The Wayback Machine - https://web.archive.org/web/20060814135520/http://blogs.technet.com:80/nap/default.aspx
Welcome to TechNet Blogs Sign in | Join | Help

SHA and QEC developers take note: the NAP API reference documentation has been updated on MSDN with information about API support on NAP for Windows XP with Service Pack 2. All client APIs are supported on this platform. The topic About NAP for Windows XP with Service Pack 2 provides information about differences in NAP functionality for XP and Vista.  The topic also has information about joining the beta program.

 

 

More MSDN updates for NAP:

 

We’ve made the following changes to the NAP API documentation:

·         The topic InitializeNapAgentNotifier was added.

·         The topic UninitializeNapAgentNotifier was added.

·         The topic NapNotifyType was added.

·         The methods of the INapClientManagement interface were updated. The methods are now declared in the napmanagement.h file.

 

 

Cathy Dumas

Programming Writer

 

Secure Wireless LAN Solution: Microsoft's Authentication Infrastructure with Aruba Networks' Mobile Edge
Live Webcast
August 16, 2006 10AM PST
Pre-Registration Available Now

 

Deploying an enterprise-class secure wireless LAN with industry-leading security can be overwhelming – but it doesn’t have to be. Experience a live on-line demo of Microsoft’s identity-based, policy-driven network authentication infrastructure built on Windows Server 2003 and Windows XP. Together with Aruba Networks mobile edge, learn how to deploy a secure wireless LAN end-to-end by watching the experts configure the user interface step-by-step.

 

The power of this solution will be demonstrated as the experts enable the most common wireless LAN access scenarios through flexible access policies in both the Windows Server 2003 Internet Authentication Service (IAS) and the stateful firewall in the Aruba Networks' Mobility Controller. The demonstration will show how to configure secure, role-based access for trusted employees and short-term contractors using company-managed PCs and a guest using their personal PC. To validate the security of the solution, access rights for an untrusted "hacker" will be shown before configuring the solution for secure role-based access and then afterwards.

 

Microsoft and Aruba Networks professionals will be online to answer your questions in real-time.

 

Featured Products:

·         Microsoft Windows Server 2003 R2 Internet Authentication Service (IAS), Active Directory and Group Policy

·         Microsoft Windows XP SP2

·         Aruba Networks Aruba 800 Mobility Controller and Aruba AP70 Access Point

 

Register now for this event and receive email reminders at the following link.

 

 

Anthony Leibovitz [MSFT]
NPS/EAP Program Manager
Anthony.Leibovitz@online.microsoft.com *
* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

 

General

Step-by-step guides

Webcasts

Community

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

 

This article touches on the fact that NAP + IPsec can be used in conjunction with a new Vista feature called AuthIP. Check it out.

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

0 Comments
Filed Under:

Check out the NAP + VPN FAQ just posted on the RRAS blog.

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

0 Comments
Filed Under:

Elliot Lewis discusses NAP possibilities on college campuses.

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

Hey. Sorry about the weird state of the NAP blog this week. This past weekend I moved it from MSDN to TechNet, as most people who are interested in NAP hangout on TechNet.

What I didn't know is that I would lose 3 months of content. Bummer! I am manually restoring it as quickly as possible. Hang in there...

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

In April/May this year, our team from Education Queensland, a government department in Australia, headed to Redmond to take part in some preliminary testing and development work on the NAP project. This was a part of a Technology Adoption Program we signed up on as part of a partnership with Microsoft. During the trip which lasted three weeks, we had the pleasure of meeting most of the NAP team (including Jeff) who led us through the land of NAP. Prior to leaving, a lot of lead up work was done in the test lab in Brisbane so that the setup and configuration of the lab in Redmond could be done as quickly as possible. Our current production environment consists of 550,000 users across 1,350 sites with 130,000 machines in an area around a third the size of the United States, so it was important to nail the preparatory work. After performing all the lead-up work, we managed to have the complete environment up and running within the first week at the Microsoft labs.

 

This environment included 150 Longhorn RODC’s to replicate a ‘region’ in our production environment (which we built in a single day!). We also emulated 6 ‘physical’ sites in order to perform end-to-end testing on the NAP scenarios identified as possibilities in our environment. These included the three ‘flavours’ of NAP (IPSec, DHCP and 802.1x) and SMSv4 to perform client remediation. All of these scenarios tested well, helped along by a lot of input from the developers, PM’s and other support staff at Microsoft.

 

All in all, the trip was a huge success with the team returning to Australia much wiser and more NAP-aware. We were quarantine checked at customs (how ironic) and headed back to work to re-build the test lab on Beta 2 and impart some knowledge on our colleagues. The project is due to continue, with a rollout of IPSec NAP using the XP client and some Vista machines into production in the coming weeks.

 

We would really like to thank Jeff and the team for making us feel extremely welcome on campus and for the effort they put into making our test plan a reality - as ambitious as it was! We would also like to stay in touch with the team, as well as any others who may be NAP-interested. Email me whenever you like on simon.OBRIEN@qed.qld.gov.au if you have any questions about our trip or our upcoming NAP production implementation.

 

Cheers, 

Simon O’Brien.

 

Turns out the band Coldplay are big fans of the NAP Blog. Wow, we are flattered! Check out their "reaction shot" to the latest posts:

Just kidding. :->

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

 

I’m here to tell you our icon has no connection with “The Lord of the Rings”. :->

We have received Vista Beta 2 feedback that the icon is confusing and isn’t consistent with the rest of the Windows Security Center, etc. We are throwing around ideas how to make this experience better and easier to understand for the end-user.

