Non-NAP Capable computers receiving full network access using DHCP enforcementI have it set up so non-nap capable computers have restricted access yet they are receiving full access to the network.  Once connected if I do a Repair or a Ipconfig/release then a renew then they revert to restricted access.  If I unplug and then plug in the network cable or reboot they once again receive full access until I again do a Repair or ipconfig/release then renew.  Everything else is working as I want. © 2009 Microsoft Corporation. All rights reserved.Tue, 27 Oct 2009 03:21:29 Za79cc00e-f425-4662-af7f-931fe32fb6a7http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#a79cc00e-f425-4662-af7f-931fe32fb6a7http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#a79cc00e-f425-4662-af7f-931fe32fb6a7Lefty777http://social.technet.microsoft.com/Profile/en-US/?user=Lefty777Non-NAP Capable computers receiving full network access using DHCP enforcementI have it set up so non-nap capable computers have restricted access yet they are receiving full access to the network.  Once connected if I do a Repair or a Ipconfig/release then a renew then they revert to restricted access.  If I unplug and then plug in the network cable or reboot they once again receive full access until I again do a Repair or ipconfig/release then renew.  Everything else is working as I want. Tue, 23 Jun 2009 16:28:42 Z2009-06-23T16:28:42Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#3b4f34e6-f85a-477f-9537-4c75f6f750e5http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#3b4f34e6-f85a-477f-9537-4c75f6f750e5Lefty777http://social.technet.microsoft.com/Profile/en-US/?user=Lefty777Non-NAP Capable computers receiving full network access using DHCP enforcementI should add a little more information.  If I check the DHCP server it tells me NAP is ON for this machine.  If I check the NAP logs in tells me this computer is quarantined yet it still has full network access until the Repair or release/renew is done then it acts as it should, with restricted access.Wed, 24 Jun 2009 11:06:23 Z2009-06-24T11:06:23Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#f3dea0b9-98c3-4a08-a42b-f319e6a49f3ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#f3dea0b9-98c3-4a08-a42b-f319e6a49f3eGreg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayNon-NAP Capable computers receiving full network access using DHCP enforcementHi,<br/><br/>Is the client running XP SP3?<br/><br/>-GregWed, 24 Jun 2009 20:16:28 Z2009-06-24T20:16:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#6e1713cf-8893-4ebf-997f-af7a943f20fbhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#6e1713cf-8893-4ebf-997f-af7a943f20fbLefty777http://social.technet.microsoft.com/Profile/en-US/?user=Lefty777Non-NAP Capable computers receiving full network access using DHCP enforcementYes it is.Thu, 25 Jun 2009 01:04:27 Z2009-06-25T01:04:27Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#edd34f52-661d-4b7a-a9bf-382110762e49http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#edd34f52-661d-4b7a-a9bf-382110762e49Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayNon-NAP Capable computers receiving full network access using DHCP enforcement<p>Hi,<br/><br/>The reason I ask is I've seen this issue before only with XP SP3 and DHCP enforcement - usually the first time a non-NAP capable client joins the network. You can also see it 50% of the time if you manually release and renew the IP address. It never happens if the client renews its DHCP lease normally, or if NAP agent is running.<br/><br/>You can confirm this is the same problem by reviewing the NPS event log. When a DHCP client requests network access in a NAP DHCP scenario, there must be an access request recorded. NPS will then accept/deny/restrict the client based on the contents of the request (health, computer group, etc). Even if the client is non-NAP capable, there should be a record of the DHCP request.<br/><br/>However, sometimes when a non-NAP capable XP SP3 client sends the first request this isn't processed at all by NPS. The result is that the DHCP server simply provides a typical IP address configuration. You can confirm this by looking at the NPS event log to see that no access request was logged.