Enterasys-networks 9034385 Uživatelský manuál Strana 57

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 56
Survey the Network
Enterasys NAC Design Guide 4-5
tolocallyauthorizeallMACauthenticationrequestsforconnectingendsystems,therebynot
requiringalistofknownMACaddresses.Infact,EnterasysNACcanbeconfiguredina“learning
mode”todynamicallylearntheMACaddressesofalldevicesconnectingtothenetwork,
permittingnetworkaccesstoallofthese
endsystemsforaperiodoftime.
AftertheMACaddressesarelearned,NACcanbereconfiguredtopermitaccessonlytothese
endsystems,requiringallotherdevicesconnectingtothenetworktogothrougharegistration
process.
WithMACauthenticationdeployedonthenetwork,abackendRADIUSserver
withassociated
directoryservicesisnotrequired,simplifyingtheimplementation.Furthermore,becauseMAC
authenticationonlyrequirestheendsystemtogenerateanEthernetpacketontothenetwork,both
humancentricandmachinecentricendsystemshavethecapabilitytoauthenticatetothe
network,regardlessofwhethertheendsystemisa
PCoraprinter.
Case #2: Authentication methods are deployed on the network.
Ifauthenticationiscurrentlydeployedonthenetworkwith802.1X,webbased,and/or MAC
authentication,thenaRADIUSserverwithassociatedbackenddirectoryservicesmustbe
deployedforuser/device802.1Xand webbasedcredentialvalidation.Moreover,ifRADIUS
authenticationforswitchmanagementloginsisimplemented,aRADIUSservermustbedeployed
onthenetwork.Inthisscenario,outofbandNACisconfiguredtoseamlesslyproxyRADIUS
authenticationrequestsreceivedfromtheswitchesattheintelligentedgeofthenetworktothe
backendRADIUSserver,withoutrequiringcomplexconfigurationchangestotheRADIUSserver
andassociateddirectoryservices.Inaddition,NAC
canalsobeconfiguredtolocallyauthorize
MACauthenticationrequests.
Overview of Supported Authentication Methods
FollowingisanoverviewofauthenticationmethodssupportedbyEnterasysandsomethirdparty
switches,andproxiedbyoutofbandNAC.
802.1XAuthentication
TheIEEE802.1Xstandardforportbasednetworkaccesscontrol,providesnetworkadministrators
withtheabilitytoauthenticateandauthorizeanenduserattheportlevel.
The
802.1XauthenticationmethodisusuallyimplementedonPCsinsecureenvironmentsand
requiresthattheendsystemimplementan802.1X supplicant,whichisspecialsoftwarethat
communicatesinthisprotocol.
Because802.1Xrequirestheinputofusercredentials,802.1Xisnormallyusedonusercentricend
systemsthathaveaconcept
ofanassociateduser,suchasaPC.Therefore,thisauthentication
methodmaybeinappropriateformachinecentricdevices,suchasprintersandIPcameras.
However,newersoftwarereleasesforIPphonesmayincludean802.1Xsupplicant.
SinceEnterasysNAConlyactsasapassthroughtoanupstreamRADIUSServer,
itismandatory
thatafullauthenticationdeploymentisconfiguredonthenetworkif802.1Xisused.
WebBasedAuthentication
Webbasedauthentication,orPortWebAuthentication(PWA),isanauthenticationprocessthat
usesawebbrowser,userloginprocesstogainaccesstoports.ItemployseitherCHAP(Challenge
Handshake
AuthenticationProtocol)orPAP(PasswordAuthenticationProtocol).
Sincewebbasedauthenticationonlyrequiresthatawebbrowserisontheendsystem,itis
deployedinheterogeneousenvironmentswherecertainendsystemsmaynothavean802.1X
supplicantinstalled.
Zobrazit stránku 56
1 2 ... 52 53 54 55 56 57 58 59 60 61 62 ... 97 98

Komentáře k této Příručce

Žádné komentáře