Enterasys-networks 9034385 Bedienungsanleitung Seite 61

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 60
Survey the Network
Enterasys NAC Design Guide 4-9
Ifthenetworkinfrastructuredoesnotcontainintelligentdevicesattheedgeordistributionlayer,
theninlineNACusingtheNACControllerastheauthorizationpointforconnectingendsystems
mustbeimplemented.ThisisnotassecureasoutofbandNACbecausetheauthorizationpoint
forendsy stemsis
locateddeeperintothenetworkattheNACController.WithinlineNAC,a
quarantinedendsystem,whilerestrictedfromnetworkaccesstoresourcesupstreamfromthe
NACController,isstillabletointeractopenlywithresourcesandassetsonthenetwork
downstreamfromtheNACController.However,anadvantageof
theNACControlleristhatit
providesnetworkaccesscontrolwithoutrequiringtheupgradeoftheaccesslayerordistribution
layerofthenetwork.
Furthermore,itisimportanttonotethattheNACControllerandNACGatewaycanbedeployed
concurrentlyinthenetworkforthesimultaneousimplementationofinlineand
outofbandNAC,
allcentrallymanagedfromtheNetSightNACManager.TheNACGatewaycanbeutilizedfor
areasofthenetworkwhereintelligentswitchesreside,whiletheNACControllercanbe
positionedinlineforsegmentsofthenetworkwherenonintelligentdevicesexist.
Ifthedeploymentofoutof
bandNACisdesiredforanetworkwithnonintelligentaccesslayer
devices,thefollowingoptionsshouldbeconsidered:
DistributionlayerinfrastructuredevicescanbestrategicallyupgradedtoEnterasysMatrixN
Seriesdevicesthatarecapableofindividuallyauthenticatinganduniquelyauthorizing
multipledevicesconnectedtoasingleport.Mostof
thesecuritybenefitsofoutofbandNAC
usingEnterasyspolicycanbeobtainedbyimplementingauthorizationatthedistribution
layerinsteadofatthe portofconnectionintheaccesslayer.
AccesslayerinfrastructuredevicescanbeupgradedtoEnterasyspolicycapableswitchesor
RFC3580capableswitches to
obtainthesecuritybenefitsofoutofbandNAC.
4. Identify Network Connection Methods
ThepreviousstepshavebeenconcernedwithimplementingNACfortheinternalLAN.Inthis
step,varioustypesofnetworkconnectionmethodsarediscussed,alongwiththeirimpactonNAC
deployment.
Wired LAN
OutofbandorinlineNACcanbeimplemented,dependingonthecapabilitiesoftheaccessedge
infrastructuredevices.
Wireless LAN
WirelessLANdeploymentsmaybecategorizedintoeitherthickwirelessdeploymentswhere
accesspoints(APs)operateind e pend entlyonthenetwork,orthinwirelessdeploymentswhere
APscommunicatebacktocentrallydeployedwirelessswitchesthatfacilitatecommunication
betweenAPs.
Thick Wireless Deployments
ThickwirelessdeploymentsmayconsistoffullfeaturedAPsthatsupportauthenticationand
authorization.FullfeaturedthickAPsfallintotheintelligentedgecategoryandhavethesame
NACimplicationsasanintelligentwirededge.Inthiscase,intelligentAPsinathickwireless
deploymentcanbeconfiguredwithoutof
bandNACusingtheNACGateway,with
authenticationandauthorizationimplementedonthethickAPs.
OtherthickAPdeploymentsmayconsistofAPsthatdonotsupportauthenticationand/or
authorizationandmerelyactasamediaconverterbetweenthewirelessandwirednetworks.In
Seitenansicht 60
1 2 ... 56 57 58 59 60 61 62 63 64 65 66 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare