Enterasys-networks 9034385 Manuel d'utilisateur Page 50

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 49
Scenario 4: VPN Remote Access
3-12 Use Scenarios
Figure 3-6 VPN Remote Access
Scenario 4 Implementation
IntheVPNremoteaccessusescenario,thefiveNACfunctionsareimplementedinthefollowing
mannerwiththedeploymentoftheNACControllerforinlinenetworkaccesscontrol.
1.Detection‐TheuserʹsendsystemsuccessfullyestablishesaVPNtunnelwiththeVPN
concentrator,andtheVPNconcentratortransmitsunencrypted
datatrafficontothenetworkthat
traversestheNACController.ThistrafficissourcedfromanIPaddressnotpreviously seenbythe
controller.
2.Authentication‐AuthenticationismostlikelydisabledaltogetherontheNACController,
trustingthatthedownstreamVPNconcentratorauthenticatedtheconnectinguser.
3.Assessment‐TheNACControllerrequests
anassessmentoftheendsystemaccordingto
predefinedsecuritypolicyparameters.Theassessmentcanbeagentbasedoragentless,andis
executedlocallybytheNACControllerʹsassessmentfunctionalityand/orremotelybyapoolof
assessmentservers.
4.Authorization‐Onceauthenticationandassessmentarecomplete,theNACController
allocatestheappropriatenetworkresourcestotheendsystembasedonauthenticationand/or
assessmentresults.ThisisimplementedlocallyontheNACControllerbyassigningapolicyto
trafficsourcedfromtheendsystem.Ifauthenticationfailsand/ortheassessmentresultsindicatea
noncompliantendsystem,theNACControllercan
eitherdenytheendsystemaccesstothe
network,orquarantinetheendsystembyassigningaparticularpolicyonthecontroller.
1
3
3
5
Enterasys
NAC Manager
NAC
Controller
(inline appliance)
Assessment
Server
Role=Quarantine
1
2
3
4
5
NAC Functions
Detect
Authenticate
Assess
Authorize
Remediate
VPN Concentrator
Remediation
Web Page
3
4
Vue de la page 49
1 2 ... 45 46 47 48 49 50 51 52 53 54 55 ... 97 98

Commentaires sur ces manuels

Pas de commentaire