<br/><br/>We are already looking at this issue, but if this is indeed your problem then additional reports help. Can you confirm that no NPS events are recorded when this occurs? View NPS events at Custom Views\Server Roles\Network Policy and Access Services.<br/><br/>Thanks,<br/>-Greg</p>Thu, 25 Jun 2009 01:21:21 Z2009-06-25T01:21:21Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#31ee3a93-b581-48f5-b839-182b8a572ef0http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#31ee3a93-b581-48f5-b839-182b8a572ef0Lefty777http://social.technet.microsoft.com/Profile/en-US/?user=Lefty777Non-NAP Capable computers receiving full network access using DHCP enforcement<p>I am pasting in the 4 log entries I get for this computer, as I get with any computer, they all show as Non Nap-capaple at first and then change to either Compliant or Non-compliant depending on their health state, they all change to a Result of Full Access as they should.  This one shows as quarantined all the way thru despite getting full access.  It looks to me as it should, but will let you examine it.  You are right about the 50% also.  I can do a release/renew, one time it restricts it, the next time it allows it, and back and forth it goes, even though the logs are the same each time.  I also am having problems with computers being put in an Exception group not being processed as exceptions and being restricted instead of being allowed access but I figure I will tackle this problem first before moving on, maybe there is a common fix for both.<br/><br/>Here are the log entries.  I should add, I have pasted the log entries in the order they get logged, so the first one you read is the first log entry posted.<br/><br/>Log Name:      Security<br/>Source:        Microsoft-Windows-Security-Auditing<br/>Date:          6/25/2009 7:47:43 AM<br/>Event ID:      6272<br/>Task Category: Network Policy Server<br/>Level:         Information<br/>Keywords:      Audit Success<br/>User:          N/A<br/>Computer:      LEG-FS1.gnb.ca<br/>Description:<br/>Network Policy Server granted access to a user.</p> <p>User:<br/> Security ID:   NULL SID<br/> Account Name:   -<br/> Account Domain:   -<br/> Fully Qualified Account Name: -</p> <p>Client Machine:<br/> Security ID:   NULL SID<br/> Account Name:   leg-co489486<br/> Fully Qualified Account Name: -<br/> OS-Version:   -<br/> Called Station Identifier:  142.139.19.0<br/> Calling Station Identifier:  001422EDA6CC</p> <p>NAS:<br/> NAS IPv4 Address:  142.139.19.161<br/> NAS IPv6 Address:  -<br/> NAS Identifier:   LEG-FS1<br/> NAS Port-Type:   Ethernet <br/> NAS Port:   -</p> <p>RADIUS Client:<br/> Client Friendly Name:  -<br/> Client IP Address:   -</p> <p>Authentication Details:<br/> Proxy Policy Name:  NAP DHCP<br/> Network Policy Name:  NAP DHCP Non NAP-Capable<br/> Authentication Provider:  Windows <br/> Authentication Server:  LEG-FS1.gnb.ca<br/> Authentication Type:  Unauthenticated <br/> EAP Type:   -<br/> Account Session Identifier:  323732393137363738</p> <p>Quarantine Information:<br/> Result:    Quarantined <br/> Session Identifier:   -</p> <p>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br/>    &lt;EventID&gt;6272&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;0&lt;/Level&gt;<br/>    &lt;Task&gt;12552&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-25T10:47:43.855Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;149022&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;712&quot; ThreadID=&quot;6220&quot; /&gt;<br/>    &lt;Channel&gt;Security&lt;/Channel&gt;<br/>    &lt;Computer&gt;LEG-FS1.gnb.ca&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;leg-co489486&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;MachineInventory&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CalledStationID&quot;&gt;142.139.19.0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CallingStationID&quot;&gt;001422EDA6CC&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;142.139.19.161&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;LEG-FS1&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPortType&quot;&gt;Ethernet &lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP DHCP&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP DHCP Non NAP-Capable&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;LEG-FS1.gnb.ca&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br/>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;323732393137363738&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Quarantined &lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSessionIdentifier&quot;&gt;-&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</p> <p>Log Name:      Security<br/>Source:        Microsoft-Windows-Security-Auditing<br/>Date:          6/25/2009 7:47:43 AM<br/>Event ID:      6272<br/>Task Category: Network Policy Server<br/>Level:         Information<br/>Keywords:      Audit Success<br/>User:          N/A<br/>Computer:      LEG-FS1.gnb.ca<br/>Description:<br/>Network Policy Server granted access to a user.</p> <p>User:<br/> Security ID:   NULL SID<br/> Account Name:   -<br/> Account Domain:   -<br/> Fully Qualified Account Name: -</p> <p>Client Machine:<br/> Security ID:   NULL SID<br/> Account Name:   leg-co489486<br/> Fully Qualified Account Name: -<br/> OS-Version:   -<br/> Called Station Identifier:  142.139.19.0<br/> Calling Station Identifier:  001422EDA6CC</p> <p>NAS:<br/> NAS IPv4 Address:  142.139.19.161<br/> NAS IPv6 Address:  -<br/> NAS Identifier:   LEG-FS1<br/> NAS Port-Type:   Ethernet <br/> NAS Port:   -</p> <p>RADIUS Client:<br/> Client Friendly Name:  -<br/> Client IP Address:   -</p> <p>Authentication Details:<br/> Proxy Policy Name:  NAP DHCP<br/> Network Policy Name:  NAP DHCP Non NAP-Capable<br/> Authentication Provider:  Windows <br/> Authentication Server:  LEG-FS1.gnb.ca<br/> Authentication Type:  Unauthenticated <br/> EAP Type:   -<br/> Account Session Identifier:  323732393137363738</p> <p>Quarantine Information:<br/> Result:    Quarantined <br/> Session Identifier:   -</p> <p>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br/>    &lt;EventID&gt;6272&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;0&lt;/Level&gt;<br/>    &lt;Task&gt;12552&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-25T10:47:43.855Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;149023&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;712&quot; ThreadID=&quot;6220&quot; /&gt;<br/>    &lt;Channel&gt;Security&lt;/Channel&gt;<br/>    &lt;Computer&gt;LEG-FS1.gnb.ca&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;leg-co489486&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;MachineInventory&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CalledStationID&quot;&gt;142.139.19.0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CallingStationID&quot;&gt;001422EDA6CC&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;142.139.19.161&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;LEG-FS1&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPortType&quot;&gt;Ethernet &lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP DHCP&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP DHCP Non NAP-Capable&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;LEG-FS1.gnb.ca&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br/>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;323732393137363738&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Quarantined &lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSessionIdentifier&quot;&gt;-&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</p> <p>Log Name:      Security<br/>Source:        Microsoft-Windows-Security-Auditing<br/>Date:          6/25/2009 7:47:43 AM<br/>Event ID:      6276<br/>Task Category: Network Policy Server<br/>Level:         Information<br/>Keywords:      Audit Success<br/>User:          N/A<br/>Computer:      LEG-FS1.gnb.ca<br/>Description:<br/>Network Policy Server quarantined a user.</p> <p>Contact the Network Policy Server administrator for more information.