Security Basics mailing list archives

Re: Network Access Quarantine


From: "JM" <jm () mindless com>
Date: Thu, 22 Jan 2004 01:12:46 -0000

Depends on your OSs

I know that in W2003 (maybe 2000 too) you can set policies based on WBEM
properties of the device connecting.

You would need a number of GPOs.  You could have a GPO for OK'd machines,
and a GPO for non OK machines defined by using WBEM criteria, say like, must
have AV pattern file = 123 or above or if you don't have so and so
executable, you can not go to a certain OU, , or can connect / go to another
OU  but only to download the GPO that will give you the minimum spec.  Then
reboot and join the full function OU.

Sorry I can't be more specific, I am sure it can be done

Someone must have done it...somewhere....


---------------------------------------------------------------------------
Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any 
course! All of our class sizes are guaranteed to be 10 students or less. 
We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, 
and many other technical hands on courses. 
Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off 
any course!  
----------------------------------------------------------------------------


Current thread: