Enterasys-networks 9034385 Manuel d'utilisateur Page 21

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 20
Summary
Enterasys NAC Design Guide 1-11
•Model3:EndSystemAut horization withAssessment‐Implementsdetection,authentication,
assessment,andauthorizationtoprovidenetworkaccesscontrolbasedonthesecurityposture
ofaconnectingendsystem,aswellasuseranddeviceidentityandlocation.Thismodel
requirestheuseofeitherintegratedassessmentserverfunctionality or
theabilitytoconnectto
externalassessmentservices,inordertoperformtheendsystemassessment.
•Model4:EndSystemAut horization withAssessmentandRemediation‐Implements
detection,authentication,assessment,authorization,andremediation,providingtheadditional
abilitytoquarantineandremediatenoncompliantdevices.
TheNACapplianceisacorecomponent
oftheEnterasysNACsolutionandisrequiredforall
NACdeploymentmodels.Itprovidestheabilitytodetect,authenticate,andauthorizeenddevices
attemptingtoconnecttothenetwork.Italsointegrateswithorconnectstoassessmentservicesto
performassessmentofendsystemsconnectingtothenetwork.Onceauthentication
and
assessmentarecomplete,theNACapplianceauthorizesdevicesonthenetworkbyallocatingthe
appropriatenetworkresourcestotheendsystembasedonauthenticationand/orassessment
results.TheNACappliancealsoprovidesremediationfunctionality,allowingenduserstosafely
remediatetheirquarantinedendsystemwithoutimpactingIToperations.
Enterasysoffers
twotypesofNACappliances:
•TheNACGatewayapplianceimplementsoutofbandnetworkaccesscontrolandrequires
theimplementationofintelligentwiredorwirelessedgeinfrastructuredevicesonthe
network.
•TheNACControllerapplianceimplementsinlinenetworkaccesscontrolandisapplicableto
scenarioswherenonintelligentwiredorwireless
edgeinfrastructuredevicesaredeployedin
thenetwork.TheNACControllerisalsorequiredinIPSecandSSLVPNdeployments.
TheNACappliancesareconfigured,monitored,andmanagedthroughEnterasysNetSight
managementapplications.NetSightNACManagerandNetSightConsolearerequiredforallfour
NACdeploymentmodels.NACManagerprovides
configurationsfortheassessment,
authentication,authorization,andremediationparametersforallNACappliances,whileNetSight
Consoleisusedtomonitorthehealthandstatusofinfrastructuredevicesinthenetwork,
includingswitches,routers,andEnterasysNACappliances.
NetSightPolicyManagerandNetSightInventoryManagerareoptionalNetSightapplications.
PolicyManagerprovides
theabilitytocentrallydefineandconfiguretheauthorizationlevelsor
“policies”forcertainoutofbandNACdeploymentsandallinlineNACdeployments.Inventory
Managerprovidescomprehensivenetworkinventoryandchangemanagementcapabilitiesfor
yournetworkinfrastructure.
ThenextchapterprovidesamoredetaileddescriptionofthefourNACdeployment
models
includingtheirrequirementsandimplementation.
Vue de la page 20
1 2 ... 16 17 18 19 20 21 22 23 24 25 26 ... 97 98

Commentaires sur ces manuels

Pas de commentaire