Enabling quarantine for clients that are not NAP-capable

Updated: February 1, 2011

Applies To: Forefront Threat Management Gateway (TMG)

If your deployment includes clients that are not able to use Network Access Protection (NAP), it is recommended that you enable support for these clients via quarantine based on Forefront TMG.

To enable quarantine for these clients, you need to prepare Forefront TMG as a remote access quarantine agent (RQS) listener. For instructions on how to do this, see Installing the remote access quarantine tool.

For an up-to-date list of client operating systems that support NAP, see "Which versions of Windows support Network Access Protection as a client?" in Network Access Protection: Frequently Asked Questions (https://go.microsoft.com/fwlink/?LinkID=153403).

Concepts

Enforcing VPN client health requirements using NAP