1.0

Table Of Contents
CHAPTER 14 Understanding Policies
231
and retrieves the list. If you need to make any changes in the future, you
update the list stored on the server.
Dynamic quarantine gives you the flexibility to modify the access list at any
time you need to make changes. If you are using Active Directory and choose
to store the access list in your Active Directory service, VMware ACE Manager
stores your updates on the server for you. If you use a Web server to store the
access list, VMware ACE Manager creates the file, which you must then copy
to the specified location on the Web server.
Version-based quarantine — You specify two lists of approved networks and
machines. One list is used for virtual machines that have a network quarantine
version approved for normal access. The other list is used for virtual machines
with versions that do not qualify for normal access. The lists are stored on a
server. Each time the virtual machine runs, and at frequent intervals while it is
running, it contacts the server and provides its network quarantine version.
Based on that version, the server provides the appropriate list of approved
networks and machines. If you need to make any changes to the lists or the
network quarantine version in the future, you do so by updating the
information stored on the server.
Like dynamic quarantine, version-based quarantine gives you the flexibility to
modify the access lists at any time you need to make changes. In addition,
version-based quarantine allows you to impose special restrictions on virtual
machines that do not meet the current criteria for normal access — for
example, allowing them to communicate only with an update server.
If you are using Active Directory and choose to store the access lists in your
Active Directory service, VMware ACE Manager stores your updates on the
server for you. If you use a Web server to store the access lists, VMware ACE
Manager creates the files, which you must then copy to the specified location
on the Web server.
Note: VMware Tools provides services that are essential for version-based
quarantine. This means you cannot use version-based quarantine with guest
operating systems such as MS-DOS and Windows 3.1
Custom quarantine using script — You develop your own plug-in, using any
scripting language that can run on the end user’s machine, to apply the tests
you need to apply and return results that indicate whether access should be
restricted. Rules can be stored statically or dynamically. Custom quarantine is
useful, for example, if you need to integrate your deployment with third-party