Enterasys-networks 9034385 Manuel d'utilisateur Page 88

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 87
Out-of-Band NAC Design Procedures
5-24 Design Procedures
6. VLAN Configuration
ThisstepisforNACdeploymentsthatuseRFC3580compliantswitchesintheintelligentedgeof
thenetworktoimplementdynamicVLANassignmentofconnectingdevices.
NACleveragesVLANTunnelRADIUSattributemodificationinRADIUSauthentication
messagesfornetworkresourceallocationtoendsystemsconnectedtotheseRFC3580compliant
switches.ThisrequiresthatbeforeNACisdeployedonthenetwork,eachRFC3580compliant
switchintheintelligentedgeofthenetworkisconfiguredwiththeappropriateVLANsthatmay
bereturnedfromtheNACGateways.AlistofVLANsthatmaybeassignedtoconnectingend
systemsforeach
SecurityDomainmustbegeneratedbyanalyzingtheAcceptPolicy,Assessment
Policy,FailsafePolicy,andQuarant inePolicyofthefollowing NACconfigurations:
•TheSecurityDomains’defaultNACconfigurations
•MACoverridesfortheSecurityDomains
•UseroverridesfortheSecurityDomains
•GlobalMACanduseroverrides
7. Policy Role Configuration
ThisstepisforNACdeploymentsthatuseEnterasyspolicyenabledswitchesintheintelligent
edgeofthenetworktoimplementdynamicpolicyassignmentofconnectingdevices.
NACleveragesFilterIDRADIUSattributemodificationinRADIUSauthenticationmessagesfor
networkresourceallocationtoendsystemsconnectedtotheseEnterasysswitches.Therefore,
beforeNACisdeployedonthenetwork,eachEnterasysswitchintheintelligentedgeofthe
networkmustbeconfiguredwiththeappropriatepolicyrolesthatmaybereturnedfromtheNAC
Gateways.AlistofpolicyrolesthatmaybeassignedtoconnectingendsystemsforeachSecurity
Domain
canbegeneratedbyanalyzingtheAcceptPolicy,AssessmentPolicy,FailsafePolicy,and
QuarantinePolicyofthefollowingNACconfigurations:
•TheSecurityDomains’defaultNACconfiguration
•MACoverridesfortheSecurityDomains
•UseroverridesfortheSecurityDomains
•GlobalMACanduseroverrides
8. Define NAC Access Policies
AccesspoliciesdefinetheauthorizationlevelthatNACassignstoaconnectingendsystembased
ontheendsystemʹsauthenticationand/orassessmentresults.Therearefouraccesspoliciesused
inNACManager:FailsafePolicy,AcceptPolicy,QuarantinePolicy,andAssessmentPolicy.Inyour
securitydomainandoverrideconfigurations,theseaccess
policiesdefineasetofnetworkaccess
servicesthatdetermineexactlyhowanendsystemʹstrafficisauthorizedonthenetwork.
WhenEnterasyspolicyenabledswitchesaredeployedintheintelligentedgeofthenetworkto
authenticateandauthorizeconnectingendsystems,theseswitchesmustbeconfiguredwith
access
policiesbeforeNACisdeployed.NetSightPolicyManagerenablestheenterprisewide
deploymentofpolicyrolestoEnterasyspolicyenabledswitches,withasingleclick.
Inadditiontotheenterpriseʹsbusinessspecificroles,suchas“Faculty”or“Sales,”NACpolicy
rolesmustbedefined,configured,andenforcedtothenetwork
forNAC.Allpolicyroles
Vue de la page 87
1 2 ... 83 84 85 86 87 88 89 90 91 92 93 ... 97 98

Commentaires sur ces manuels

Pas de commentaire