Hi! I'm doing some labs with the Netsight and Nac appliances. The problem comes when I try to deploy an agent-less informational assessment managed by a profile which maps to a "Assessing" vlan while assessing, a "Quarantine" vlan in order to put the end-system in quarantine and an internal vlan for the accept policy.
Please, correct me if I'm wrong, but the way I think it should work is that while the end-system is being scanned, this end-system is assigned to the Assessing vlan and the assessment server should reach him just to start the scoring tests. But, in order to do that, the end-system should receive a new IP (dhcp needed?) while it's assigned to the Assessing vlan and it should be able to reach the assessment server by its gateway. So the question is, should I need to enable the ipforwarding command between all vlans and how do I receive a new IP for the end-systems while assigned to the Assessing vlan? If I enable the ipforwarding option, the quarantine could be able to reach anywhere but it should be limited by the upm profile assigned to it right? These things come up to my mind because I'm getting the END_SYSTEM_UNREACHABLE error.
Thanks in advance