Network Access Control via DHCP Filtering and Firewall Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network health enforcement methods struggle to effectively restrict non-compliant client computers' access to a network until they meet administrator-defined health policy standards, lacking a systematic approach to guide clients in remediation and restrict access efficiently.
Innovation Solution
A method where clients send a Statement of Health (SoH) to a server, which determines compliance and sends remediation and filtering instructions via DHCP or DHCPv6, allowing clients to download necessary updates by restricting access to specific network portions until compliance is achieved, using firewall rules to manage access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DHCP is used to control client access by modifying routes and gateway, then network access control is improved, but the ability to provide systematic remediation guidance and restrict access to specific remediation resources is insufficient
Solution Approach 1:
The patent segments network access into different levels: full network access for compliant clients and restricted access to specific remediation servers for non-compliant clients. The DHCP server divides the network into accessible and inaccessible segments based on compliance status, allowing clients to only reach remediation resources while blocking access to other network portions.
Solution Approach 2:
The patent introduces an intermediary mechanism where the DHCP server acts as a mediator between non-compliant clients and network resources. Instead of directly controlling all network access, the DHCP server provides filtered routing information that guides clients to appropriate remediation servers while blocking access to other resources, enabling systematic remediation guidance.
2Object-affected harmful factors
If non-compliant clients are completely blocked from network access, then network security is improved, but clients cannot obtain necessary updates and patches to achieve compliance
Solution Approach 1:
The patent applies local quality by providing different network access permissions to different parts of the network based on client compliance status. Non-compliant clients receive restricted access quality that allows communication only with specific remediation servers, while compliant clients receive full network access quality. This localized access control enables security maintenance while preserving remediation capability.
3Ease of operation
If full network access is granted to all clients, then ease of operation is improved, but network health policy compliance cannot be enforced and network risk increases
Solution Approach 1:
The patent implements dynamic network access control where client access permissions change based on their compliance status. Initially, non-compliant clients receive restricted access to remediation resources only. After applying updates and achieving compliance, clients dynamically transition to full network access. This dynamic adjustment balances ease of operation with health policy enforcement.
Data Source
AI summary
Systems and methods for controlling network access determine that a client computer on the network is in compliance with administrator-defined network health policy standards before the client computer is granted access to the network. A packet exchange mechanism is defined wherein filtering instructions from a server are converted into firewall rules on the client computer to restrict client access to remediation servers on the network. The client computer obtains update patches from the remediation servers to become compliant with network health policy standards.