</p> <p>User:<br/> Security ID:   NULL SID<br/> Account Name:   -<br/> Account Domain:   -<br/> Fully Qualified Account Name: -</p> <p>Client Machine:<br/> Security ID:   NULL SID<br/> Account Name:   leg-co489486<br/> Fully Qualified Account Name: -<br/> OS-Version:   -<br/> Called Station Identifier:  142.139.19.0<br/> Calling Station Identifier:  001422EDA6CC</p> <p>NAS:<br/> NAS IPv4 Address:  142.139.19.161<br/> NAS IPv6 Address:  -<br/> NAS Identifier:   LEG-FS1<br/> NAS Port-Type:   Ethernet <br/> NAS Port:   -</p> <p>RADIUS Client:<br/> Client Friendly Name:  -<br/> Client IP Address:   -</p> <p>Authentication Details:<br/> Proxy Policy Name:  NAP DHCP<br/> Network Policy Name:  NAP DHCP Non NAP-Capable<br/> Authentication Provider:  Windows <br/> Authentication Server:  LEG-FS1.gnb.ca<br/> Authentication Type:  Unauthenticated <br/> EAP Type:   -<br/> Account Session Identifier:  323732393137363738</p> <p>Quarantine Information:<br/> Result:    Quarantined <br/> Extended-Result:   -<br/> Session Identifier:   -<br/> Help URL:   -<br/> System Health Validator Result(s): -</p> <p>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br/>    &lt;EventID&gt;6276&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;0&lt;/Level&gt;<br/>    &lt;Task&gt;12552&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-25T10:47:43.855Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;149024&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;712&quot; ThreadID=&quot;6220&quot; /&gt;<br/>    &lt;Channel&gt;Security&lt;/Channel&gt;<br/>    &lt;Computer&gt;LEG-FS1.gnb.ca&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;leg-co489486&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;MachineInventory&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CalledStationID&quot;&gt;142.139.19.0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CallingStationID&quot;&gt;001422EDA6CC&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;142.139.19.161&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;LEG-FS1&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPortType&quot;&gt;Ethernet &lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP DHCP&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP DHCP Non NAP-Capable&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;LEG-FS1.gnb.ca&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br/>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;323732393137363738&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Quarantined &lt;/Data&gt;<br/>    &lt;Data Name=&quot;ExtendedQuarantineState&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSessionID&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineHelpURL&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSystemHealthResult&quot;&gt;-&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</p> <p>Log Name:      Security<br/>Source:        Microsoft-Windows-Security-Auditing<br/>Date:          6/25/2009 7:47:43 AM<br/>Event ID:      6276<br/>Task Category: Network Policy Server<br/>Level:         Information<br/>Keywords:      Audit Success<br/>User:          N/A<br/>Computer:      LEG-FS1.gnb.ca<br/>Description:<br/>Network Policy Server quarantined a user.</p> <p>Contact the Network Policy Server administrator for more information.</p> <p>User:<br/> Security ID:   NULL SID<br/> Account Name:   -<br/> Account Domain:   -<br/> Fully Qualified Account Name: -</p> <p>Client Machine:<br/> Security ID:   NULL SID<br/> Account Name:   leg-co489486<br/> Fully Qualified Account Name: -<br/> OS-Version:   -<br/> Called Station Identifier:  142.139.19.0<br/> Calling Station Identifier:  001422EDA6CC</p> <p>NAS:<br/> NAS IPv4 Address:  142.139.19.161<br/> NAS IPv6 Address:  -<br/> NAS Identifier:   LEG-FS1<br/> NAS Port-Type:   Ethernet <br/> NAS Port:   -</p> <p>RADIUS Client:<br/> Client Friendly Name:  -<br/> Client IP Address:   -</p> <p>Authentication Details:<br/> Proxy Policy Name:  NAP DHCP<br/> Network Policy Name:  NAP DHCP Non NAP-Capable<br/> Authentication Provider:  Windows <br/> Authentication Server:  LEG-FS1.gnb.ca<br/> Authentication Type:  Unauthenticated <br/> EAP Type:   -<br/> Account Session Identifier:  323732393137363738</p> <p>Quarantine Information:<br/> Result:    Quarantined <br/> Extended-Result:   -<br/> Session Identifier:   -<br/> Help URL:   -<br/> System Health Validator Result(s): -</p> <p>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br/>    &lt;EventID&gt;6276&lt;/EventID&gt;<br/>    &lt;Version&gt;0&lt;/Version&gt;<br/>    &lt;Level&gt;0&lt;/Level&gt;<br/>    &lt;Task&gt;12552&lt;/Task&gt;<br/>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br/>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-06-25T10:47:43.855Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;149025&lt;/EventRecordID&gt;<br/>    &lt;Correlation /&gt;<br/>    &lt;Execution ProcessID=&quot;712&quot; ThreadID=&quot;6220&quot; /&gt;<br/>    &lt;Channel&gt;Security&lt;/Channel&gt;<br/>    &lt;Computer&gt;LEG-FS1.gnb.ca&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;leg-co489486&lt;/Data&gt;<br/>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;MachineInventory&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CalledStationID&quot;&gt;142.139.19.0&lt;/Data&gt;<br/>    &lt;Data Name=&quot;CallingStationID&quot;&gt;001422EDA6CC&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;142.139.19.161&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;LEG-FS1&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPortType&quot;&gt;Ethernet &lt;/Data&gt;<br/>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP DHCP&lt;/Data&gt;<br/>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP DHCP Non NAP-Capable&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;LEG-FS1.gnb.ca&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br/>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;323732393137363738&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Quarantined &lt;/Data&gt;<br/>    &lt;Data Name=&quot;ExtendedQuarantineState&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSessionID&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineHelpURL&quot;&gt;-&lt;/Data&gt;<br/>    &lt;Data Name=&quot;QuarantineSystemHealthResult&quot;&gt;-&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;</p>Thu, 25 Jun 2009 11:22:11 Z2009-06-25T11:22:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#51b63152-6696-4bda-9bf1-5cdd949deab1http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#51b63152-6696-4bda-9bf1-5cdd949deab1Bhuvanlhttp://social.technet.microsoft.com/Profile/en-US/?user=BhuvanlNon-NAP Capable computers receiving full network access using DHCP enforcementHi, <br/>   Yes, This behaviour has been noticed at my set up too. Client Getting 50% of times Full access despite client being Quarantined. This is only on XP S3 Clients<br/>Fri, 26 Jun 2009 06:16:05 Z2009-06-26T06:16:05Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#7735680f-01c9-4057-807a-00f9eed24f15http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#7735680f-01c9-4057-807a-00f9eed24f15Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayNon-NAP Capable computers receiving full network access using DHCP enforcementLefty777,<br/> <br/> Thanks for posting the event logs. The events all say that the policy that was matched is the Non-NAP capable policy:<br/> <br/> <strong>Network Policy Name:  NAP DHCP Non NAP-Capable</strong> <br/> <br/> None of the events evaluate a client as compliant or non-compliant. In order to match one of these health states, the client must be NAP-capable. When it is non-NAP capable (because NAP agent is not running) it is quarantined because you have configured the non-NAP capable policy's &quot;NAP enforcement&quot; setting to provide limited network access. This is expected.<br/> <br/> The problem you are seeing is due to a recently reported bug that only affects XP SP3 non-NAP capable clients using DHCP enforcement. We are investigating the cause. It may be a client side problem or an issue on the DHCP server. I'll update this thread if additional details or fixes become available. The only solution available at this time is to allow the client to renew its DHCP lease.