Enterasys-networks 9034385 Uživatelský manuál Strana 93

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 92
Inline NAC Design Procedures
Enterasys NAC Design Guide 5-29
However,theclosertheNACControllerisplacedtotheedgeofthenetwork,themoreNAC
Controllersarerequiredonthenetwork,increasingNACdeploymentcostandcomplexity.
Conversely,whenmovingtheNACControllertowardsthecoreofthenetwork,fewerNAC
Controllersarerequired,decreasingNACdeploymentcostand
complexity, butalsodecreasing
thelevelofsecurity.
ForimplementingNAConwiredandwirelessLANs,itisrecommendedthattheLayer2NAC
Controllerispositionedbetweentheaccesslay eranddistributionlayerbeforethefirstroutedhop
inthenetwork.Asanalternative,theNACControllermaybepositioned
deeperintothenetwork
afterthefirstroutedhopusingtheLayer3configuration.TheLayer3NACControllercanalsobe
positionedafteraVPNconcentratororWANconnectiontoimplementNACforremoteusers.
UnliketheoutofbandNACdesign,theimplementationofremediationand/orMAC(network)
registrationdoesnotaffectthelocationoftheNACController.TheNACControllerwill
appropriatelyinterceptwebtrafficforthepurposeofremediationandregistration.
Lastly,itshouldbeunderstoodthatsomeadva ntagesexistwiththedeploymentofaLayer2NAC
ControlleroveraLayer3NACController,whichmay
affectthedecisionofhowNACControllers
arepositioned.WhileaLayer2NACControlleralwaysknowstheMACaddressofthe
downstreamconnectedendsystem,theLayer3NACControllermaynotbeabletodeterminethe
MACaddressofadownstreamendsystem(denotedas“Unknown”inNACManager.)
TechniquessuchasNetBIOSlookupsandDHCPsnoopingareimplementedtoattempttoresolve
theIPaddressofthedownstreamconnectedendsystems;however,scenariosexistwheretheIP
addressofthedownstreamendsystemmaynotbedetermined.
TheMACaddressofadownstreamendsystemwillbedetermined
bytheNACControllerinthe
followingscenarios:
•EndsystemssupportNetBIOSandahostfirewalldoesnotdropinboundNetBIOS requests
fortheLANconnection.
•DHCPisimplementedandtheDHCPserverexistsupstreamfromtheNACController.
SincetheLayer3NACControllermaynotbeabletodeterminethe
MACaddressofa
downstreamendsystem,“LockMAC”andMACoverridesarenotapplicabletoLayer3NAC
Controllers.Furthermore,MAC(network)registrationmaynotbeimplementedwhentheMAC
addressofadownstreamconnectedendsystemisunknown.Inthiscase,theendsystemis
assignedtheSecurityDomain’s
defaultNACconfiguration.
Zobrazit stránku 92
1 2 ... 88 89 90 91 92 93 94 95 96 97 98

Komentáře k této Příručce

Žádné komentáře