Enterasys-networks 9034385 Manuel d'utilisateur Page 35

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 34
Model 4: End-System Authorization with Assessment and Remediation
Enterasys NAC Design Guide 2-13
Assistedremediationinformsenduserswhentheirendsystemshavebeenquarantineddueto
networksecuritypolicynoncompliance,andallowsenduserstosafelyremediatetheirnon
compliantendsystemswithoutassistancefromIToperations.Theprocesstakesplacewhenan
endsystemconnectstothenetworkandassessmentis
performed.Enduserswhosesystemsfail
assessmentarenotifiedviawebredirectionthattheirsystemshavebeenquarantined,andare
instructedinhowtoperformselfserviceremediationspecifictothedetectedcompliance
violations.
Oncetheremediationstepshavebeensuccessfullyperformedandtheendsystemiscompliant,
theend
usercaninitiateanondemandreassessmentoftheendsystemandcanbeallocatedthe
appropriatenetworkresources,againwithouttheinterventionofIToperations.
Implementation
InModel4,endsystemscanbedetected,authenticated,assessed,authorized,andremediatedin
differentwaysdependingonthewhetherinlineoroutofbandnetworkaccesscontrolis
implementedintheEnterasysNACsolution.
Out-of-Band NAC
ForoutofbandEnterasysNACdeploymentsutilizingtheNACGateway,NACfunctionsare
implementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐AsdescribedinModel3.
Authorization‐AsdescribedinModel3.
Remediation‐WhenendsystemsarequarantinedbytheNACGateway,
thenetworkmustbe
configuredtodirectalltrafficfromthequarantinedendsystemstotheNACGateway.Thiscanbe
implementedbyconfiguringpolicybasedroutingonarouterinlinewiththetrafficsourcedfrom
quarantinedendsystems.Thisrouterwouldbeconfiguredtosendallwebtrafficfrom
quarantined
endsystemstotheNACGateway,whichthenservesbacktheremediationwebpage
totheenduser.
Thewaytherouteridentifiesthetrafficfromquarantinedendsystemsdiffersbetweenanetwork
composedofpolicyenabledswitchesintheaccessedgeoranetworkcomposedofswitches
implementingRFC
3580dynamicVLANassignmentintheaccessedge.ForanEnterasyspolicy
enablededge,theQuarantinepolicycanbeconfiguredtorewritetheTypeofService(ToS)valueof
HTTPtraffictoaparticularsettingthatmatchesthepolicybasedroutingconfiguration.Foran
RFC3580capableedge,thepolicybased
routingwouldbeconfiguredtomatchthesourceIP
addressoftheHTTPtrafficbeinggeneratedfromthesubnetsthatcorrespondstotheQuarantine
and/orAssessingVLAN.Ineithercase,bydirectingtheHTTPtrafficfromquarantinedend
systemsovertotheNACGateway,theNACGatewaywillserveback
theremediationwebpageto
thenoncompliantendsy stem.
Vue de la page 34
1 2 ... 30 31 32 33 34 35 36 37 38 39 40 ... 97 98

Commentaires sur ces manuels

Pas de commentaire