Tips for Implementing NAP in Configuration Manager (SCCM + NAP)</title><link>http://blogs.technet.com/nap/archive/2008/04/21/gotchas-faqs-best-practices-and-tips-for-implementing-nap-in-configuration-manager-sccm-nap-2.aspx</link><pubDate>Mon, 21 Apr 2008 23:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3042048</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/3042048.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3042048</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;My &lt;A class="" href="http://blogs.technet.com/nap/archive/2008/04/21/the-low-down-on-configuration-manager-nap-remediation-sccm-nap-2.aspx" mce_href="http://blogs.technet.com/nap/archive/2008/04/21/the-low-down-on-configuration-manager-nap-remediation-sccm-nap-2.aspx"&gt;&lt;FONT color=#0000ff&gt;previous guest post&lt;/FONT&gt;&lt;/A&gt; walked you through what was happening in the background with Configuration Manager NAP when a noncompliant computer connected to the network, and was restricted and remediated for a software update. This post follows up with some gotchas, FAQs, best practices, and tips for implementing NAP in Configuration Manager.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;I’m Carol Bailey, Senior Technical Writer for System Center Configuration Manager 2007 (formally SMS 2003), and I’m involved with many of the security-related features in Configuration Manager – including Internet-based client management, desired configuration management, ….. and Network Access Protection (NAP).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Gotchas:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;The prereqs. Of particular note for NAP, you must extend the Active Directory schema for Configuration Manager 2007: &lt;A href="http://technet.microsoft.com/en-us/library/bb681008.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb681008.aspx"&gt;&lt;FONT color=#0000ff&gt;Prerequisites for Network Access Protection&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Remediation in Configuration Manager does not include installing the Configuration Manager client (SCCM SHA) if it is not installed. If the policies on the NAP health policy server (NPS) include the Configuration Manager System Health Validator (SCCM SHV) and do not exclude computers that do not have the Configuration Manager client (SCCM SHA) installed, the computer will be deemed noncompliant and cannot be automatically remediated. In the Network Access Protection dialog box, you’ll see “SHA Not Present” with ID 79745. In this scenario, either configure exemption policies for computers that should not have the Configuration Manager client (SCCM SHA) installed, or provide a method of manually installing the client that works when the computer is on the restricted network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Until you enable the Network Access Protection client agent (aka NAPAgent; not enabled by default), the Policies node under the Network Access Protection node in the Configuration Manager console does not display, and neither does the NAP Evaluation tab in the software update, or the NAP option in the &lt;SPAN style="COLOR: black"&gt;Deploy Software Update Wizard&lt;/SPAN&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;If the NAP health policy server (NPS) allows full network access (“reporting mode”), Configuration Manager will not remediate on the unrestricted network. This facility is supported through standard Configuration Manager software updates. Additionally, if the NAP health policy server (NPS) is enforcing health policies, Configuration Manager will always remediate noncompliant computers, even if the option on the NAP health policy server &lt;B style="mso-bidi-font-weight: normal"&gt;Enable auto-remediation of client computers&lt;/B&gt; is not enabled. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/bb633268.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb633268.aspx"&gt;&lt;FONT color=#0000ff&gt;About Network Access Protection Remediation&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/bb681013.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb681013.aspx"&gt;&lt;FONT color=#0000ff&gt;Configuring Network Policies for Configuration Manager Network Access Protection.&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Unlike software update deployments, NAP policies in Configuration Manager are not targeted to collections – they are automatically targeted to all clients assigned to the site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Like other objects that are created in a Configuration Manager hierarchy, NAP policies flow down the hierarchy. However, unlike other objects, child sites cannot create their own NAP policies. For more information: &lt;A href="http://technet.microsoft.com/en-us/library/bb632505.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632505.aspx"&gt;&lt;FONT color=#0000ff&gt;About Network Access Protection in Configuration Manager Hierarchies&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l2 level1 lfo1"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Do not expect NAP in Configuration Manager to offer real-time enforcement. &lt;SPAN style="COLOR: black"&gt;While NAP helps keep computers compliant over the long run, enforcement delays might be several hours or more due to a variety of factors, including the settings of various configuration parameters. However, you can minimize these delays if you have a zero-day exploit situation (see &lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb694188.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb694188.aspx"&gt;&lt;FONT color=#0000ff&gt;How to Configure a Configuration Manager NAP Policy for a Zero-Day Exploit in Network Access Protection&lt;/FONT&gt;&lt;/A&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;FAQs:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Q: Does NAP in Configuration Manager require you to be running Windows Server 2008 on the servers?