Enterasys-networks 9034385 Manuel d'utilisateur Page 54

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 53
Survey the Network
4-2 Design Planning
accesstoawebbrowsertosafelyremediatetheirquarantinedendsystemwithoutimpacting
IToperations.
Onceadeploymentmodelisselected,thecurrentnetworkinfrastructuremustbeexaminedto
identifythetechnicaldependenciesandrequirementsimposedbytheNACsolution.
Survey the Network
Thestepsinthissectionwillhelpyouidentifyandevaluatethecurrentnetworkinfrastructureso
thatyoucanmakedesigndecisionsregardingNACcomponentrequirements.
1. Identify the Intelligent Edge of the Network
Thefirststepinsurveyingyournetworkistodeterminewhetherornotyournetworkhasan
“intelligentedge.”ThisinformationwillhelpyoudecidewhethertheNACGatewayorNAC
Controllerappliancebestsuitsyournetworkinfrastructure.
Theterm“intelligent”referstoanetworktopologywheretheaccessedgeis
composedof
Enterasyspolicyenabledswitchescapableofsupportingauthenticationandpolicyenforcement,
orthirdpartyswitchescapableofsupportingauthenticationanddynamicVLAN assignmentas
definedinRFC3580.
Nonintelligentinfrastructuredevices,suchasrepeatersandhubs,arenotcapableofsupporting
authenticationand/orauthorizat ion ofendsystems,and
simplyprovideconnectivitytothe
infrastructure.
AnintelligentedgeisrequiredwhentheNACGatewayisutilizedforimplementingoutofband
NAC.TheNACGatewayapplianceleveragestheintelligentedgeof thenetworktoimplementthe
authenticationandauthorizationofconnectingendsystems.TheNACGatewayeffectsthe
assignmentof
policiesorVLANsonEnterasysswitchesorRFC3580capableswitcheslocatedat
edgeofthenetwork,toauthorizealevelofnetworkaccesstoconnectingendsystems.These
assignmentsarebasedonvariousparameters,suchasthelocationoftheendsystemandsecurity
postureassessmentresults.Theintelligentedge
ofthenetworkalsoimplementsanauthentication
method(802.1X,webbased,orMACauthentication)forvalidatingthedeviceand/oruseridentity
ofconnectingendsystems.
However,innetworkswithnonintelligentdevicesattheaccessedge,itisnotnecessarytoreplace
thesenonintelligentdevicestobeabletoimplement
outofbandNACwiththeNACGateway.
Instead,theEnterasysMatrixNseriesswitchcanbepositionedupstreamfromnonintelligent
devices(suchasinthedistributionlayer)toimplementtheauthenti cationandauthorization
functionsfordownstreamconnecteddevices.MatrixNSeriesdevicessupportMultiUser
Authentication(MUA)which
enablestheswitchtoindividuallyauthenticateanduniquely
authorizemultipleendsystemsconnectedtothesamephysicalport.MUAontheMatrixNseries
Platinumsupportstheconcurrentauthenticationandauthorizationofover1000endsystemsona
singleportwiththeallocationofdisparatenetworkresourcestoeachendsystem.
Inthiscase,the
MatrixNseriesswitchistheintelligentedgeofthenetworkalthoughitisnotphysicallylocatedin
theaccesslayer.ByutilizingtheMatrixNseriesinthistypeofconfiguration,mostofthebenefits
ofoutofbandNACcanbeobtainedwithoutupgrading
theedgeofthenetwork.
Vue de la page 53
1 2 ... 49 50 51 52 53 54 55 56 57 58 59 ... 97 98

Commentaires sur ces manuels

Pas de commentaire