Enterasys-networks Enterasys Diamond Distributed Forwarding Engine 7K Manuel d'utilisateur Page 20

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 64
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 19
Secure Networks Policy Support
1-4 Introduction
Secure Networks Policy Support
PolicyEnabledNetworkingmanagestheallocationofnetworkinginfrastructureresourcesina
secureandeffectivemanner.UsingSecureNetworksPolicy,anITAdministratorcanpredictably
assignappropriateresourcestotheUsers,Applications,andServicesthatusethenetwork;while
blockingorcontainingaccessforinappropriateorpotentiallydangerousnetworktraffic.Using
thistechnologyitispossible,forthefirsttime,toalignITserviceswiththeneedsofspecificusers
andapplications,andtoleveragethenetworkasakeycomponentoftheorganization’ssecurity
strategy.
TheSecureNetworksPolicyArchitectureconsistsof3components:ClassificationRules,Network
Services,andBehavioralProfiles.
Thesearedefinedasfollows:
ClassificationRulesdeterminehowspecifictrafficflows(identifiedbyLayer2,Layer3,and
Layer4informationinthedatapacket)aretreatedbyeachSwitch orRouter.Ingeneral,
ClassificationRulesareappliedtothenetworkinginfrastructureatthenetworkedge/ingress
point.
•NetworkServicesare
logicalgroupsofClassificationRulesthatidentifyspecificnetworked
applicationsorservices.Usersmaybepermittedordeniedaccesstotheseservicesbasedon
theirrolewithintheorganization.Priorityandbandwidthratelimitingmayalsobecontrolled
usingNetworkServices.
•BehavioralProfiles(orroles)areusedtoassignNetworkServices
togroupsofuserswho
sharecommonneeds–forexampleExecutiveManagers,HumanResourcesPersonnel,or
GuestUsers.Access,resources,andsecurityrestrictionsareappliedasappropriatetoeach
BehavioralProfile.Avarietyofauthenticationmethodsincluding802.1X,EAPTLS,EAP
TTLS,andPEAPmaybeusedtoclassifyandauthorizeeach
individualuser;andtheIT
AdministratormayalsodefineaBehavioralProfiletoapplyintheabsenceofan
authenticationframework.
Standards Compatibility
TheDFEDiamondmodulesarefullycompliantwiththeIEEE802.32002,802.3ae2002,
802.1D1998,and802.1Q1998standards.TheDFEDiamondmoduleprovidesIEEE802.1D1998
SpanningTreeAlgorithm(STA)supporttoenhancetheoverallreliabilityofthenetworkand
protectagainst“loop”conditions.
LANVIEW Diagnostic LEDs
LANVIEWdiagnosticLEDsserveasanimportanttroubleshootingaidbyprovidinganeasyway
toobservethestatusofindividualportsandoverallnetworkoperations.
Vue de la page 19
1 2 ... 15 16 17 18 19 20 21 22 23 24 25 ... 63 64

Commentaires sur ces manuels

Pas de commentaire