This new icon would appear in the “notification area”, just like the old one did. The “shield” notion would move into the bubble message to help emphasize the healthy/unhealthy state:

The icon, and the bubbles, should only appear when your health state changes from healthy to un-healthy (and hopefully back to healthy).

Let us know what you think.

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

Well, we haven’t just been sitting around recovering from the Beta 2 push, that’s for sure. We jumped right in to Vista RC1 work. You only get a couple of hour’s breath, once a major milestone releases, to collect yourself before starting in on the next one. :->

 

We took a hard look at what work remains before shipping Vista and completing the last “polishing touches” before the train leaves the station.

 

It is really starting to feel like the good ol’ Win2k-XP days. As the months close towards a release date, the focus and intensity keeps stepping-up to a new level. Every bug is scrutinized; every code change is triple checked. Meetings are packed; “Shiproom” is heated (literally). Everyone wants to ship a great product people will love. It’s a matter of pride.

 

For some on the NAP team, this will be their first ever OS release. For others like me, it is another one under the belt. That doesn’t mean the butterflies ever leave your stomach that the product of the last couple of years of your life will exceed everyone’s expectations.

 

This is the closest I’ve ever felt towards a product. In the past, I’ve really only worked on technology pieces - IPsec, Routing and Remote Access and the Firewall. NAP is different; it brings a bunch of technology together to form a *solution* to a real world problem.

 

If you are in the United States, I hope you enjoy your 4th. Ciao to all!

 

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

 

Network Access Protection has quite a few moving parts and setting it up the first time can be a little daunting. To help everyone give it a try and make that first attempt as smooth as possible there are three step-by-step guides that can help. These documents will help you through the process of getting NAP up and running in your lab environment. They are detailed step-by-step guides for setting up a NAP system with a specific enforcement scenario. The scenarios documented are NAP with Server/Domain Isolation using IPsec policies, NAP with DHCP enforcement and NAP with VPN enforcement.

 

These guides go into great detail, specifically identifying what needs to be installed, configured and how. They also walk through how to test and verify the functionality of the system once it is installed and configured. The intent of these documents is to flatten out the initial learning curve for getting a working system and provide a jumping off spot for additional learning, and do this with as little hardware footprint as reasonable. They are not intended to be deployment guides. Deployment planning will obviously take more planning based on the needs and goals of your network.

 

The following guides apply to Beta 2 versions of Windows Vista and Windows Server Code Name "Longhorn":

 

Setting Up Internet Protocol Security Enforcement for Network Access Protection in a Test Lab

 

Setting Up Virtual Private Network Enforcement for Network Access Protection in a Test Lab

 

Setting Up Dynamic Host Configuration Protocol Enforcement for Network Access Protection in a Test Lab

 

Enjoy.

 

- Joseph Davies and Kevin Rhodes
Windows Network and Device Technologies / Network Access Protection

We visit many customers and partners around the world. One thing we hear consistently is “NAP client enforcement MUST BE SUPPORTED on XP”.

Which OS’es would block / hinder your NAP deployments if they weren’t supported? Any nice-to-have’s (non-blocking)? Raw numbers and/or supporting facts about your deployments, to justify the need, would really help us judge how big the problem really is.

Do you need support for:

1.)  Windows 2000

2.)  Windows Server 2003

3.)  Mac

4.)  Linux

5.)  Other

Please post your comments through the blog.

 

Jeff Sigman [MSFT]
NAP Release Manager
Jeff.Sigman@online.microsoft.com *
http://blogs.technet.com/nap

* Remove the "online" to actually email me.
** This posting is provided "AS IS" with no warranties, and confers no rights.

The Network Access Protection Client for Windows XP is the same “platform” as the one shipping in Windows VISTA. However, some of the ways it differentiates itself from XP are:

 

  • It is built-in to the product (out-of-the-box)
  • An administration console is available for local and Group Policy configuration.
  • The Windows System Health Agent (built-in “client” piece of NAP) takes advantage of Windows Defender support in the Security Center.
  • The underlying enforcement technologies have advanced features including: Authenticated IP for IPsec and Single Sign-On support for 802.1x.

As a platform is the same, this has advantages for those who want to extend NAP. Vendors can write NAP extensions ONCE, and use it on many OS platforms. It will also enable NAP deployments to define their server-side policies ONCE, no matter where they are in their migration towards VISTA clients.

 

 

- Rob Trace

Program Manager

Network Access Protection

Rob.Trace@online.microsoft.com

 

The NAP API documentation has been updated on MSDN. Here’s a list of changes for the beta 2 docs:

Some other minor changes were made to fix typos and add links to pages.

 

If you are looking for sample code, download and install the Vista Beta 2 SDK (available here). If you install the SDK to the default location, you will find the NAP sample application in C:\Program Files\Microsoft SDKs\Windows\v1.0\Samples\NetDS\NAP.

 

To send feedback on the documentation, click the “Send comments about this topic to Microsoft” link at the bottom of any API reference page. A programming writer will email you with a response. The majority of these updates were in response to feedback from customers. Thanks for all the great comments we have received so far on the docs. Your input is important!

 

Cathy Dumas

Programming Writer

More Posts Next page »