Re: VPN and quarantine

"Tina Bird" <[email protected]> Tue, 17 May 2005 16:47:10 -0700
Newsgroups gmane.comp.security.vpn
Message-ID <000901c55b3a$be919590$6401a8c0@lindesfarne>
> The problem is that unquarantine means tell your VPN gateway 
> that this or 
> this user has to be unquarantined .. so it requires that the 
> VPN Servers has 
> such mechanism or somthing close.

So you mean you're looking for a way to tell the VPN server to switch from
quarantine to full access?

At this point, that mechanism is presumably "whatever you use to change the
VPN configuration," because you're probably making changes to the access
control lists, right? 
If you can control the client side can you trigger a re-authentication
request or something like that?

How do you communicate this change of status through ISA?
 
> When you see the price of a solution such as CISCO NAC (and 
> the limited 
> service it provides) .. linux is really somthing good for companies.

The Trusted Network Connect subgroup of the TCG has just released the first
stage of their specification for endpoint integrity measurements and
actions. They don't have the APIs for communicating "quarantine decisions"
to the network infrastructure, but since TNC is the open standard effort in
this area, you probably want to check it out:

https://www.trustedcomputinggroup.org/downloads/TNC/