Windows Server TechCenter > Windows Server Forums > Network Access Protection > remote access quatantine enforcement client problems on windows 7
Ask a questionAsk a question
 

Answerremote access quatantine enforcement client problems on windows 7

  • Saturday, September 05, 2009 3:43 PMcurious user Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    I am running windows 7 rtm and am having trouble with the remote access quarantine client, in fact the client doesn't appear to be on this computer.. when i go to napclcfg.msc the remote access quatantine enforcement client is not listed.  If I try to enable it from the command prompt, this is the message I get

    C:\Users\whittla>netsh nap client set enforcement ID = 79618 ADMIN = "ENABLE"
    Element not found.


    set enforcement
       [ID = ] id
       [ADMIN = ] ENABLE|DISABLE


       Enables or disables enforcement clients. You can specify one or more
       enforcement clients, but you must specify at least one. By default, all
       enforcement clients are disabled.


       Id - the identifier for the Quarantine Enforcement Client (QEC).


       Examples:

         set enforcement ID = 67213 ADMIN = "DISABLE"

    And if I run the "NETSH NAP CLIENT SHOW GROUPPOLICY" command I get this result


    NAP client configuration:
    ----------------------------------------------------

    Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Prov
    ider, keylength = 2048

    Hash algorithm = sha1RSA (1.3.14.3.2.29)

    Enforcement clients:
    ----------------------------------------------------
    Name            = DHCP Quarantine Enforcement Client
    ID              = 79617
    Admin           = Disabled

    Name            = IPsec Relying Party
    ID              = 79619
    Admin           = Disabled

    Name            = RD Gateway Quarantine Enforcement Client
    ID              = 79621
    Admin           = Disabled

    Name            = EAP Quarantine Enforcement Client
    ID              = 79623
    Admin           = Enabled

    Client tracing:
    ----------------------------------------------------
    State = Enabled
    Level = Advanced

    Ok.

    Which shows that the client isn't even installed.  How can I install that client.

    Thanks

Answers

  • Tuesday, September 08, 2009 4:16 PMSrini MSFT Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Hi,

    As Miles had mentioned, Remote Access or VPN client in windows 7 uses the EAP QEC (Mentioned as Wireless EAP over LAN in the documentation ) for connecting to the VPN Server. So Remote Access QEC is removed in the Windows 7. You would need the enable this EAP QEC for VPN to work.

    Thanks,
    Srinivasulu.

All Replies

  • Monday, September 07, 2009 9:59 AMMiles LiMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Hello,


    Thanks for your post here.

     

    As described in the following link, the EAP enforcement client is also used for virtual private network (VPN) connections in Windows 7.

     

    Configure NAP Enforcement Clients

    http://technet.microsoft.com/en-us/library/cc770670.aspx

     

    If you have any questions or concerns, please do not hesitate to let me know.

     

  • Tuesday, September 08, 2009 4:00 PMcurious user Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    I checked out the document you mentioned above and it talks about there being 6 different enforcement clients but the remote access quarantine client is not on my computer.  I am running the enterprise version of Windows 7, does that make a difference?  After tinkering with the settings sent out by our corporate IT team, i was able to connect through the corporate VPN anyways without this client being enabled.  is the remote access quarantine client maybe built and enabled on this version of Windows?

    Thanks
  • Tuesday, September 08, 2009 4:16 PMSrini MSFT Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Hi,

    As Miles had mentioned, Remote Access or VPN client in windows 7 uses the EAP QEC (Mentioned as Wireless EAP over LAN in the documentation ) for connecting to the VPN Server. So Remote Access QEC is removed in the Windows 7. You would need the enable this EAP QEC for VPN to work.

    Thanks,
    Srinivasulu.
  • Tuesday, September 08, 2009 4:22 PMcurious user Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    perfect, thanks very much
  • Thursday, October 29, 2009 1:03 AMArnold Martínez V Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Hello,


    Thanks for your post here.

     

    As described in the following link, the EAP enforcement client is also used for virtual private network (VPN) connections in Windows 7.

     

    Configure NAP Enforcement Clients

    http://technet.microsoft.com/en-us/library/cc770670.aspx

     

    If you have any questions or concerns, please do not hesitate to let me know.

     

    Hello Miles,

    Effectively i was a little lost because i am trying to configure my NAP VPN Enforcement, and i am getting a problem:
    I have a W7 Build 7600 making a VPN to a VPN Server, this VPN Server is a RADIUS Client of a NPS Server that is a NAP& HRA Server.

    I have configured the VPN NAP ENforcement with the wizard and it created me all the Network Connection Policies / Connection Request Poliies. Actually i have 3 Network Policies: NAP VPN Compliant / NAP VPN Noncompliant / NAP VPN Non NAP-Capable, my problem comes when i make the VPN Connection from my W7, i got connected with EAP & Secure MS-CHAP V2, but it get connected and evaluated by the NAP VPN Non NAP-Capable Policy, if i go to my VPN connection Properties it apperas NAP State - Not NAP-capable.

    It seems like if the W7 clien does not send SoH to the NPS.

    May you client sends a statement of health (SoH) to NPS

    I'd really appreciate if you give some ideas.

    Thanks Arnold