Enterasys-networks 9034385 Uživatelský manuál Strana 96

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 98
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 95
Inline NAC Design Procedures
5-32 Design Procedures
3. Identify Backend RADIUS Server Interaction
Layer2NACControllersdetectdownstreamendsystemsviaauthentication:MAC,webbased,or
802.1X.Ifwebbasedor802.1X authenticationisimplemented,thenabackendRADIUSserver
mustbeconfiguredtovalidateendusercredentialsintheauthenticationprocess.Foreach Layer2
NACController,primaryandsecondaryRADIUSservers
maybespecifiedforthevalidationof
user/devicenetworklogincredentialsonthenetwork.
4. Define Policy Configuration
PoliciesareassignedtodownstreamendsystemsontheNACControllertoauthorizeconnecting
deviceswithalevelofnetworkaccess.Adefaultsetofpoliciesareautomaticallyconfiguredon
eachNACControllerafterinstallationandinitializationoftheappliance.Thissetofpolicies
includesallpoliciesdefinedbydefaultin
NACManager,suchasEnterpriseUser,Quarantine,
Assessing,Unregistered,andFailsafe.Itisstronglyrecommendedthatthepolicyconfigurations
ofallNACControllersareimportedintoNetSightPolicyManager,reviewed,andappropriately
modified,priortothefullrolloutofinlineNAC.
Failsafe Policy and Accept Policy Configuration
TheFailsafePolicyisassignedtoendsystemswhenanerroroccursintheNACprocess.The
FailsafepolicyroleisconfiguredbydefaultontheNACControllertobeusedastheFailsafe
PolicyinNACManager.Thispolicyisrestrictive,allowingDNSandDHCP,andredirectingweb
trafficto
servebackawebpagestatinganerrorhasoccurredonthenetwork,whilediscardingall
othertypesoftraffic.
Ifitisdesiredtoopennetworkaccesswhenanerrorisencountered,theEnterpriseUserpolicy
rolecanbeselectedastheFailsafePolicyintheNACConfiguration.The
EnterpriseUserpolicy
roleisfairlyopen,permittingmosttypesofcommunicationontothenetwork.Forsecurity
purposestheEnterpriseUserpolicyroledoesdenycommunicationtotheNACControllerover
TCPandUDPports(utilizedforadministrativepurposes,suchasRADIUSandSSH).Inaddition,
theEnterpriseUserpolicydiscards
allcommunicationtoNACManagerʹsIPaddressforfurther
securityhardening.Thispolicyrolecanbealteredtofurthercontrolwhichservicesacompliant
endsystemisallowedtoutilize.
TheAcceptPolicyisassignedtoendsystemswhentheyaredeemedcompliant.TheEnterprise
Userpolicyroleisconfigured
bydefaultontheNACControllertobeusedastheAcceptPolicyin
NACManager.
Assessment Policy and Quarantine Policy Configuration
TheAssessmentPolicyandQuarantinePolicyareusedwhenendsystemassessmentis
implementedintheNACdeployment.TheAssessmentPolicymaybeusedtotemporarilyallocate
asetofnetworkresourcestoendsystemswhiletheyarebeingassessed.TheAssessingpolicyrole
isconfiguredbydefaultonNACControllers
tobeusedastheAssessmentPolicyinNAC
Manager.ThispolicyallowsDNSand DHCP,and anytrafficdestinedtotheIPaddressofthe
assessmentserversdeployedonthenetwork.Thepolicyalsoredirectswebtraffictoservebacka
webpagestatingthattheendsystemhas
beenrestrictedaccesswhileitssecuritypostureisbeing
determined.Allothertypesoftrafficarediscarded.
Ifitisdesiredtoopennetworkaccesswhileanendsystemisbeingassessed,theuseofthe
AssessmentPolicycanbedisabledintheNACconfiguration,ortheEnterpriseUserpolicyrole
canbeselectedastheAssessmentPolicyinstead.ItisimportanttonotethatwheneveraNAC
configurationisenforcedtotheNACController,theAssessmentPolicyisconfiguredtoallow
Zobrazit stránku 95
1 2 ... 91 92 93 94 95 96 97 98

Komentáře k této Příručce

Žádné komentáře