Enterasys-networks 9034385 Uživatelský manuál Strana 69

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 68
Procedures for Out-of-Band and Inline NAC
Enterasys NAC Design Guide 5-5
•Howhealthresultsareprocessed.
Whenanassessmentisperformedonanendsystem,a“healthresult”isgenerated.Foreach
healthresult,theremaybeseveral“healthresultdetails.”Ahealthresultdetailisaresultfor
anindividualtestperformedduringtheassessment.Eachhealthresultdetailisgiven
ascore
rangingfrom1to10,andbasedonthisscore,thehealthresultisassignedarisklevel.
However,itispossibletooverridethescorewithadifferentvaluethatbetteralignsthescore
withtheenterpriseʹscompliancepolicy. Forexample,Wiresharkisapopularnetworktraffic
analysisapplicationthatcanbeusedforbothinformationalandmaliciousintentions.IfIT
operationsdeterminesthatWiresharkisanapplicationthatshouldnotbeinstalledonend
systemsconnectingtothenetwork,ascoringoverridecanbeconfiguredtoassociateahigh
riskscoreifWiresharkisdetectedon
anendsystem.
•Whichendsystemsarequarantined.
NACManagerusesrisklevelstodeterminewhetherornotanendsystemwillbe
quarantined.Basedonthescoresfromthehealthresultdetails,endsystemareclassifiedinto
oneoffourrisklevels:highrisk,mediumrisk,lowrisk,andnorisk.
Dependingontherisk
leveltowhichtheendsystemisclassified,theendsystemmaybequarantined.
Authorization
TheNACconfigurationalsospecifiestheauthorizationlevels,referredtoas“accesspolicies,”that
willbeappliedtotheendsystem,dependingontheauthenticationandassessmentresults.
AcceptPolicythepolicythatisassignedtocompliantendsys tems.
•QuarantinePolicy–thepolicythatisassignedtononcompliantendsystems
thathavefailed
assessment.
AssessmentPolicythepolicythatis(optionally) assignedtoendsystemswhiletheyare
beingassessed.
FailsafePolicythepolicythatisassignedtoendsystemswhenanerroroccursintheNAC
process.
Zobrazit stránku 68
1 2 ... 64 65 66 67 68 69 70 71 72 73 74 ... 97 98

Komentáře k této Příručce

Žádné komentáře