<br/> <br/> -GregSun, 28 Jun 2009 22:39:29 Z2009-06-28T22:41:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#54b0d3e5-6498-48b2-b909-ac9162264e36http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#54b0d3e5-6498-48b2-b909-ac9162264e36tklosehttp://social.technet.microsoft.com/Profile/en-US/?user=tkloseNon-NAP Capable computers receiving full network access using DHCP enforcementI am also seeing the same pattern on XP SP3<br/>I'm working with very basic DHCP based rules based on the article &quot;Geek of all Trades Control network Access Using DHCP Enforcement&quot; <br/><br/>If you run napstat.exe on the client...it thinks everything is good, and its not. <br/><br/>Is there better logging on the server side? Does anyone have details on how to read the accounting logs? <br/>Mon, 29 Jun 2009 18:56:00 Z2009-06-29T18:56:00Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#8f9a86ca-e230-462a-9656-7e705a0f9dd4http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#8f9a86ca-e230-462a-9656-7e705a0f9dd4MyGpostshttp://social.technet.microsoft.com/Profile/en-US/?user=MyGpostsNon-NAP Capable computers receiving full network access using DHCP enforcementIs there a fix for XP SP3 clients or is this fixed in 2008 R2 DHCP servers?Fri, 21 Aug 2009 19:40:54 Z2009-08-21T19:40:54Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#ca8a1723-9670-4eaa-8f14-95c8b74837d6http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#ca8a1723-9670-4eaa-8f14-95c8b74837d6Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayNon-NAP Capable computers receiving full network access using DHCP enforcementHi,<br/><br/>To answer tklose's question about logging, the best way to interpret client status is with SQL logging. We are working on making this simpler to implement, but for now you must create a SQL database, table, and stored procedure. I provided some example commands for this <a href="http://social.technet.microsoft.com/Forums/en-US/winserverNIS/thread/5b55600d-33b8-4186-a55c-762315be5e17/">in this thread</a>, and I've reproduced it below for you also.<br/><br/> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">USE [master]</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">CREATE DATABASE [NPSXML] ON PRIMARY </span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">(NAME = N'NPSXML', FILENAME = N'D:\NPSSQL\NPSXML.mdf’)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">LOG ON  (NAME = N'NPSXML_log', FILENAME = N'D:\NPSSQL\NPSXML_log.LDF') </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">USE [NPSXML]</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">CREATE TABLE [dbo].[NPS_Packets] ([PacketTime] [datetime] NOT NULL DEFAULT (getutcdate()),</span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">[NPS_Attributes] [xml] NOT NULL) ON [PRIMARY]</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">CREATE PROCEDURE [dbo].[Report_Event]</span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">(@doc nvarchar(max))</span></p> <p class=MsoNormal style="margin:0in 0in 0pt 0.5in;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">AS</span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">INSERT INTO NPS_Packets (PacketTime, NPS_Attributes)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt;text-indent:0.5in"><span style="font-size:10pt;color:#1f497d;font-family:'Courier New'">VALUES (GETUTCDATE(), @doc)</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="color:#1f497d"><span style="font-size:small;font-family:Calibri"> </span></span><br/>To answer MyGposts, question, there isn't a fix yet. I've just updated the bug with more information. Please add any information you can about how this problem is affecting your NAP deployment. This will help to expedite a hotfix.<br/><br/>-Greg</p>Fri, 21 Aug 2009 21:31:34 Z2009-08-21T21:31:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#400cd930-eea3-4994-bb65-45a7173e1732http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#400cd930-eea3-4994-bb65-45a7173e1732Lefty777http://social.technet.microsoft.com/Profile/en-US/?user=Lefty777Non-NAP Capable computers receiving full network access using DHCP enforcementI would think the fact that there are known bugs in NAP would be enough to expedite a hotfix.Thu, 27 Aug 2009 13:22:16 Z2009-08-27T13:22:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#d43704c9-d0df-4ddf-8a9a-86890765111ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#d43704c9-d0df-4ddf-8a9a-86890765111eMyGpostshttp://social.technet.microsoft.com/Profile/en-US/?user=MyGpostsNon-NAP Capable computers receiving full network access using DHCP enforcementWe were planning to upgrade our domain from 2003 to 2008 and DHCP enforcement was one of the most important reasons why.  The majority of clients will be XPSP3, so this is a complete show stopper.  