Enterasys-networks 9034385 Uživatelský manuál Strana 92

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 91
Inline NAC Design Procedures
5-28 Design Procedures
Figure 5-8 Service for the Quarantine Role
Furthermore,theQuarantinePolicyandothernetworkinfrastructuredevicesmustbeconfigured
toimplementHTTPtrafficredirectionforquarantinedendsystemstoreturnwebnotificationof
thequarantinedstateofanendsystem.
Unregistered Policy
IfMAC(network)registrationisconfiguredintheNACdeployment,an“Unregistered”policy
canbeassignedtoconnectingendsystemswhiletheyareunregisteredonthenetwork.This
policymustbeconfiguredtoallowbasicservicessuchasARP,DNS,DHCP,andtoimplement
HTTPtrafficredirectiontoreturnwebbased
notificationforunregist eredendsystems.(Because
thisconfigurationissimilartotheQuarantinePolicyandtheAssessmentPolicy,thosepolicies
couldbeassignedtounregisteredendsystems,ifdesired).
Inline NAC Design Procedures
ThefollowingsectioncontinuestheEnterasysNACdesignprocedurewithstepsspecifically
relatingtotheimplementationofinline NACwiththeNACController.
1. Determine NAC Controller Location
BecausetheNACControllerisplacedinlinewithtrafficsourcedfromconnectingendsystems,the
locationofNACControllersisdirectlydependentonthenetworktopology.NACControllersare
typicallyplacedbetweentheedgewhereendsystemsconnecttothenetwork(forexample,the
wiredandwirelessaccessedge,orthe
remoteaccessedgebehindaVPNconcentrator)andthe
networkʹscoreanddatacenterwheremissioncriticalinfrastructureresourcesreside.Thisway,
noncompliantendsystemscanberestrictedfromcommunicatingtomissioncriticalresources.
WiththeNACControlleractingastheauthorizationpointfortrafficenforcementwithinline
NAC,there
isafundamentaltradeoffwhenpositioningtheNACControllerinthenetwork
topology:theclosertheNACControllerisplacedtotheedgeofthenetwork,thehigherthelevel
ofsecurityisachieved,inthatendsystemsareauthorizedclosertothepointofconnectionand
endsystems
deemednoncomplianthaveaccesstoasmallersetofnetworkresources.
Zobrazit stránku 91
1 2 ... 87 88 89 90 91 92 93 94 95 96 97 98

Komentáře k této Příručce

Žádné komentáře