Enterasys-networks 9034385 Bedienungsanleitung Seite 58

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 57
Survey the Network
4-6 Design Planning
Similarto802.1X,webbasedauthenticationrequirestheinputofcredentialsandisnormallyused
onusercentricendsystems thathaveaconceptofanassociateduser,suchasaPC.Therefore,this
authenticationmethodisinappropriateformachinecentricdevicessuchasprintersandIP
cameras.
Notethatweb
basedauthenticationisauserinitiatedauthenticationmethodwheretheusermust
manuallybeginthenetworkloginprocessbyopeningawebbrowserandenteringcredentials.
Thisuserinitiatedmethodpreventsseamlessnetworkconnectivitybecausetheendusermust
initiatethereauthenticationafterassessmentiscomplete.
SinceEnterasysNAConlyacts
asapassthroughtoanupstreamRADIUSServer,itismandatory
thatafullauthenticationdeploymentisconfiguredonthenetworkifwebbasedauthentica tionis
used.
MACAuthentication
MACauthenticationauthenticatesthesourceMACaddressofanendsystemandgrantsthe
appropriatelevelofaccessbyvalidatingtheMAC
addressontheRADIUSauthenticationserver.
Thisauthenticationmethodonlyrequiresthattheendsystemgenerateapacket;itrequiresno
specialsoftwareontheendsystem.
Unlike802.1Xandwebbasedauthentication,MACauthenticationcanbeusedtoauthenticate
machinecentricendsystemsthathavenoconceptofanassociated
user,suchasaprinterorIP
camera.
Withthisauthenticationmethod,EnterasysNACcanactasapassthroughtoanupstream
RADIUSServerorcanlocallyauthorizeMACauthenticationattempts.Therefore,ifafull
authenticationdeploymenthasnotbeenconfiguredonthenetwork,MACauthenticationshould
beused.
End-System Capabilities
Whenauthenticationisconfiguredonthenetwork,itisimportanttoconsiderendsystem
capabilitiesandtheirabilitytointeractwiththeauthentication process.Machinecentricend
systemsthatdonotpossessan802.1Xsupplicant,suchasIPcamerasandprinters,mayonlybe
capableofMACauthenticatingtothenetwork.
SomehumancentricendsystemssuchasPCs,
maybecapableof802.1XandwebbasedauthenticationwhileotherPCsnotinstalledwithan
802.1Xsupplicant,are onlycapableofwebbasedauthentication.Ifendsystemsareimplementing
802.1Xandwebbasedauthentication,EnterasysNACshould leveragetheseauthentication
methods
forendsystemdetection.Forendsystemsnotimplementing802.1Xorwebbased
authentication,MACbasedauthenticationcanbeenabledontheseswitchports.
Support of Multiple Authentication Methods
Inordertosupportanenterprisenetworkconsistingofadiverseenvironmentofmachinecentric
andhumancentricdevices,itisimportantthattheintelligentedgeofthenetworksupportsthe
concurrentenablingofmultipleauthenticationmethods,allatthesametimeonthesameswitch
port.Someintelligentswitchesmay
notsupporttheenablingofmultipleauthenticationmethods
concurrentlyonasingleport.Forexample,MACand802.1Xauthenticationmaybeconcurrently
enabledonaporttoaccountforthefactthatatrusteduser,guestuser,orIPphonemayconnectto
thisport.Theabilitytosupportmultiple
authenticationmethodsconcurrentlyonaportiseven
moreimportantforenvironmentswheremobilityofdevicesaroundthenetworkisessentialfor
ensuringbusinesscontinuity.
Support for Multiple End-System Connection
Itisimportanttoknow whethermultipleendsystemconnectionissupportedbytheintelligent
edgeofthenetwork.Iftheintelligentedgedevicesonlysupporttheauthenticationofoneend
Seitenansicht 57
1 2 ... 53 54 55 56 57 58 59 60 61 62 63 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare