Enterasys-networks 9034385 Uživatelský manuál Strana 87

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 86
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-23
Itisimportanttonotethatonly theNACGatewaysthatareconfiguredwithremediationand
registrationfunctionalityneedtobepositionedinsuchamanner.AllotherNACGatewaysmay
bepositionedatanylocationonthenetwork,withtheonlyrequirementbeingthataccesslayer
switchesareableto
communicatetothegateways.Typically ,theNACGatewaywithremediation
andregistrationfunctionalityispositionedonanetworksegmentdirectlyconnectedtothe
distributionlayerroutersontheenterprisenetwork,sothatanyHTTPtrafficsourcedfrom
quarantinedendsystemsthatareconnectedtothenetworkʹsaccesslayercan
beredirectedtothat
NACGateway.Asanalternative,theNACGatewaymaybepositionedonanetworksegment
directlyconnectedtotherouterprovidingconnectivitytotheInternetorinternalwebserverfarm.
Inthisscenario,theHTTPtrafficsourcedfromquarantinedendsystemswouldberedirectedto
theNAC
GatewaybeforereachingtheInternetorinternalwebservers.
4. Identify Backend RADIUS Server Interaction
IfaNACGatewayisreceiving802.1Xand/orwebbasedauthenticationrequestsforconnecting
endsystems,thenabackendRADIUSservermustbeconfiguredtovalidateendusercredentials
intheauthenticationprocess.ForeachNACGateway,aprimaryandsecondaryRADIUSserver
canbespecifiedforthevalidationofuser/device
networklogincredentialsonthenetwork.
If802.1X,webbased,orRADIUSauthenticationforswitchmanagementloginsisimplemented,a
RADIUSserverwithbackenddirectoryservicesmustbedeployedonthenetwork.ARADIUS
serverisnotnecessaryifonlyMACauthenticationisdeployedonthenetwork.
AllRADIUSserverssupporting
RFC2865andsubsequentRADIUSstandardsaresupportedby
EnterasysNACapplianceswhenproxyingRADIUSauthenticationrequests.Testshavebeen
conductedonthefollowingRADIUSservers:
FreeRADIUS
•MicrosoftIAS
•FunkSteelbeltedRADIUS
•CiscoACS
5. Determine End-System Mobility Restrictions
WhileSecurityDomainspecificMACanduseroverridescanbeconfiguredtocontrolendsystem
andendusermobilityacrossthenetworkandbetweenSecurityDomains,the“LockMAC”
featureallowsthenetworkadministratortorestrictnetworkaccessforspecificendsystemtoa
switchportorswitch.Theendsystem
canbedeniednetworkaccesswithaRADIUSAccessReject
messagereturnedtotheswitch,orassignedaspecificpolicyorVLANwhenconnectingtothe
networkinarestrictedarea.HerearesomeexamplesofhowtheLockMACfeaturecanbeused:
•Aprinter,server,orotherendsystem
couldbeallowednetworkaccessonlywhenitis
connectedtoaports p ecifiedbyIToperations.Thispreventssecurityissuesthatcouldresultif
thedevicewasmovedtoadifferentareaofthenetwork.
•AnIPphonewithaMACoverridecouldbelockedtoaspecificporton
aswitch.Thiswould
allowexactidentificationofthephoneʹslocationincaseanemergency(911)callwasplaced
fromthephone.
Zobrazit stránku 86
1 2 ... 82 83 84 85 86 87 88 89 90 91 92 ... 97 98

Komentáře k této Příručce

Žádné komentáře