Remote Access Policies

Discussion in 'Network Infrastructure' started by Daniel, Sep 21, 2009.

  1. Daniel

    Daniel Byte Poster

    Hello guys, just thought I'd pop in and use your fountain of knowledge.



    Policy 1

    Day/Time: Mon - Friday
    Group: Sales

    Now, I've heard two answers to this question.

    If I meet the first condition of the policy, but not the second condition of the policy, is the policy logic finished? Or do me move onto the next policy.

    My LabSim software says in the tutorial that we move onto the next policy, but in the Q/A section, it says that the policy logic is finished, we do not check any more policies if you meet one condition of a policy but not all.

    I have a sneaking suspicion that if you do not meet all conditions of a policy or you meet some but not all of the conditions in a the policy, we move onto the next one.

    Cheers guys.
  2. craigie

    craigie Terabyte Poster

    It's a bit of both mate.

    The rules are processed in order, however if certain explicit conditions are not met then, no further rules are processed. Therefore, you have to be careful how you do the rules.

    For example, if you always wanted the Sales group to have access regardless of time and day, but the Marketing group to only have access between 9-5 M-F, you would set it up as follows:

    Policy 1 - Sales Allow Access
    Policy 2 - M-F 9-5
    Policy 3 - Marketing Allow Access
  3. Daniel

    Daniel Byte Poster


    I got that.

    If you meet the conditions of a policy but your denied in Active Directory, THEN the policy logic is finish.

    We do not check any other policies.
