skip to content

Which destinations must a NAC quarantine segment reach, and what does each hand an intruder?

level: juniorimportance: must knowfreq 61%

answer

  1. quarantine admits, it does not deny
  2. the device must still be fixable
  3. patch, DNS, identity, time
  4. every allowed destination is a route
  5. allow-list by address versus a CDN

basics

~20 s

A quarantined device can only be fixed if the segment still reaches patching, name resolution, identity and a time source. Every one of those is also an open path for an intruder sitting on the device that failed the check.

solid answer

~50 s

Quarantine is not a denial: the device is admitted, just into a restricted segment, so whatever fixes it has to be reachable from inside. That is normally the patch or update service, DNS to resolve it, the directory or identity service so the machine and user can authenticate, a time source so TLS certificate validation succeeds, and often revocation or certificate-enrolment endpoints. The list is the price. Each entry is negotiated with the team that owns the destination, and each is a route that an intruder already resident on the failed device inherits for free — including one they can choose, by stopping the health agent so the device is deliberately placed there. The common operational failure is DNS plus a content-delivery network: an allow-list written as IP addresses stops matching the addresses the update service resolves to, remediation silently fails, and the exception list grows until quarantine is nearly production.

go deeper

for a junior

Be ready to say what quarantine is for: the device is admitted, not blocked, so it must still reach what repairs it. Name patching, DNS, identity and time without prompting.

for a middle

Explain why each destination is needed and why time and DNS are the two people forget. Describe the CDN address-list failure and the fix of filtering by name or using an internal distribution point.

for a senior

Show that you write the reach-list as if the host is hostile, and that you can defend each entry to the team that owns that service. Explain how the list is prevented from growing until quarantine equals production.

for a principal

Own the fact that this list is a standing exception register with named owners and review dates, and be able to say what business the estate declines to do rather than widen it further.

## What quarantine actually is Network access control makes a decision at admission. One outcome is a plain deny — the port stays dead. The other, and the one estates actually deploy, is a restricted authorization: the device is admitted but placed somewhere it can do very little. That somewhere is usually called the quarantine or remediation segment, and the name contains the whole problem. A device is put there *because it is broken*, and a device that is broken has to be able to reach the things that fix it. Quarantine that reaches nothing is just a slower deny with a helpdesk ticket attached. ## The reach-list Work it out from the remediation the device must perform, not from a template: | Destination | Why remediation needs it | What it gives an intruder on that device | |---|---|---| | Patch / update service | The actual fix — OS updates, agent version, definitions | An outbound path to a large, trusted, often internet-hosted service | | DNS | To resolve the update, identity and time endpoints at all | A resolver that answers, i.e. an outbound channel that is never fully inspected | | Directory / identity | Machine and user authentication, policy retrieval, credential renewal | Reach to the most valuable service in the estate from an unhealthy host | | Time | TLS certificate validity checks fail on a skewed clock, so nothing downloads | Little on its own, which is why it is the entry people forget to ask for | | Revocation / certificate enrolment | Validating or renewing the certificate the device authenticates with | Minor, but it is another named hole with an owner who must approve it | Each row is a conversation with a different team. The patching owner, the directory owner and the DNS owner each have to agree that a segment full of known-unhealthy machines may talk to their service, and each of them is entitled to ask what happens when one of those machines is not merely unpatched but actively hostile. That negotiation, one owner at a time, is the real cost of running quarantine — far more than the switch configuration. ## The direction of the claim Being in quarantine proves that a check returned a failing result. It does not prove the device is merely out of date, and it does not prove the device is not compromised. Those are different states with the same verdict. So the correct posture toward the reach-list is that every entry is reachable by an adversary, not by a well-meaning laptop; write it as though the host in quarantine is hostile, because sometimes it is, and because an intruder who wants those holes can obtain them by making the device fail on purpose — stopping the health service is enough. ## The failure everybody hits Allow-lists are usually written as addresses, because that is what a filter takes. Update services are usually delivered from content-delivery networks whose addresses change constantly and differ per region and per resolver. The result is an allow-list that worked in the lab, works for a week, and then silently stops matching: devices sit in quarantine, downloads time out, users call, and somebody widens the rule until it is effectively general egress. If the destination cannot be pinned to stable addresses, the honest answers are a forward proxy for the segment that resolves and filters by name, an on-premises distribution point the device can reach instead, or an accepted, documented broad hole that somebody owns. The symmetrical mistake is a resolver split: quarantine points at a restricted DNS view, the update endpoint resolves to an address the filter denies, and the failure looks like a patching problem rather than a network one. ## What quarantine must not reach Say this part out loud in an interview, because it is what separates a reach-list from a second production network. Quarantine should not reach general internet egress, production application or data services, the management plane of the network devices enforcing it, or — ideally — its own peers, since everything else in that segment is by definition unhealthy too. A quarantine that has grown holes for six teams and never lost one is not a control any more; it is a slightly awkward VLAN, and the fact that a device landed there means nothing.

  • Why is a quarantine allow-list written as IP addresses so often the thing that breaks?
    Update services are usually delivered from content-delivery networks: the addresses returned vary by region, by resolver and over time. The filter matches on the day it is written and then quietly stops matching, so downloads fail, devices never leave quarantine, and the rule gets widened until it is close to general egress. Filter by name through a proxy, or point the segment at an internal distribution point with a stable address.
  • Why does a laptop that has been powered off for months often fail remediation even with the right holes open?
    Its clock has drifted. Certificate validity is checked against local time, so the TLS connection to the update or identity service is rejected as not-yet-valid or expired before any content moves. Nothing about the allow-list is wrong; the missing entry is a reachable time source. It is the most commonly forgotten row in the reach-list because nobody thinks of it as remediation.
  • What should quarantine explicitly not be allowed to reach?
    General internet egress, production application and data services, the management plane of the switches and the policy server enforcing the decision, and its own peers. Everything else in that segment is unhealthy by definition, so peer reachability means a device that failed for a bad reason sits adjacent to devices that failed for a worse one, sharing a first hop they all trust.

It is a hospital isolation room, not a locked cell: the door has to open for the doctor, the pharmacy and the meal trolley, and every one of those openings is also a way out.

saying these in an interview costs you the question

  • Says quarantine means the device has no network access
  • Assumes the patch service is the only destination remediation needs
  • Forgets DNS and time, then blames the update agent
  • Pins an allow-list to addresses for a CDN-hosted update service
  • Treats every hole as harmless because the segment is called isolated
  • Never mentions that an intruder can choose quarantine by failing on purpose

context