Enterasys-networks 9034385 Manuel d'utilisateur Page 31

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 30
Model 3: End-System Authorization with Assessment
Enterasys NAC Design Guide 2-9
serverisrunningoriftheHTTPserverisoutofdate)and clientsidechecks(running
applications,softwareconfigurations,installedoperatingsystempatches)providedendsystem
administrativecredentialsareavailableforremotelogintoconnectingdevices.Additionally,the
NACGatewayʹslocalassessmentservicesalsoincludeagentbasedassessmentusing
aJavaWeb
Startbasedclientapplicationthatallowsexecutionofserversideandclientsidecheckswithout
requiringadministrativecredentialsorspecialhostfirewallconfigurations.
TheNACGatewayʹsremoteassessmentservicesincludeagentlessandagentbasedassessment
onotherNACGatewaysdeployedonthenetworkand/orthird
partyvulnerabilityscannerssuch
asNessusandLockdownEnforcer.As endsystemsconnecttothenetwork,assessmentscanbe
loadbalancedamongalloftheconfiguredassessmentservicesoradefinedpool.Thisprovides
maximumscalabilityandflexibility,and minimizestheamountoftimenecessarytocompletean
endsystemassessment.
Authorization‐TheNACGatewayallocatestheappropriatenetworkresourcestotheendsystem
basedonauthentication,location,and/orassessmentresults.For Enterasyspolicyenablededge
switches,theNACGatewayformatsinformationintheRADIUSauthenticationmessagesthat
directstheedgeswitchtodynamicallyassignaparticularpolicytotheconnectingend
system.For
RFC3580capableedgeswitches,theNACGatewayformatsinformationintheRADIUS
authenticationmessagesintheformofRFC3580VLANTunnelattributesthatdirectstheedge
switchtodynam icallyassignaparticularVLANtotheconnectingendsystem.Ifauthentication
failsand/ortheassessmentresultsindicate
anoncompliantendsystem,theNACGatewaycan
eitherdenytheendsystemaccesstothenetworkbysendingaRADIUSaccessrejectmessageto
theedgeswitchorquarantinetheendsystemwithahighlyrestrictivesetofnetworkresources(or
possiblypermitnetworkaccess)byspecifyingaparticularpolicy
orVLANtoassigntothe
authenticatedendsystemontheedgeswitch.
Inline NAC
ForinlineEnterasysNACdeploymentsutilizingtheLayer2orLayer3NACController,theNAC
functionsareimplementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐TheNACControllercanleverageeitherlocalassessmentservicesand/orremote
assessmentservicesdeployedonthe
network,aspreviouslydescribedfortheNACGateway.The
NACControllerʹslocalassessmentservicesincludeagentlessassessmentwhichcanexecute
variousserversidechecksandclientsidechecks.Localassessmentservicesalsoincludeagent
basedassessmentusingaJavaWebStartbasedclientapplicationthatallowsexecutionofserver
sideandclientsidechecks.TheNACControllerʹsremoteassessmentservicesincludeagentless
andagentbasedassessmentwithNACGatewaysand/orthirdpartyvulnerabilityscannerssuch
asNessusandLockdownEnforcer.As endsystemsconnecttothenetwork,assessmentcanbe
loadbalancedamongalloftheconfigured
assessmentservicestoprovidemaximumscalability
andflexibilitywhileminimizingassessmenttimes.
Authorization‐TheNACControllerallocatestheappropriatenetworkresourcestotheend
systembasedonauthenticationand/orassessmentresults.Thisisimplementedbyassigninga
policytotrafficsourcedfromtheendsystemlocallyonthecontroller.Ifauthentication
failsand/
ortheassessmentresultsindicateanoncompliantendsystem,theNACControllercaneither
denytheendsystemaccesstothenetwork,quarantinethe endsystemwithahighlyrestrictiveset
ofnetworkresources,orpermitnetworkaccessbyspecifyingaparticularpolicy.
Vue de la page 30
1 2 ... 26 27 28 29 30 31 32 33 34 35 36 ... 97 98

Commentaires sur ces manuels

Pas de commentaire