<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Network Access Protection (NAP) : design</title><link>http://blogs.technet.com/nap/archive/tags/design/default.aspx</link><description>Tags: design</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Network Access Protection Design Guide wins big at Society of Technical Communication (STC) awards!</title><link>http://blogs.technet.com/nap/archive/2009/02/04/network-access-protection-design-guide-wins-big-at-society-of-technical-communication-stc-awards.aspx</link><pubDate>Thu, 05 Feb 2009 02:47:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3197227</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3197227.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3197227</wfw:commentRss><description>&lt;P&gt;Greg Lindsay (writer) and Allyson Adley (editor) won the Online&amp;nbsp;Best of Show award for the &lt;A class="" href="http://technet.microsoft.com/en-us/library/dd125338.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125338.aspx"&gt;NAP Design Guide&lt;/A&gt; at&amp;nbsp;the Puget Sound Chapter of the Society for Technical Communication (STC) awards ceremony on January 29th.&lt;/P&gt;
&lt;P&gt;Congratulations Greg and Allyson for the fantastic technical&amp;nbsp;documentation&amp;nbsp;on NAP!&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAP Product Team&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3197227" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Resources/default.aspx">Resources</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>What is NAP traffic?</title><link>http://blogs.technet.com/nap/archive/2009/01/05/what-is-nap-traffic.aspx</link><pubDate>Tue, 06 Jan 2009 03:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3176809</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3176809.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3176809</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Here is a question posed by a member of the NAP community: &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;What new traffic will there be on the network when I deploy NAP?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;A NAP deployment can have the following additional sets of network traffic: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Traffic between the NAP client and the NAP enforcement point. The nature of this traffic depends on the NAP enforcement method.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 1in; tab-stops: list 1.0in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For IPsec enforcement, the NAP client communicates to the HRA using HTTP or HTTPS to indicate its identity and health state and to receive the system health evaluation results and the health certificate.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 1in; tab-stops: list 1.0in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For 802.1X enforcement, the NAP health evaluation is done over PEAP-TLV, resulting in a small amount of additional EAPOL traffic to send the health state and health evaluation results between the NAP client and the switch or wireless access point.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 1in; tab-stops: list 1.0in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For VPN enforcement, the NAP health evaluation is done over PEAP-TLV, resulting in small amount of additional PPP traffic to send the health state and health evaluation results between the NAP client and the VPN server.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 1in; tab-stops: list 1.0in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For DHCP enforcement, the NAP health evaluation is done using the same DHCP messages that are already being used for DHCP address allocation, resulting in larger payloads for some DCHP messages, but not additional messages.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 1in; tab-stops: list 1.0in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;For TS Gateway enforcement, the NAP health evaluation is done over the &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc239604.aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc239604.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Remote Procedure Call (RPC) over HTTP protocol&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Trebuchet MS" size=3&gt; that is used for connections to a TS Gateway server, resulting in a small amount of additional traffic to send the health state from the TS Gateway client and the TS Gateway server.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Traffic between the NAP enforcement point and the NAP health policy server. This is RADIUS traffic, consisting of one or multiple exchanges of RADIUS request and response messages. RADIUS traffic is UDP-based and adds minimal additional traffic on your network.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Traffic between the NAP enforcement point and other servers. The most obvious example is the traffic between the Health Registration Authority (HRA) and an Active Directory domain controller and a certification authority (CA) to authenticate the NAP client and obtain a health certificate.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Traffic between the NAP health policy server and health requirement servers. This traffic depends on the SHVs running on the NAP health policy server. The Windows Security Health Validator (WSHV) does not require communication with health requirement servers.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Trebuchet MS'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3176809" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>The no enforcement design for NAP</title><link>http://blogs.technet.com/nap/archive/2008/12/22/the-no-enforcement-design-for-nap.aspx</link><pubDate>Tue, 23 Dec 2008 02:20:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3172388</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/3172388.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3172388</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Although NAP can be used to enforce restricted access for noncompliant NAP clients and non-NAP-capable clients, NAP can also be used to provide you with information about the overall level of health compliance on your network and correct system health problems automatically without notifying the user or restricting their access. This latter configuration of a NAP deployment is known as the no enforcement design and consists of deploying NAP in reporting mode with autoremediation enabled.