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: No, only the server with the Network Policy Server (NPS) role and configured as a NAP health policy server must be running Windows Server 2008. This is the server onto which you install the Configuration Manager System Health Validator (SCCM SHV) point.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: I’m using DHCP and VPN enforcement. Which servers need to be added to the Remediation Server Group on the Network Policy Server (NPS)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: The Configuration Manager remediation servers (management point, software update point, and distribution points) are automatically added to the Remediation Server Group – there is no need to manually add them. However, you will still need to add servers that provide infrastructure services, such as DNS servers and domain controllers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;More information: &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb681061.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb681061.aspx"&gt;&lt;FONT color=#0000ff&gt;Configuring Remediation Server Groups for Configuration Manager Network Access Protection&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: Why is the Configure button not available for the Configuration Manager System Health Validator (SCCM SHV) on the Network Policy Server (NPS)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: With the exception of mapping error conditions to compliant or noncompliant, configuration for the Configuration Manager System Health Validator (SCCM SHV) is done through the Configuration Manager console, by configuring the properties of the System Health Validator Point Component Properties. To help you understand these configuration options and the consequences of changing the default values, use the F1 help: &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693842.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb693842.aspx"&gt;&lt;FONT color=#0000ff&gt;System Health Validator Point Component Properties.&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: How do you configure NAP for a cross-forest scenario?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: See &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb694305.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb694305.aspx"&gt;&lt;FONT color=#0000ff&gt;About Network Access Protection and Multiple Active Directory Forests&lt;/FONT&gt;&lt;/A&gt;. As with all Configuration Manager site system servers, the Configuration Manager System Health Validator (SCCM SHV) must reside on a member server; it is not supported in a workgroup environment. However, it can be installed in a different forest than the site server’s forest.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: Do you have a step-by-step or checklist for configuring NAP in Configuration Manager?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: See &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680600.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680600.aspx"&gt;&lt;FONT color=#0000ff&gt;Administrator Checklist: Configure Network Access Protection for Configuration Manager&lt;/FONT&gt;&lt;/A&gt; and you might also find the following useful: &lt;A href="http://technet.microsoft.com/en-us/library/bb632421.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632421.aspx"&gt;&lt;FONT color=#0000ff&gt;Example Scenarios for Implementing Network Access Protection in Configuration Manager&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT face="Times New Roman" size=3&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: Why is my Configuration Manager client going into restriction when it has all the software updates that are configured for NAP?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: The Configuration Manager System Health Validator (SCCM SHV) makes a number of checks for compliance. A client might be noncompliant because it hasn’t downloaded the latest policies; its statement of health has expired; or it’s from an unknown site. For more information, see &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680720.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680720.aspx"&gt;&lt;FONT color=#0000ff&gt;About Compliance for Network Access Protection in Configuration Manager&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: I’ve heard that the Configuration Manager client might use a cached statement of health (SoH) rather than performing a fresh evaluation when it is asked for its health state – what’s going on here?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: There are several scenarios under which the client can use a cached statement of health (SoH). &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;Using a cached statement of health results in faster connections, but the NAP evaluation information might be out of date. For more information, &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;see &lt;A href="http://technet.microsoft.com/en-us/library/bb680833.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680833.aspx"&gt;&lt;FONT color=#0000ff&gt;About the Statement of Health (SoH) in Network Access Protection&lt;/FONT&gt;&lt;/A&gt; and&lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'; mso-ansi-language: EN"&gt; &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693935.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb693935.aspx"&gt;&lt;FONT color=#0000ff&gt;NAP Evaluation Conditions for Configuration Manager Clients&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: I’m testing NAP in Configuration Manager, and clients have full network access when they should be restricted. How can I troubleshoot this?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: There are multiple possible reasons for this scenario. Check &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680328.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680328.aspx"&gt;&lt;FONT color=#0000ff&gt;Computers Have Full Network Access When They Should Not Using Network Access Protection&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: I’m testing NAP in Configuration Manager, and clients are failing to remediate. How can I troubleshoot this?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: There are multiple possible reasons for this scenario. Check &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb632575.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632575.aspx"&gt;&lt;FONT color=#0000ff&gt;Client Fails to Successfully Remediate with Network Access Protection&lt;/FONT&gt;&lt;/A&gt;.&lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; COLOR: #ff6600; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Q: What log files are specific to Configuration Manager NAP?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;A: See &lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb632606.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632606.aspx"&gt;&lt;FONT color=#0000ff&gt;Log Files for Network Access Protection.&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;Best Practices:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 6pt 0in 0pt"&gt;&lt;SPAN lang=EN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-ansi-language: EN"&gt;For a complete list, see &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb932197.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb932197.aspx"&gt;&lt;FONT color=#0000ff&gt;Best Practices for Network Access Protection&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/bb694218.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb694218.aspx"&gt;&lt;FONT color=#0000ff&gt;Network Access Protection Security Best Practices&lt;/FONT&gt;&lt;/A&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 6pt 0in 0pt 0.25in; VERTICAL-ALIGN: top; TEXT-INDENT: -0.25in; tab-stops: list .25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;Confirm the successful installation of software updates on the unrestricted network using the software updates feature in Configuration Manager before configuring software updates for Network Access Protection (NAP).&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 6pt 0in 0pt 0.25in; VERTICAL-ALIGN: top; TEXT-INDENT: -0.25in; tab-stops: list .25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;Test average remediation times to set expectations&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 6pt 0in 0pt 0.25in; VERTICAL-ALIGN: top; TEXT-INDENT: -0.25in; tab-stops: list .25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;Educate users in advance to encourage them to install software updates before the NAP effective date.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 6pt 0in 0pt 0.25in; VERTICAL-ALIGN: top; TEXT-INDENT: -0.25in; tab-stops: list .25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;Do not install the WSUS system health agent on a computer that has the Configuration Manager client installed with the Network Access Protection client agent enabled.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Tips:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; COLOR: black; tab-stops: list .5in; mso-list: l1 level1 lfo3"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: windowtext; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Factor in early the collaboration that will needed between different groups and define the processes that will be used for a smooth transfer of responsibilities. Probably more than any other feature in Configuration Manager, NAP requires careful coordination with multiple teams. For a list of the different roles and processes that might be involved, see &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-weight: bold"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680748.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680748.aspx"&gt;&lt;FONT color=#0000ff&gt;Determine Administrator Roles and Processes for Network Access Protection&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l1 level1 lfo3"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Be prepared for the political consequences of restricting network access. In the heat of the moment it can be difficult to justify this preventative action when it impacts short term business continuity. For examples of how implementing Network Access Protection can affect users in their working environment, see &lt;A href="http://technet.microsoft.com/en-us/library/bb632421.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632421.aspx"&gt;&lt;FONT color=#0000ff&gt;Example Scenarios for Implementing Network Access Protection in Configuration Manager.&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l1 level1 lfo3"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Installing software updates can result in requiring a reboot, which is enforced when remediating on the restricted network. If this is unacceptable in your working environment, consider enforcing compliance on the full network for a limited time (deferred enforcement) – in this scenario the reboot is requested but not enforced until the grace period ends. For more information, see the section “Remediation Restarts and Retries” in &lt;A href="http://technet.microsoft.com/en-us/library/bb633268.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb633268.aspx"&gt;&lt;FONT color=#0000ff&gt;About Network Access Protection Remediation&lt;/FONT&gt;&lt;/A&gt; and the flowchart &lt;A href="http://technet.microsoft.com/en-us/library/bb632734.