We are not going forward with the domain upgrade at all until this is resolved.<br/>Thu, 27 Aug 2009 13:37:13 Z2009-08-27T13:37:13Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#4feac6ca-c007-4823-a765-f61c775bdff9http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#4feac6ca-c007-4823-a765-f61c775bdff9Marcos Vinícios W. F. da Costahttp://social.technet.microsoft.com/Profile/en-US/?user=Marcos%20Vin%u00edcios%20W.%20F.%20da%20CostaNon-NAP Capable computers receiving full network access using DHCP enforcementI have the same problems when i test with ws08-R2...<br/>Anyone solved this problem?<hr class="sig">Marcos Vinícios Wasem Ferreira da Costa [ MCP / MCSA / MCSA+S / MCSE / MCSE+S ]Mon, 31 Aug 2009 10:35:02 Z2009-08-31T10:35:02Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#1aa4d631-c60a-4dc2-8c2a-35077d59cdefhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#1aa4d631-c60a-4dc2-8c2a-35077d59cdefVincent Ngaihttp://social.technet.microsoft.com/Profile/en-US/?user=Vincent%20NgaiNon-NAP Capable computers receiving full network access using DHCP enforcementHi all,<br/> <br/> Read through all of yours message and got the answer that NAP with XP SP3 have know bug issue.<br/> May i know where can i see the update infromation/hotfix, for this problem . Our company also want to control user network access by antivirus.<br/> <br/> Regard,<br/> VincentTue, 20 Oct 2009 03:16:43 Z2009-10-20T03:17:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#f3209e2f-ae1a-4daa-bbe1-0154cc736c02http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#f3209e2f-ae1a-4daa-bbe1-0154cc736c02Greg Lindsayhttp://social.technet.microsoft.com/Profile/en-US/?user=Greg%20LindsayNon-NAP Capable computers receiving full network access using DHCP enforcementHi,<br/><br/>There is not a hotfix available for this yet. A workaround would be to use ipconfig/renew in the logon script for XP computers only, but I know this is not ideal.<br/><br/>I believe the problem is still under investigation, but I have notified the product group that handles this of your request.<br/><br/>-GregTue, 20 Oct 2009 04:56:23 Z2009-10-20T04:56:23Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#97db8d0e-9a46-4207-b591-124da59d4319http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/a79cc00e-f425-4662-af7f-931fe32fb6a7#97db8d0e-9a46-4207-b591-124da59d4319Vincent Ngaihttp://social.technet.microsoft.com/Profile/en-US/?user=Vincent%20NgaiNon-NAP Capable computers receiving full network access using DHCP enforcementFinally, i've got a test with those NAP supported client platform Window XP SP3,Window Vista, Winodw 7 and One Non supported platform Winodw XP SP2...<br/> <br/> My enviroment is as follow...<br/> <br/> Window 2003        Role: DC + DNS<br/> Window 2008        Role: NAP Server + DHCP Server<br/> Window XP SP3      Role: Client without AntiVirus Client<br/> Window Vista         Role:Client with AntiVirus Symantec Endpoint 11 Client<br/> Window 7              Role:Client with AntiVirus AVG Free Edition 9.0<br/> <br/> Such that the result i've got is <br/> <br/> Window XP SP2 ....match the expected result that it does not have NAP agent , and it never got a Health IP *Even do ipconfig /release + renew<br/> <br/> Window XP SP3 ....match the expected result that this version have known bug issue , no matter disable the NAP agent , client status is match or no match of the SHVs , client can get the Health/Limited IP after they do ipconfig /release + renew<br/> <br/> Window Vista  ....match the expected result and it support with Symantec Endpoint 11 Client<br/> <br/> Window 7 .....match the expected result and it support with AVG Free Edition 9.0<br/> <br/> It's a great technology but just very hope that to fix XP SP3 issue ....otherwise i will thinks that NAP is <span style="text-decoration:underline"><strong>NOT</strong> </span> support in XP!!!!<br/> <br/> P.S If the situation like that , i think it is better to make XP SP3 Client same as XP SP2 result....that...make me feel normal....<br/> <br/> P.S.2 Thanks Greg answer ! <br/> <br/> P.S.3 Did anybody know a list for antivirus support client in NAP, or i need to test one by one?<br/> <br/> Regards and thanks,<br/> Vincent<br/>Tue, 27 Oct 2009 03:21:29 Z2009-10-27T03:21:57Z