Enterasys-networks 9034385 Bedienungsanleitung Seite 29

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 28
Model 2: End-System Authorization
Enterasys NAC Design Guide 2-7
apasswordintheregistrationwebpage.Thissponsorusernameandpasswordcanbe
validatedagainstanexistingdatabaseonthenetworktoauthenticatethesponsorʹsidentity.
Sponsorsmaybeallowedtosecurelyaccessanadministrativewebpagewheretheycan
delete,add,andmodifyregisteredendsystemsonthe
networkthattheyhavesponsored.
Withsponsoredregistrationenabled,IToperationscanholdtrustedusersaccountablefor
guestsbroughtontheenterprisenetwork,whilecontrollingaccessforonlyappropriate
guests.
Post-Connect NAC integration with NetSight Automated Security Manager
NetSightAutomatedSecurityManager(ASM),asoftwareapplicationthatispartofthe
NetSightSuite,hasthecapabilitytosearchtheinfrastructureandlocatetheswitchportof
connection,basedonthereceiptofasecurityeventforaparticularIPaddress.ASMresponds
tothiseventbydisablingtheport
orassigningaVLAN(suchasthequarantineVLAN)tothe
port.Inresponsetoarealtimesecuritythreatdetectedonthenetwork,ASMcanbe
configuredtonotifyNACManageronthisevent,dynamicallyquarantiningtheMAC
address.Thiseffectivelyrestrictsthequarantinedendsystemfromaccessingthe
network
fromanylocation,enterprisewide.IfASMreversesthequarantineaction,itnotifiesNAC
Manager,andthequarantineisautomaticallyremovedandtheendsystemisdynamicallyre
admittedaccesstonetworkresources.Therefore,thedeploymentofEnterasysNACfurther
increasesthesecuritypostureofthenetworkbyintegratingwith
thereactivethreatresponse
capabilitiesofASM,inadditiontocontrollingaccessandauthorizingconnectingdevices.
Required and Optional Components
ThissectionsummarizestherequiredandoptionalcomponentsforModel2.
.
TheNACGatewayandNACControlleraretheNACappliancesusedtoimplementtheoutof
bandandinlinenetworkaccesscontrolfunctionalityonthenetwork.
NetSightNACManageristhesoftwareapplicationusedtocentrallymanagetheNACappliances
deployedonthenetwork.
NetSightConsoleisthesoftwareapplicationusedto
monitorthehealthandstatusof
infrastructuredevicesinthenetwork,includingswitches,routers,andEnterasysNACappliances
(NACGatewaysandNACControllers).
Assessmentfunctionalityisoptionalbecauseinthisdeploymentmodel,endsystemsarenotbeing
assessedforsecurityposturecompliancewhenconnectingtothenetwork.
Table 2-2 Component Requirements for Authorization
Component Authorization
NAC Appliance Required
NetSight NAC Manager Required
NetSight Console Required
Assessment Optional
RADIUS Server Optional
NetSight Policy Manager Optional
NetSight Inventory Manager Optional
Seitenansicht 28
1 2 ... 24 25 26 27 28 29 30 31 32 33 34 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare