Hitachi

JP1 Version 12 JP1/IT Desktop Management 2 Overview and System Design Guide


2.8.13 Registering devices that are accessible to blocked devices

Some devices remain accessible to a device that has been blocked from the network by the network monitor feature: The computer in the same network segment that has the network monitor enabled, and any computers registered in Exclusive Communication Destination for Access-Denied Devices. Management servers and relay systems are automatically registered in Exclusive Communication Destination for Access-Denied Devices.

For example, if you register a server that provides security measures in Exclusive Communication Destination for Access-Denied Devices, a device that is blocked after being deemed a security risk can connect to the server to take security measures. The following figure shows an example in which a server that provides security measures is registered in Exclusive Communication Destination for Access-Denied Devices.

[Figure]

In Exclusive Communication Destination for Access-Denied Devices, only register computers that are fully secure and can communicate with quarantined devices without introducing a security risk.

Important

When controlling network access based on the results of security assessment, do not remove the management server from Exclusive Communication Destination for Access-Denied Devices. If you do, you will be unable to judge the security status of devices, preventing network access from being controlled on this basis. If you inadvertently remove the server, add it again manually.

Important

If you use Remote Install Manager for distribution, never delete management servers or relay systems from Exclusive Communication Destination for Access-Denied Devices. Deleting those devices makes it impossible to perform distribution. If you delete a management server or relay system by mistake, add it in Exclusive Communication Destination for Access-Denied Devices manually.

Tip

You can use the remote control feature with blocked devices by adding the computer on which you use the controller to Exclusive Communication Destination for Access-Denied Devices.