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The value of the no enforcement design was echoed to me by attendees at a recent McAfee regional security event, where I helped present an overview of NAP and McAfee Network Access Control 3.0 integration to IT staff and security architects (this is the same presentation that I gave at &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2008/10/23/standing-room-only-at-the-nap-and-unified-secure-access-presentation-at-mcafee-s-focus-08.aspx"&gt;&lt;FONT color=#800080 size=3&gt;McAfee’s FOCUS 08 event&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;). Some attendees said that they were very interested in the no enforcement design of NAP because they did not want their users notified of noncompliance (via the NAP notification message) and definitely did not want their users’ access to be restricted. They would rather determine and fix any system health issues in the background without disturbing their users. One of the benefits of the no enforcement design is that you do not have to set up a restricted network with remediation servers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;To configure a no enforcement design, use the Configure NAP wizard in the Network Policy Server snap-in for the appropriate NAP enforcement method. On the Define NAP Health Policy page, select the &lt;B style="mso-bidi-font-weight: normal"&gt;Enable Auto-Remediation of Client Computers&lt;/B&gt; check box and specify that NAP ineligible computers are allowed full access. After the Configure NAP wizard is complete, modify the network policy for noncompliant NAP clients by selecting &lt;B style="mso-bidi-font-weight: normal"&gt;Allow Full Network Access&lt;/B&gt; for the NAP Enforcement settings. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;Note&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For the 802.1X enforcement method, specify the same VLAN or ACL settings for both full access and restricted access on the Configure Virtual LANs (VLANs) page of the Configure NAP wizard.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;For more information, see the&amp;nbsp;&lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125345.aspx"&gt;&lt;FONT color=#800080 size=3&gt;No Enforcement Design&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; topic in Greg Lindsay’s excellent NAP Design Guide.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: 'Trebuchet MS'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Joe Davies&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3172388" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Deployments/default.aspx">Deployments</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>Microsoft Assessment and Planning Toolkit 3.2 Released</title><link>http://blogs.technet.com/nap/archive/2008/11/05/microsoft-assessment-and-planning-toolkit-3-2-released.aspx</link><pubDate>Wed, 05 Nov 2008 19:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3147992</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/nap/comments/3147992.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3147992</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The Microsoft Assessment and Planning (MAP) Toolkit is an integrated platform with tools and guidance that make it easier for you to assess your current IT infrastructure and determine the right Microsoft technologies for your&amp;nbsp;needs. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The MAP Toolkit 3.2&amp;nbsp;has been released and is available &lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?familyid=67240B76-3148-4E49-943D-4D9EA7F77730&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=67240B76-3148-4E49-943D-4D9EA7F77730&amp;amp;displaylang=en"&gt;here&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;. It&amp;nbsp;includes a new feature to perform readiness assessment for a deployment of NAP with &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/forefront/default.mspx" mce_href="http://www.microsoft.com/forefront/default.mspx"&gt;&lt;FONT color=#4c6d7e size=3&gt;Microsoft Forefront&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;Consume and enjoy!&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;FYI: &lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;In a previous blog post (located &lt;A class="" href="http://blogs.technet.com/nap/archive/2008/10/16/microsoft-assessment-and-planning-toolkit-3-2-beta-released.aspx" mce_href="http://blogs.technet.com/nap/archive/2008/10/16/microsoft-assessment-and-planning-toolkit-3-2-beta-released.aspx"&gt;here&lt;/A&gt;), I described the beta of the MAP Toolkit 3.2.&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3147992" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Forefront/default.aspx">Forefront</category><category domain="http://blogs.technet.com/nap/archive/tags/Resources/default.aspx">Resources</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>Microsoft Assessment and Planning Toolkit 3.2 Beta Released</title><link>http://blogs.technet.com/nap/archive/2008/10/16/microsoft-assessment-and-planning-toolkit-3-2-beta-released.aspx</link><pubDate>Thu, 16 Oct 2008 19:13:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3137359</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3137359.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3137359</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The Microsoft Assessment and Planning (MAP) Toolkit is an integrated platform with tools and guidance that make it easier for you to assess your current IT infrastructure and determine the right Microsoft technologies for your IT needs.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The existing MAP Toolkit 3.1 is located &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=67240b76-3148-4e49-943d-4d9ea7f77730&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=67240b76-3148-4e49-943d-4d9ea7f77730&amp;amp;DisplayLang=en"&gt;&lt;FONT size=3&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; and includes desktop Windows Security Center assessment, which is instrumental in analyzing your network prior to a NAP deployment. Click &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2008/06/30/nap-and-the-microsoft-assessment-and-planning-toolkit-3-1.aspx" mce_href="http://blogs.technet.com/nap/archive/2008/06/30/nap-and-the-microsoft-assessment-and-planning-toolkit-3-1.aspx"&gt;&lt;FONT size=3&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; for the NAP blog post that describes this in detail.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The MAP Toolkit 3.2 beta includes a new feature to perform readiness assessment for a deployment of NAP with &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/forefront/default.mspx" mce_href="http://www.microsoft.com/forefront/default.mspx"&gt;&lt;FONT size=3&gt;Microsoft Forefront&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Click &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2008/06/30/nap-and-the-microsoft-assessment-and-planning-toolkit-3-1.aspx" mce_href="http://blogs.technet.com/nap/archive/2008/06/30/nap-and-the-microsoft-assessment-and-planning-toolkit-3-1.aspx"&gt;&lt;FONT size=3&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; to get on the MAP 3.2 beta and try it out!