Enterasys-networks 9034385 Manuel d'utilisateur Page 15

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 14
NAC Solution Components
Enterasys NAC Design Guide 1-5
EnterasysofferstwotypesofNACappliances:theNACGatewayapplianceimplementsoutof
bandnetworkaccesscontrol,andtheNACControllerapplianceimplementsinlinenetworkaccess
control.ThefollowingsectiondescribeshoweachNACapplianceimplementsnetworkaccess
controlforconnectingendsystems.
NAC Gateway Appliance
TheNACGatewayisutilizedtoimplementoutofbandnetworkaccesscontrolforconnecting
endsystems.WiththeNACGateway,connectingendsystemsaredetectedonthenetwork
throughtheirRADIUSauthenticationinterchange.Basedontheassessmentandauthentication
resultsforaconnectingdevice,RADIUSattributesareaddedormodified
duringthe
authenticationprocesstoauthorizetheendsystemontheauthenticatingedgeswitch.Therefore,
theNACGatewaycanbepositionedanywhereinthenetworktopologywiththeonly
requirementbeingthatIPconnectivitybetweentheauthenticatingedgeswitchesandtheNAC
Gatewaysisoperational.
TheNACGatewayrequirestheimplementation
ofintelligentwiredorwirelessedge
infrastructuredevicesastheauthorizat ion pointforconnectingendsystems.Intelligentedge
devicesarecapableofsupportingauthenticationandauthorizationbasedontheauthentication
messageinterchange.Dependingontheappliancemodel,theNACGatewayprovideseither
integratedassessmentserverfunctionalityand/ortheabilityto
connecttoexternalassessment
services,todeterminethesecuritypostureofendsystemsconnectingtothenetwork.
ThreeNACGatewaymodelsareavailabletomeettheneedsofdifferentsizedimplementa tions
andassessmentserverrequirements.
SNSTAGITAsupportsupto3000concurrentendsystemsandprovidesintegrated
assessmentservers.(A
separatelicenseisrequiredforintegratedassessment.)Thisintegrated
NACGatewaysupportsbothagentless(networkbased)andagentbasedassessment.In
additiontohavingthecapabilitytorunasanintegratedappliance,italsohasthecapabilityto
runasanassessmentserver(scanner)only.TheSNSTAGITAalso
supportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGHPAsupportsupto3000concurrentendsystemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGLPAsupportsupto2000concurrentend
systemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
NAC Controller Appliance
TheNACControllerisutilizedtoimplementinlinenetworkaccesscontrolforconnectingend
systems.WiththeNACController,connectingendsystemsaredetectedthroughthereceiptofa
packetfromanewendsystem.Basedontheassessmentandauthenticationresultsfora
connectingdevice,theauthorizationoftheend
systemisimplementedlocallyontheNAC
Controllerappliancebyassigningasetoftrafficforwardingrules,referredtoas“policy,”toall
trafficsourcedbytheendsystem.TheNACControllerapplianceispositionedstrategicallyinthe
networktopologywithintheenduserLANsegmentoracrossroutedboundaries,
inlinewithdata
trafficsourcedfromendsystems.Sincethisapplianceexistsinthedata pathofnetworked
devices,ithasbeendesignedtoachievemultigigabitthroughputwithhardwarebasedtraffic
forwarding,byleveragingcustomizedEnterasysbuiltApplicationSpecificIntegratedCircuits
(ASICs).
TheNACControllerisapplicabletoscenarioswhere
nonintelligentwiredorwirelessedge
infrastructuredevicesaredeployedinthenetwork.Nonintelligentedgedevicesarenotcapable
Vue de la page 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 97 98

Commentaires sur ces manuels

Pas de commentaire