FW_H_EnableQuarantine

To enable Quarantine Control

  1. In the console tree of ISA Server Management, click Networks.

  2. In the details pane, select the Networks tab, and then select the Quarantined VPN Clients network.

  3. On the Tasks tab, click Edit Selected Network.

  4. On the Quarantine tab, select Enable Quarantine Control.

  5. Select one of the following options:

    • Quarantine according to RADIUS server policies. When a VPN client attempts to connect, Routing and Remote Access policy determines whether the connection request is passed to ISA Server. After Routing and Remote Access policy has been verified, the client unconditionally joins the VPN Clients network.
    • Quarantine VPN clients according to ISA Server policies. When a VPN client attempts to connect to the ISA Server computer, Routing and Remote Access unconditionally passes the request to ISA Server. ISA Server places the connecting client in the Quarantined VPN Clients network, subjecting the client to the firewall policy defined for that network. When the client clears quarantine, it moves into the VPN Clients network. When you select this option, you must disable the Routing and Remote Access quarantine feature so that the VPN connection can be established.
  6. If quarantined clients should be disconnected after a specified time, select Disconnect quarantine users after (seconds) and type the number of seconds that will pass before a client will be removed from the Quarantined VPN Clients network and disconnected from ISA Server.

Note

To open ISA Server Management, click Start, point to All Programs, point to Microsoft ISA Server, and then click ISA Server Management.
For ISA Server 2006 Enterprise Edition, expand Microsoft Internet Security and Acceleration Server 2006, expand Arrays, expand Array_Name, expand Configuration and then click Networks.
For ISA Server 2006 Standard Edition, expand Microsoft Internet Security and Acceleration Server 2006, expand Server_Name, expand Configuration and then click Networks.

Important

When you select this option, you must configure Quarantine Control on the ISA Server computer and on the remote VPN clients attempting to connect. Otherwise, remote VPN clients will remain in quarantine mode until the specified time passes and they are disconnected from ISA Server.

Other Resources

ISALink_Quarantine