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb632734.aspx"&gt;&lt;FONT color=#0000ff&gt;Enforced Compliance with Network Access Protection in Configuration Manager&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class=MsoNormal style="MARGIN: 6pt 0in 0pt; tab-stops: list .5in; mso-list: l1 level1 lfo3"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Download and take the &lt;B style="mso-bidi-font-weight: normal"&gt;Network Access Protection quiz&lt;/B&gt; (available as one of the &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b9fb478a-ec98-47f2-b31e-57443a8ae88f&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=b9fb478a-ec98-47f2-b31e-57443a8ae88f&amp;amp;DisplayLang=en"&gt;&lt;FONT color=#0000ff&gt;Configuration Manager quizzes&lt;/FONT&gt;&lt;/A&gt;). It’s fun, informative, and checks that you’re in good shape to start implementing NAP in Configuration Manager. (Hint, many of the answers are in this post!).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;If you have any questions or feedback about the documentation for Configuration Manager NAP, you can e-mail me (&lt;A href="mailto:Carol.Bailey@Microsoft.com" mce_href="mailto:Carol.Bailey@Microsoft.com"&gt;&lt;FONT color=#0000ff&gt;Carol.Bailey@Microsoft.com&lt;/FONT&gt;&lt;/A&gt;) or my documentation team (&lt;A href="mailto:SMSDocs@Microsoft.com" mce_href="mailto:SMSDocs@Microsoft.com"&gt;&lt;FONT color=#0000ff&gt;SMSDocs@Microsoft.com&lt;/FONT&gt;&lt;/A&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;- Carol&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;I&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;This posting is provided AS IS with no warranties and confers no rights.&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3042048" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/SCCM/default.aspx">SCCM</category></item><item><title>Debugging NAP Errors (part 1)</title><link>http://blogs.technet.com/nap/archive/2008/02/19/debugging-nap-errors-part-1.aspx</link><pubDate>Wed, 20 Feb 2008 09:15:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2913949</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/nap/comments/2913949.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=2913949</wfw:commentRss><description>I’ve heard from a lot of folks who set up NAP in a lab who would love to have more information on all the great data that Network Policy Server (NPS) writes into the audit log. If you haven’t checked out our auditing, go to Server Manager and click on the main node for our role (Network Policy and Access Services). You will see all related NAP server events at the top of the right hand pane.

This will be part 1 in a series of “Debugging NAP” posts. I decided to kick it off by examining the messages / errors which come from our Windows Security Center NAP integration piece (included in XP SP3, Vista and Server 2008). It is called the Windows System Health Agent on the client (or WSHA) and the Windows System Health Validator on the server (or WSHV).

......(&lt;a href="http://blogs.technet.com/nap/archive/2008/02/19/debugging-nap-errors-part-1.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2913949" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category><category domain="http://blogs.technet.com/nap/archive/tags/NPS/default.aspx">NPS</category><category domain="http://blogs.technet.com/nap/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category></item><item><title>Looking to integrate your product with NAP?</title><link>http://blogs.technet.com/nap/archive/2008/02/14/looking-to-integrate-your-product-with-nap.aspx</link><pubDate>Fri, 15 Feb 2008 00:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2891777</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/2891777.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=2891777</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;FONT face=Calibri&gt;If so, you have probably already taken a look at our &lt;/FONT&gt;&lt;A href="http://msdn2.microsoft.com/en-us/library/aa369712.aspx" mce_href="http://msdn2.microsoft.com/en-us/library/aa369712.aspx"&gt;&lt;FONT face=Calibri&gt;MSDN area&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;, and probably even our sample code in the &lt;/FONT&gt;&lt;A href="http://msdn2.microsoft.com/en-us/windowsserver/bb980924.aspx" mce_href="http://msdn2.microsoft.com/en-us/windowsserver/bb980924.aspx"&gt;&lt;FONT face=Calibri&gt;Platform SDK&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; (…\&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Microsoft SDKs\Windows\v6.0\Samples\NetDs\NAP&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;). Well, I have some good news for you. We worked with an awesome guy by the name of &lt;A href="http://www.jwsecure.com/" mce_href="http://www.jwsecure.com/"&gt;Dan Griffin (JWSecure, Inc.)&lt;/A&gt; to build a better example of how to integrate with NAP.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;FONT face=Calibri&gt;Dan really &lt;/FONT&gt;&lt;A href="http://www.jwsecure.com/dan/2008/01/27/setting-up-the-nap-dhcp-lab-in-vmware/" mce_href="http://www.jwsecure.com/dan/2008/01/27/setting-up-the-nap-dhcp-lab-in-vmware/"&gt;&lt;FONT face=Calibri&gt;put something cool together&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; that is closer to a real world implementation. I welcome you to &lt;/FONT&gt;&lt;A href="http://go.microsoft.com/?linkid=8076327" mce_href="http://go.microsoft.com/?linkid=8076327"&gt;&lt;FONT face=Calibri&gt;sample&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; his nicely done &lt;/FONT&gt;&lt;A href="http://msdn2.microsoft.com/en-us/library/bb945062.aspx" mce_href="http://msdn2.microsoft.com/en-us/library/bb945062.aspx"&gt;&lt;FONT face=Calibri&gt;“Registry” System Health Agent (SHA) / System Health Validator (SHV)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;FONT face=Calibri&gt;We always welcome new &lt;A class="" href="http://www.microsoft.com/windowsserver2008/en/us/nap-partners.aspx" target=_blank mce_href="http://www.microsoft.com/windowsserver2008/en/us/nap-partners.aspx"&gt;NAP Partners&lt;/A&gt;! To find out how to become a NAP partner, drop us a &lt;/FONT&gt;&lt;A href="mailto:AskNAP@Microsoft.com?subject=Partner%20Program" mce_href="mailto:AskNAP@Microsoft.com?subject=Partner%20Program"&gt;&lt;FONT face=Calibri color=#0000ff&gt;line&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;FONT face=Calibri&gt;Cheers and NAP the WORLD!