remote access quatantine enforcement client problems on windows 7
I am running windows 7 rtm and am having trouble with the remote access quarantine client, in fact the client doesn't appear to be on this computer.. when i go to napclcfg.msc the remote access quatantine enforcement client is not listed. If I try to enable it from the command prompt, this is the message I get
C:\Users\whittla>netsh nap client set enforcement ID = 79618 ADMIN = "ENABLE"
Element not found.
set enforcement
[ID = ] id
[ADMIN = ] ENABLE|DISABLE
Enables or disables enforcement clients. You can specify one or more
enforcement clients, but you must specify at least one. By default, all
enforcement clients are disabled.
Id - the identifier for the Quarantine Enforcement Client (QEC).
Examples:set enforcement ID = 67213 ADMIN = "DISABLE"
And if I run the "NETSH NAP CLIENT SHOW GROUPPOLICY" command I get this result
NAP client configuration:
----------------------------------------------------Cryptographic service provider (CSP) = Microsoft RSA SChannel Cryptographic Prov
ider, keylength = 2048Hash algorithm = sha1RSA (1.3.14.3.2.29)
Enforcement clients:
----------------------------------------------------
Name = DHCP Quarantine Enforcement Client
ID = 79617
Admin = DisabledName = IPsec Relying Party
ID = 79619
Admin = DisabledName = RD Gateway Quarantine Enforcement Client
ID = 79621
Admin = DisabledName = EAP Quarantine Enforcement Client
ID = 79623
Admin = EnabledClient tracing:
----------------------------------------------------
State = Enabled
Level = AdvancedOk.
Which shows that the client isn't even installed. How can I install that client.
Thanks
Answers
- Hi,
As Miles had mentioned, Remote Access or VPN client in windows 7 uses the EAP QEC (Mentioned as Wireless EAP over LAN in the documentation ) for connecting to the VPN Server. So Remote Access QEC is removed in the Windows 7. You would need the enable this EAP QEC for VPN to work.
Thanks,
Srinivasulu.- Proposed As Answer bySrini MSFT Wednesday, September 09, 2009 4:04 AM
- Marked As Answer byMiles LiMSFT, ModeratorThursday, September 10, 2009 8:30 AM
All Replies
Hello,
Thanks for your post here.As described in the following link, the EAP enforcement client is also used for virtual private network (VPN) connections in Windows 7.
Configure NAP Enforcement Clients
http://technet.microsoft.com/en-us/library/cc770670.aspx
If you have any questions or concerns, please do not hesitate to let me know.
- I checked out the document you mentioned above and it talks about there being 6 different enforcement clients but the remote access quarantine client is not on my computer. I am running the enterprise version of Windows 7, does that make a difference? After tinkering with the settings sent out by our corporate IT team, i was able to connect through the corporate VPN anyways without this client being enabled. is the remote access quarantine client maybe built and enabled on this version of Windows?
Thanks - Hi,
As Miles had mentioned, Remote Access or VPN client in windows 7 uses the EAP QEC (Mentioned as Wireless EAP over LAN in the documentation ) for connecting to the VPN Server. So Remote Access QEC is removed in the Windows 7. You would need the enable this EAP QEC for VPN to work.
Thanks,
Srinivasulu.- Proposed As Answer bySrini MSFT Wednesday, September 09, 2009 4:04 AM
- Marked As Answer byMiles LiMSFT, ModeratorThursday, September 10, 2009 8:30 AM
- perfect, thanks very much
Hello Miles,Hello,
Thanks for your post here.As described in the following link, the EAP enforcement client is also used for virtual private network (VPN) connections in Windows 7.
Configure NAP Enforcement Clients
http://technet.microsoft.com/en-us/library/cc770670.aspx
If you have any questions or concerns, please do not hesitate to let me know.
Effectively i was a little lost because i am trying to configure my NAP VPN Enforcement, and i am getting a problem:
I have a W7 Build 7600 making a VPN to a VPN Server, this VPN Server is a RADIUS Client of a NPS Server that is a NAP& HRA Server.
I have configured the VPN NAP ENforcement with the wizard and it created me all the Network Connection Policies / Connection Request Poliies. Actually i have 3 Network Policies: NAP VPN Compliant / NAP VPN Noncompliant / NAP VPN Non NAP-Capable, my problem comes when i make the VPN Connection from my W7, i got connected with EAP & Secure MS-CHAP V2, but it get connected and evaluated by the NAP VPN Non NAP-Capable Policy, if i go to my VPN connection Properties it apperas NAP State - Not NAP-capable.
It seems like if the W7 clien does not send SoH to the NPS.
May you client sends a statement of health (SoH) to NPS
I'd really appreciate if you give some ideas.
Thanks Arnold