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3137359" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/Deployments/default.aspx">Deployments</category><category domain="http://blogs.technet.com/nap/archive/tags/Forefront/default.aspx">Forefront</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>Network Access Protection Design Guide is live!</title><link>http://blogs.technet.com/nap/archive/2008/10/09/network-access-protection-design-guide-is-live.aspx</link><pubDate>Thu, 09 Oct 2008 23:27:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3134719</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/nap/comments/3134719.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3134719</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Hey NAP friends!&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;The &lt;/SPAN&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=130154" mce_href="http://go.microsoft.com/fwlink/?LinkId=130154"&gt;Network Access Protection&lt;SPAN lang=EN-US style="mso-ansi-language: EN-US"&gt; Design Guide&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;, authored by our very own technical writer and &lt;A href="http://social.technet.microsoft.com/forums/en-US/winserverNAP/threads/" mce_href="http://social.technet.microsoft.com/forums/en-US/winserverNAP/threads/"&gt;NAP Forum&lt;/A&gt; hero Greg Lindsay, is now live! &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;A href="http://go.microsoft.com/fwlink/?LinkId=130154" mce_href="http://go.microsoft.com/fwlink/?LinkId=130154"&gt;&lt;FONT size=3&gt;http://go.microsoft.com/fwlink/?LinkId=130154&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The NAP Design Guide explains the advantages, disadvantages, requirements, recommendations, and design considerations for deploying NAP for the IPsec, 802.1X, VPN, and DHCP enforcement methods. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The NAP Design Guide contains the following sections:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125349.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125349.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Understanding the NAP Design Process&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125341.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125341.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Identifying Your NAP Deployment Goals&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125346.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125346.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Mapping Your Deployment Goals to a NAP Design&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125348.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125348.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Evaluating NAP Design Examples&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125364.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125364.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning a NAP Deployment Strategy&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125325.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125325.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning the Placement of a NAP Health Policy Server&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125384.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125384.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning the Placement of a NAP Enforcement Server&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125388.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125388.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning the Placement of a NAP CA Server&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125378.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125378.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning the Placement of a NAP Remediation Server&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125316.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125316.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Planning the Placement of a NAP Health Requirement Server&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125353.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125353.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;NAP Capacity Planning&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125377.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125377.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Additional NAP Resources&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125301.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125301.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Appendix A: NAP Requirements&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125317.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125317.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Appendix B: Reviewing Key NAP Concepts&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125331.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125331.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Appendix C: Documenting Your NAP Design&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd125393.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd125393.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Appendix D: NAP-NAC Design&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;You can provide feedback on individual pages of the NAP Design Guide by clicking “Click to Rate and Give Feedback” just above the content pane.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Huge&amp;nbsp;thanks to Greg for his authoring efforts over the last year and to many NAP product team reviewers for helping to ensure that the content is technically accurate and complete.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Enjoy!&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3134719" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/IPsec/default.aspx">IPsec</category><category domain="http://blogs.technet.com/nap/archive/tags/802.1X/default.aspx">802.1X</category><category domain="http://blogs.technet.com/nap/archive/tags/VPN/default.aspx">VPN</category><category domain="http://blogs.technet.com/nap/archive/tags/DHCP/default.aspx">DHCP</category><category domain="http://blogs.technet.com/nap/archive/tags/Resources/default.aspx">Resources</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item><item><title>General NAP policy design considerations</title><link>http://blogs.technet.com/nap/archive/2008/09/16/general-nap-policy-design-considerations.aspx</link><pubDate>Wed, 17 Sep 2008 00:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3124935</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3124935.