Enterasys-networks 9034385 Manuel d'utilisateur Page 90

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 89
Out-of-Band NAC Design Procedures
5-26 Design Procedures
Figure 5-6 Policy Role Configuration in NetSight Policy Manager
Assessment Policy
TheAssessmentPolicymaybeusedtotemporarilyallocate asetofnetworkresourcestoend
systemswhiletheyarebeingassessed.ForEnterasyspolicyenabledswitches,acorresponding
policyrole(createdinPolicyManager)shouldallocatetheappropriatesetofnetworkresources
neededbytheassessmentservertosuccessfullycomplete
itsendsystemassessment,while
restrictingtheendsystemʹsaccesstothenetwork.Forexample,iftheassessmentserveris
configuredtoscanforFTPvulnerabilities,andtheAssessmentPolicydoesnotallowFTPtr affic
fromtheendsystemontothenetwork,thentheassessmentserverwillnotdetect
theFTP
vulnerabilitiesontheendsystem.
Toachievethistradeoff,theAssessingpolicyrolecanbeconfiguredbydefaulttodenyalltraffic,
andbeassociatedtoclassificationrulesthatpermittraffictoallassessmentservers,using
destinationIPaddressPermitclassificationrules,asshowninFigure57.
Therefore,alltraffic
involvedwiththeendsystemʹsassessmentisallowedontothenetwork.Inaddition,otherbasic
networkservicessuchasARP,DHCP,andDNSareallowedontothenetworksotheendsystem
canestablishIPconnectivityinthenetworkwhilebeingassessed.
TheAssessmentPolicycanalso
beconfiguredtoimplementwebnotificationduringtheexecution
oftheassessment,toinformtheenduserthataccesstothenetworkhasbeentemporarily
restrictedwhiletheassessmenttakesplace.ThisisimplementedbyallowingHTTPtrafficontothe
networkinadditiontotheotherservicespreviouslydescribe d.
Vue de la page 89
1 2 ... 85 86 87 88 89 90 91 92 93 94 95 96 97 98

Commentaires sur ces manuels

Pas de commentaire