H3C Technologies H3C Intelligent Management Center User Manual
Page 149

131
{
Control Hard Disk Serial Number—Select this option if you want UAM to check serial numbers
of the hard disks on the user endpoint. For more information, see "
."
{
Enable SSID Access Control—Select this option if you want UAM to check the SSID to which the
user endpoint is connected. For more information, see "
6.
Configure the User Client Configuration area parameters:
{
iNode Client Only—Select this option if you want user authentication to be performed only
through the iNode client.
{
Disable iNode DC for Windows—Select this option if you want to block use of the iNode DC on
Windows endpoints.
{
Disable iNode DC for Linux/Mac OS—Select this option if you want to block use of the iNode
DC on Linux and Mac OS endpoints.
{
Forbid Modifying IP When Online—Select this option if you want to disable an online user from
modifying the endpoint's IP address. Otherwise, the user is logged out. When the policy server
feature is also enabled, the user is logged out immediately after the endpoint's IP address is
changed. When the policy server is disabled, the user is logged out several minutes after the
endpoint's IP address is changed. For information about configuring the policy server feature,
see "
Configuring policy server parameters
{
Auto Reconnect after Network Failure—Select this option if you want to enable the iNode client
to automatically reconnect if the user connection is closed because of a network failure.
{
Retry Interval (Minutes)—Select an interval at which the iNode client automatically reconnects,
in minutes. This parameter appears only when the Auto Reconnect after Network Failure option
is selected.
{
Retries—Select the maximum number of reconnection retries. This parameter appears only when
the Auto Reconnect after Network Failure option is selected.
{
Lowest Client Version—Configure the lowest version number of the iNode client that can be
used on the network, such as 5.00-0105. This parameter must be used together with the iNode
Client Only parameter of access services. If you select iNode Client Only for a service, the
service users must use an iNode client of the specified version or a higher version for network
access.
{
Action for Violation—Select the action to take on the user who violates a check item. The action
can be Kick Out or Monitor. The Kick Out option disconnects the online user or rejects the
access request. The Monitor option logs the violation without affecting the user state. For more
information about the violation logs, see "
Managing authentication violation logs
UAM checks the selected items on the user endpoint. The check items include:
−
Disable Proxy Server—Select this option if you want to prohibit use of proxy servers.
−
Disable Proxy Setting in IE—Select this option if you want to prohibit use of proxy settings
in the Internet Explorer browser.
−
Disable Multiple NICs—Select this option if you want to prohibit use of more than one NIC.
−
Prohibit Multiple OSs—Select this option if you want to prohibit installation of more than
one Windows operating system.
−
Prohibit Multi-IP on Authenticated NIC—Select this option if you want to prohibit the
authenticated NIC from using more than one IP address.
−
Forbid Modifying MAC—Select this option if you want to prohibit modifying the MAC
address of the authenticated NIC.