Enterasys-networks Enterasys Matrix 9034310-01 Manuel d'utilisateur Page 21

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 58
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 20
Secure Networks Policy Support
Matrix DFE-Platinum Series Installation Guide 1-5
Secure Networks Policy Support
AfundamentalconceptthatiskeytotheimplementationoftheEnterasysSecureNetworks
methodologyispolicyenablednetworking.Thisapproachprovidesusersofthenetworkwiththe
resourcestheyneed‐inasecurefashionwhileatthesametimedenyingaccesstoapplicationsor
protocolsthataredeemedinappropriate
basedontheusersfunctionwithintheorganization.By
adoptingsucha“userpersonalized”model,itispossibleforbusinesspoliciestobetheguidelines
inestablishingthetechnologyarchitectureoftheenterprise.Twomajorobjectivesareachievedin
thisway:ITservicesarematchedappropriatelywithindividualusers;and
thenetworkitself
becomesanactiveparticipantintheorganization’ssecuritystrategy.TheSecureNetworks
architectureconsistsofthreetiers:
Classificationrulesmakeupthefirstorbottomtier.TherulesapplytodevicesintheSecure
Networksenvironment,suchasswitchesandrouters.Therulesaredesignedtobe
implemented
atorneartheuserspointofentrytothenetwork.Rulesmaybewrittenbased
oncriteriadefinedintheLayer2,Layer3orLayer4informa tionofthedataframe.
•ThemiddletierisServices,whicharecollectionsofindividualclassificationrules,grouped
logicallytoeitherpermit
ordenyaccesstoprotocolsorapplicationsbasedontheusersrole
withintheorganization.Priorityandbandwidthratelimitingmayalsobedefinedinservices.
•Roles,orbehavioralprofiles,makeupthetoptier.Therolesassignservicestovarious
businessfunctionsordepartments,suchasexecutive,sales,andengineering.
Toenhancesecurityanddeliveratruepolicybasedinfrastructure,theEnterasysSecureNetworks
methodologycantakeadvantageofauthenticationmethods,suchas802.1X,usingEAPTLS,EAP
TTLS,orPEAP,aswellasothertypesofauthentication.Authorizationinformation,attachedtothe
authenticationresponse,determinestheapplicationofpolicy.
Authorizationinform ationis
communicatedviathepolicynameinaRADIUSFilterIDattribute.Anadministratorcanalso
definearoletobeimplementedintheabsenceofanauthenticationframework.Refertothe
releasenotesshippedwiththemodulefordetails.
Standards Compatibility
TheDFEmodulesarefullycompliantwiththeIEEE802.32002,802.3ae2002,802.1D1998,and
802.1Q1998standards.TheDFEmoduleprovidesIEEE802.1D1998Spanning TreeAlgorithm
(STA)supporttoenhancetheoverallreliabilityofthenetworkandprotectagainst“loop”
conditions.
LANVIEW Diagnostic LEDs
LANVIEWdiagnosticLEDsserveasanimportanttroubleshootingaidbyprovidinganeasyway
toobservethestatusofindividualportsandoverallnetworkoperations.
Vue de la page 20
1 2 ... 16 17 18 19 20 21 22 23 24 25 26 ... 57 58

Commentaires sur ces manuels

Pas de commentaire