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt; LINE-HEIGHT: 115%"&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;A href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!" mce_href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Jeff Sigman&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Senior Program Manager&lt;BR&gt;Network Access Protection (NAP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;Please check out the NAP &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.technet.com/nap" mce_href="http://blogs.technet.com/nap"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;Blog&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;,&lt;/SPAN&gt;&lt;SPAN style="COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/network/nap/napfaq.mspx" mce_href="http://www.microsoft.com/technet/network/nap/napfaq.mspx"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;FAQ&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;,&lt;/SPAN&gt;&lt;SPAN style="COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17" mce_href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;Forum&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;,&lt;/SPAN&gt;&lt;SPAN style="COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://msdn2.microsoft.com/en-us/library/aa369712(VS.85).aspx" mce_href="http://msdn2.microsoft.com/en-us/library/aa369712(VS.85).aspx"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;MSDN&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #993366; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt; &lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;and &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://microsoft.com/nap" mce_href="http://microsoft.com/nap"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT face=Calibri size=3&gt;Site&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="COLOR: #1f497d; mso-fareast-font-family: 'Times New Roman'; mso-no-proof: yes; mso-fareast-theme-font: minor-fareast"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2891777" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/MSDN/default.aspx">MSDN</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item><item><title>XP NAP Rude Q and A</title><link>http://blogs.technet.com/nap/archive/2007/11/08/xp-nap-rude-q-and-a.aspx</link><pubDate>Fri, 09 Nov 2007 03:09:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2372137</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/nap/comments/2372137.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=2372137</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Since I spend nearly 1/3 of my week answering (or ignoring :-&amp;gt;) emails about the XP NAP Client, I thought it might be smart to give a very concise Q&amp;amp;A. Here goes:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class=MsoNormalTable style="BORDER-COLLAPSE: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in" cellSpacing=0 cellPadding=0 border=0 class="MsoNormalTable"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #215868; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="COLOR: white"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Questions&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: black 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #215868; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;SPAN style="COLOR: white"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Jeff’s (brilliant) Answers&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; mso-background-themecolor: accent5; mso-background-themetint: 51" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How do I get a copy of the BETA?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; mso-background-themecolor: accent5; mso-background-themetint: 51" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT face=Calibri size=3&gt;While it is on MSConnect, it is easier just to &lt;/FONT&gt;&lt;A href="mailto:jeff.sigman@microsoft.com?subject=XP%20NAP%20Beta%20Request" mce_href="mailto:jeff.sigman@microsoft.com?subject=XP%20NAP%20Beta%20Request"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;email me&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; to get a copy. I have US-English and Language Neutral versions from the April 2007 Beta release. Remember, this is a BETA and is not officially supported (i.e. no QFEs); see XP SP3 info below.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How will this actually release officially?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="COLOR: #003300"&gt;ONLY&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;SPAN style="COLOR: #003300"&gt; via &lt;A href="http://www.microsoft.com/windows/lifecycle/servicepacks.mspx" mce_href="http://www.microsoft.com/windows/lifecycle/servicepacks.mspx"&gt;Windows XP Service Pack 3&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;When will XP SP3 RTM?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://www.microsoft.com/windows/lifecycle/servicepacks.mspx" mce_href="http://www.microsoft.com/windows/lifecycle/servicepacks.mspx"&gt;&lt;FONT face=Calibri size=3&gt;1H CY2008&lt;/FONT&gt;&lt;/A&gt;&lt;B&gt;&lt;SPAN style="COLOR: red"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 4"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Will you please ship it outside of SP3?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I am sorry, no.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 5"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Why won’t you ship it outside of SP3?