In the console tree of ISA Server Management, click
Networks.
In the details pane, select the Networks tab, and then
select the Quarantined VPN Clients network.
On the Tasks tab, click Edit Selected
Network.
On the Quarantine tab, select Enable Quarantine
Control.
Select one of the following options:
Quarantine according to RADIUS server policies. When a
VPN client attempts to connect, Routing and Remote Access policy
determines whether the connection request is passed to ISA Server.
After Routing and Remote Access policy has been verified, the
client unconditionally joins the VPN Clients network.
Quarantine VPN clients according to ISA Server policies.
When a VPN client attempts to connect to the ISA Server computer,
Routing and Remote Access unconditionally passes the request to ISA
Server. ISA Server places the connecting client in the Quarantined
VPN Clients network, subjecting the client to the firewall policy
defined for that network. When the client clears quarantine, it
moves into the VPN Clients network. When you select this option,
you must disable the Routing and Remote Access quarantine feature
so that the VPN connection can be established.
If quarantined clients should be disconnected after a specified
time, select Disconnect quarantine users after (seconds) and
type the number of seconds that will pass before a client will be
removed from the Quarantined VPN Clients network and disconnected
from ISA Server.
Notes
To open ISA Server Management, click Start, point to
All Programs, point to Microsoft ISA Server, and then
click ISA Server Management.
For ISA Server 2006 Enterprise Edition, expand
Microsoft Internet Security and Acceleration
Server 2006, expand Arrays, expand
Array_Name, expand Configuration, and then
click Networks.
For ISA Server 2006 Standard Edition, expand Microsoft
Internet Security and Acceleration Server 2006, expand
Server_Name, expand Configuration, and then
click Networks.
Important
When you select this option, you must configure Quarantine
Control on the ISA Server computer and on the remote VPN clients
attempting to connect. Otherwise, remote VPN clients will remain in
quarantine mode until the specified time passes and they are
disconnected from ISA Server.