Enterasys-networks 9034385 Bedienungsanleitung Seite 35

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 34
Model 4: End-System Authorization with Assessment and Remediation
Enterasys NAC Design Guide 2-13
Assistedremediationinformsenduserswhentheirendsystemshavebeenquarantineddueto
networksecuritypolicynoncompliance,andallowsenduserstosafelyremediatetheirnon
compliantendsystemswithoutassistancefromIToperations.Theprocesstakesplacewhenan
endsystemconnectstothenetworkandassessmentis
performed.Enduserswhosesystemsfail
assessmentarenotifiedviawebredirectionthattheirsystemshavebeenquarantined,andare
instructedinhowtoperformselfserviceremediationspecifictothedetectedcompliance
violations.
Oncetheremediationstepshavebeensuccessfullyperformedandtheendsystemiscompliant,
theend
usercaninitiateanondemandreassessmentoftheendsystemandcanbeallocatedthe
appropriatenetworkresources,againwithouttheinterventionofIToperations.
Implementation
InModel4,endsystemscanbedetected,authenticated,assessed,authorized,andremediatedin
differentwaysdependingonthewhetherinlineoroutofbandnetworkaccesscontrolis
implementedintheEnterasysNACsolution.
Out-of-Band NAC
ForoutofbandEnterasysNACdeploymentsutilizingtheNACGateway,NACfunctionsare
implementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐AsdescribedinModel3.
Authorization‐AsdescribedinModel3.
Remediation‐WhenendsystemsarequarantinedbytheNACGateway,
thenetworkmustbe
configuredtodirectalltrafficfromthequarantinedendsystemstotheNACGateway.Thiscanbe
implementedbyconfiguringpolicybasedroutingonarouterinlinewiththetrafficsourcedfrom
quarantinedendsystems.Thisrouterwouldbeconfiguredtosendallwebtrafficfrom
quarantined
endsystemstotheNACGateway,whichthenservesbacktheremediationwebpage
totheenduser.
Thewaytherouteridentifiesthetrafficfromquarantinedendsystemsdiffersbetweenanetwork
composedofpolicyenabledswitchesintheaccessedgeoranetworkcomposedofswitches
implementingRFC
3580dynamicVLANassignmentintheaccessedge.ForanEnterasyspolicy
enablededge,theQuarantinepolicycanbeconfiguredtorewritetheTypeofService(ToS)valueof
HTTPtraffictoaparticularsettingthatmatchesthepolicybasedroutingconfiguration.Foran
RFC3580capableedge,thepolicybased
routingwouldbeconfiguredtomatchthesourceIP
addressoftheHTTPtrafficbeinggeneratedfromthesubnetsthatcorrespondstotheQuarantine
and/orAssessingVLAN.Ineithercase,bydirectingtheHTTPtrafficfromquarantinedend
systemsovertotheNACGateway,theNACGatewaywillserveback
theremediationwebpageto
thenoncompliantendsy stem.
Seitenansicht 34
1 2 ... 30 31 32 33 34 35 36 37 38 39 40 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare