Enterasys-networks 9034385 Manuel d'utilisateur Page 34

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 33
Model 4: End-System Authorization with Assessment and Remediation
2-12 NAC Deployment Models
Required and Optional Components
ThissectionsummarizestherequiredandoptionalcomponentsforModel3.
.
TheNACGatewayandNACControlleraretheNACappliancesusedtoimplementtheoutof
bandandinlinenetworkaccesscontrolfunctionalityonthenetwork.
NetSightNACManageristhesoftwareapplicationusedtocentrallymanagetheNACappliances
deployedonthenetwork.
NetSightConsoleisthesoftwareapplicationusedto
monitorthehealthandstatusof
infrastructuredevicesinthenetwork,includingswitches,routers,andEnterasysNACappliances
(NACGatewaysandNACControllers).
Assessmentfunctionalityisrequiredbecauseinthisdeploymentmodel,connectingendsystems
arebeingassessedforsecurityposturecompliance.
ARADIUSserverisonlyrequiredifoutof
bandnetworkaccesscontrolviatheNACGatewayis
implementedwithwebbasedand/or802.1Xauthentication.
NetSightPolicyManagerisrequiredforallinlineNACdeployments,andrecommendedforout
ofbandNACdeploymentsthatutilizeEnterasyspolicycapableswitches.PolicyManager
providestheabilitytocentrallydefineandconfigurethe
authorizationlevelsorpolicies.
NetSightInventoryManagerisanoptionalcomponent,providingcomprehensivenetwork
inventoryandchangemanagementcapabilities.
Model 4: End-System Authorization with Assessment and
Remediation
ThisNACdeploymentmodelimplementsallfiveNACfunctions:detection,authentication,
assessment,authorization,andremediation.InModel3,endsystemsandendusersconnectedto
thenetworkareauthorizedbasedonthedeviceidentity,useridentity,location,and/orsecurity
postureinformation.And,asexplainedinModel3,itwasnotnecessary
toquarantine
noncompliantendsystemswhilephasingintheNACsolutiononthenetwork.However,oncea
restrictiveauthorizationlevelisallocatedtononcompliantendsystems,itisimportanttoinform
theenduseroftherestrictionsandprovidethestepstheycanexecuteforselfrepairofthedevice.
Thisistheprocessofassistedremediation,whichistheNACfunctionintroducedinModel4.
Table 2-3 Component Requirements for Authorization with Assessment
Component
Authorization with
Assessment
NAC Appliance Required
NetSight NAC Manager Required
NetSight Console Required
Assessment Service Required
RADIUS Server Optional
NetSight Policy Manager Optional
NetSight Inventory Manager Optional
Vue de la page 33
1 2 ... 29 30 31 32 33 34 35 36 37 38 39 ... 97 98

Commentaires sur ces manuels

Pas de commentaire