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In brief, the risk and cost to Windows was too high. NAP on XP changes 19+ core OS files (e.g. RAS, Wireless, EAP, etc) and we wouldn’t get the same testing coverage outside of SP3. Also, OOB releases are notoriously expensive to sustain. The code base would have to be maintained, orthogonally to XP itself, for 10+ years (i.e. MSRC’s). Wow.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 6"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How does the XP client compare with Vista?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT face=Calibri size=3&gt;Read my &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2007/06/21/nap-demystified-hopefully.aspx" mce_href="http://blogs.technet.com/nap/archive/2007/06/21/nap-demystified-hopefully.aspx"&gt;&lt;FONT face=Calibri size=3&gt;cool blog post&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 7"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Is it true that you brought all the great Vista Wired 802.1x features to XP?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Very true. Many customers have wanted Group Policy configuration for Wired 802.1x on XP. NAP gave us the needed business justification to pull it off in XP SP3.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 8"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Will the NAP Client release for any other Microsoft O/S’s?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Not at this time. No support for Windows Bob, 3.x, 9x, ME, 2000 and/or 2003.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 9"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;What about Linux, Mac, etc?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT face=Calibri size=3&gt;Oh yeah baby, we have &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2007/11/07/linux-nap-progress-scriptable-health-checker.aspx" mce_href="http://blogs.technet.com/nap/archive/2007/11/07/linux-nap-progress-scriptable-health-checker.aspx"&gt;&lt;FONT face=Calibri size=3&gt;Linux right now&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt;. Mac is nearly here. This is the &lt;/FONT&gt;&lt;A href="mailto:Calvin.Choe@microsoft.com?subject=The%20amazing%20ecosystem%20of%20NAP%20partners!" mce_href="mailto:Calvin.Choe@microsoft.com?subject=The%20amazing%20ecosystem%20of%20NAP%20partners!"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;dude&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; making it all happen.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 10"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;What administration tools are available in the XP Client?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Only the command-line (netsh.exe nap). The MMC was written in managed code and isn’t available on XP. Also, our assumption is that Group Policy / script is good enough for XP.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 11"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;What Active Directory schema changes are required, if any?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #daeef3; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;NAP, in general, does NOT require any AD schema updates. NAP fits in well with existing Server 2000/2003 deployments and simply requires a minimum of ONE Server 2008 computer (NAP Server / NPS).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT face=Calibri size=3&gt;However, in order to manage Vista (and XP SP3) Wired 802.1x settings a schema update may be required. If you are using Server 2008 AD, it is included. &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb727029.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb727029.aspx"&gt;&lt;FONT face=Calibri size=3&gt;Server 2003 AD requires an updated schema&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 12; mso-yfti-lastrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: black 1pt solid; WIDTH: 184.1pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=245&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Will XP NAP honor my GP configuration settings just like Vista NAP (i.e. NAPAgent, QECs, etc)?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: black 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; WIDTH: 294.7pt; PADDING-TOP: 0in; BORDER-BOTTOM: black 1pt solid; BACKGROUND-COLOR: transparent" vAlign=top width=393&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Yup!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Thanks for helping us NAP the WORLD!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;A href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!" mce_href="mailto:jeff.sigman@microsoft.com?subject=I%20LOVE%20NAP!"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Jeff Sigman&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; &lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Network Access Protection (NAP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;A href="http://blogs.technet.com/nap" mce_href="http://blogs.technet.com/nap"&gt;&lt;FONT face=Calibri size=3&gt;NAP Blog&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;A href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17" mce_href="http://forums.microsoft.com/TechNet/ShowForum.aspx?ForumID=576&amp;amp;SiteID=17"&gt;&lt;FONT face=Calibri size=3&gt;NAP Forum&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: #003300"&gt;&lt;A href="http://microsoft.com/nap" mce_href="http://microsoft.com/nap"&gt;&lt;FONT face=Calibri size=3&gt;NAP Site&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2372137" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Downlevel+OS+Support/default.aspx">Downlevel OS Support</category><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/Linux/default.aspx">Linux</category><category domain="http://blogs.technet.com/nap/archive/tags/FAQ/default.aspx">FAQ</category></item></channel></rss>