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3124935</wfw:commentRss><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Greetings, citizens of NAPville!&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Here is some information to take into account when designing your policies for NAP, adapted from a section in the upcoming &lt;I style="mso-bidi-font-style: normal"&gt;Network Access Protection Design Guide&lt;/I&gt; and written by our own Greg Lindsay:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 1pt; BORDER-BOTTOM: medium none; mso-border-top-alt: solid windowtext .5pt; mso-element: para-border-div"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-padding-alt: 1.0pt 0in 0in 0in; mso-border-top-alt: solid windowtext .5pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Consider the following rules when configuring connection request policies and network policies in the Network Policy Server (NPS) snap-in:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;A RADIUS client access request can only match one connection request policy and one network policy. When the access request successfully matches a policy, no other policies are used to evaluate the access request.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Policies are evaluated based on processing order and source:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.5in; tab-stops: list -1.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;RADIUS access requests from Windows-based RADIUS clients can contain the &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/cc209935.aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc209935.aspx"&gt;&lt;FONT face="Trebuchet MS" size=3&gt;MS-Network-Access-Server-Type&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face="Trebuchet MS" size=3&gt; RADIUS attribute, which specifies the source of the request. For example, access requests from a Windows Server 2008-based VPN server specify the source of Remote Access Server (VPN-Dial up).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.5in; tab-stops: list -1.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;Access requests are evaluated against policies with the same source.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.5in; tab-stops: list -1.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;If the source is not specified in the access request, the NPS service will evaluate it against the policies with a source of &lt;B style="mso-bidi-font-weight: normal"&gt;Unspecified&lt;/B&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.5in; tab-stops: list -1.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;If there are no policies with the same source as the access request, the NPS service will evaluate it against the policies with a source of &lt;B style="mso-bidi-font-weight: normal"&gt;Unspecified&lt;/B&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=Bullet style="MARGIN: auto 0in auto 0.5in; tab-stops: list -1.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face="Trebuchet MS" size=3&gt;If there are multiple policies with the same source as the access request, the NPS service will evaluate it against the policy with the same source that is highest in the processing order (that is, the policy with the lowest Processing Order number). If the access request does not match the conditions of the policy, the NPS service evaluates the policy next highest in the processing order with the same source. This continues until the access request matches a policy or all policies with the same source have been evaluated.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;The following table lists the NAP enforcement methods and their corresponding source. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class=MsoNormalTable style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none; BORDER-COLLAPSE: collapse; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 160; mso-border-alt: solid windowtext .5pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext" cellSpacing=0 cellPadding=0 border=1 class="MsoNormalTable"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #d9d9d9; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;NAP enforcement method&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #d9d9d9; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Source&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;IPsec&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Health Registration Authority&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;802.1X&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Unspecified&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;VPN&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Remote Access Server (VPN-Dial up)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 4"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;DHCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;DHCP Server&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 5; mso-yfti-lastrow: yes"&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 2.45in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=235&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Terminal Server (TS) Gateway&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class="" style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #d4d0c8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #d4d0c8; WIDTH: 207pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" vAlign=top width=276&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Terminal Server Gateway&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-padding-alt: 0in 0in 1.0pt 0in; mso-border-bottom-alt: solid windowtext .75pt"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;You can select a source from &lt;B style="mso-bidi-font-weight: normal"&gt;Type of network access server&lt;/B&gt; on the &lt;B style="mso-bidi-font-weight: normal"&gt;Overview&lt;/B&gt; tab in the properties of the policy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Thanks Greg!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Joe Davies&lt;BR&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3124935" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/configuration/default.aspx">configuration</category><category domain="http://blogs.technet.com/nap/archive/tags/design/default.aspx">design</category></item></channel></rss>