Enterasys-networks 9034385 Manuel d'utilisateur Page 26

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 25
Model 2: End-System Authorization
2-4 NAC Deployment Models
deviceidentity,useridentity,and/orlocationinformationisusedtoauthorizetheconnectingend
systemwithacertainlevelofnetworkaccess.Itisimportanttonotethatinthismodel,network
accessisnotbeingcontrolledbasedonendsystemassessmentresults.Assessmentwillbe
introducedinthenextNAC
deploymentmodel.
Implementation
InModel2,endsystemscanbedetected,authenticated,andauthorizedindifferentways
dependingonwhetherinlineoroutofbandnetworkaccesscontrolisimplemented.
Out-of-Band NAC
ForoutofbandNACutilizingtheNACGateway,NACfunctionsareimplementedinthe
followingway:
Detection‐End systemsaredetectedviathereceiptofRADIUSpacketsfromanaccessedge
switchattempting toauthenticateanendsystem.
Authentication‐Iftheendsystemis802.1Xorwebauthenticatingtothenetwork,
theNAC
GatewayproxiestheRADIUSauthenticationrequesttoabackend authentication(RADIUS)
servertovalidatetheidentityoftheuser/deviceconnectingtothenetwork.Forendsystemsthat
areMACauthenticatingtothenetwork,theNACGatewaycanbeconfiguredtoeitherproxythe
MACauthenticationrequeststoa
RADIUSserverorlocallyauthorizeMACauthentication
requestsattheNACGateway.IfonlyMACauthenticationisdeployedonthenetworkandthe
NACGatewayisconfiguredtolocallyauthorizeMA C a uthenti cationrequests,thenabackend
RADIUSserverisnotrequiredfortheEnterasysNACsolution.
Authorization‐TheNACGatewayallocates
theappropriatenetworkresourcestotheendsystem
basedondeviceidentity,useridentity,andlocation.ForEnterasyspolicyenablededgeswitches,
theNACGatewayformatsinformationintheRADIUSauthenticationmessagesthatdirectsthe
edgeswitchtodynamicallyassignaparticularpolicytotheconnectingendsystem.ForRFC3580
capableedgeswitches,theNACGatewayformatsinformationintheRADIUSauthentication
messages(intheformofRFC3580VLANTunnelattributes)thatdirectstheedgeswitchto
dynamicallyassignaparticularVLANtotheconnectingendsystem.TheNACGatewaymay
denytheendsystemaccesstothenetwork
bysendingaRADIUSAccessRejectmessagetothe
edgeswitchorassigntheendsystemasetofnetworkresourcesbyspecifyingaparticularpolicy
orVLANtoassigntotheauthenticatedendsystemontheedgeswitch.
Inline NAC
ForinlineNACutilizingtheLayer2orLayer3NACController,NACfunctionsareimplemented
inthefollowingway:
Detection‐End systemsaredetectedviathereceiptofRADIUSpacketsfromanaccessedge
switchattempting toauthenticateanendsystem.
Authentication‐Oneoftwoauthenticationconfigurationscanbeimplementedon
theNAC
Controller.Authenticationcanbedisabledaltogether,trustingthatthedownstreaminfrastructure
devicesauthenticatedtheendsystemandpermittednetworkaccess.Alternately,MAC
registrationcanbeimplementedfornewdevicesconnectingtothenetwork,whereausername
andpasswordand/orasponsorusernameandpasswordmustbevalidatedagainst
abackend
LDAPcompliantdatabasebeforenetworkaccessispermitted.
Authorization‐TheNACControllerallocatestheappropriatenetworkresourcestotheend
systembyassigningapolicylocallyonthecontrollertothetrafficsourcedfromtheendsystem.
Vue de la page 25
1 2 ... 21 22 23 24 25 26 27 28 29 30 31 ... 97 98

Commentaires sur ces manuels

Pas de commentaire