Enterasys-networks 9034385 Bedienungsanleitung Seite 46

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 45
Scenario 2: Intelligent Wireless Access Edge
3-8 Use Scenarios
Scenario 2 Implementation
Intheintelligentwirelessaccessedgeusescenario,thefiveNACfunctionsareimplementedinthe
followingmanner:
1.Detection‐Theuserʹsendsystemconnectstothenetwork.ThewirelessswitchorthickAP
sendsaRADIUSauthenticationrequest(802.1X,webbased,orMACauthentication)withthe
associatedcredentialsto
theNACGateway.
2.Authentication‐Iftheendsystemisauthenticatingtothe networkusing802.1Xorwebbased
authentication,theNACGatewayproxiestheRADIUSa uthenti cationrequesttoabackend
authentication(RADIU S)servertovalidatetheidentityoftheenduser/device.Forendsystems
thatareMACauthenticatingtothe
network,theNACGatewaymaybeconfiguredtoeitherproxy
theMACauthenticationrequeststotheRADIUSserver,orlocallyauthorizeMACauthentication
requests.IfonlyMACauthenticationisdeployedonthenetworkandtheNACGatewayis
configuredtolocallyauthorizeMACauthenticationrequests,abackendRADIUSserverisnot
requiredwiththeEnterasysNACsolution.
3.Assessment‐Aftertheidentityoftheendsystemorenduserisvalidatedviaauthentication,
theNACGatewayrequestsanassessmentoftheendsystemaccordingtopredefinedsecurity
policyparameters.Theassessmentcanbeagentbasedoragentless,andisexecutedlocally
bythe
NACGatewayʹsassessmentfunctionalityand/orremotelybyapoolofassessmentservers.
4.Authorization‐Onceauthenticationandassessmentarecomplete,theNACGatewayallocates
theappropriatenetworkresourcestotheendsystembasedonauthenticationand/orassessment
results.ForEnterasyspolicyenabledwirelessswitchesandaccesspoints,the
NACGateway
formatsinformationintheRADIUSauthenticationmessagesthatdirectstheedgeswitchto
dynamicallyassignaparticularpolicytothewirelessendsystemonthewirelessswitchorAP,
dependingonthetypeofwirelessimplementation.ForRFC3580capablewirelessswitchesand
APs,theNACGatewayformats
informationintheRADIUSauthenticationmessages(intheform
ofRFC3580VLANTunnelattributes)thatdirectstheedgeswitchtodynamicallyassigna
particularVLANtothewirelessendsystem.Ifauthenticationfailsand/ortheassessmentresults
indicateanoncompliantendsystem,theNACGatewaycaneitherdenytheend
systemaccessto
thenetworkbysendingaRADIUSaccessrejectmessage,orquarantinetheendsystemby
assigningaQuarantinepolicyorVLANtothewirelessendsystem.
5.Remediation‐Whenthequarantinedenduseropensawebbrowsertoanywebsite,itstrafficis
dynamicallyredirectedtoa
Remediationwebpagethatdescribesthecomplianceviolationsand
providesremediationsstepsfortheusertoexecuteinordertoachievecompliance.Aftertaking
theappropriateremediationsteps,theenduserclicksonabuttononthewebpagetoreattempt
networkaccess,forcingthereassessmentoftheend
system.Atthispoint,theEnterasysNAC
solutiontransitionstheendsystemthroughtheentireNACcycleofdetection,authentication,
assessment,andauthorization,reassessingthesecuritypostureoftheendsystemtodetermineif
theremediationtechniquesweresuccessfullyfollowed.Iftheendsystemisnowcompliantwith
networksecurity
policy,theNACGatewayauthorizestheendsystemwiththeappropriateaccess
policy.Iftheendsystemisnotcompliant,theendsystemisrestrictedaccesstothenetworkand
theprocessstartsagain.
Seitenansicht 45
1 2 ... 41 42 43 44 45 46 47 48 49 50 51 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare