Enterasys-networks 9034385 Bedienungsanleitung Seite 66

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 65
Procedures for Out-of-Band and Inline NAC
5-2 Design Procedures
PolicyManagerisnotrequiredforoutofbandNACthatutilizesRFC3580compliantswitches
(Enterasysandthirdpartyswitches).Inthiscase,aVLANisspecifiedinNACManagerto
authorizeconnectingendsystemswithaparticularlevelofnetworkaccess,usingdynamicVLAN
assignment.
RefertotheEnterasys
Networkswebsitehttp://www.enterasys.com/products/management/
downloads/NetSight.htmlforNetSightsoftwarelicensinganddownloadinformation.
2. Define Network Security Domains
AdifferentSecurityDomainshouldbedefinedforeachareaofthenetworkthathasitsown
uniquerequirementsforendsystemauthentication,assessment,andauthorization.
ASecurityDomaindefinesasetofNACGatewaysandNACControllersthathavecommon
authentication,assessment,andauthorizationrequirementsforendsystemsconnectingto
the
network.ForNACGateways,thedomainalsoincludestheassociatedswitchesthatareuniquely
assignedtothegateways.
ASecurityDomaincanbecomposedofbothNACControllerandNACGatewayappliances.Each
NACGatewaycanonlybeassignedtooneSecurityDomainandthereforeallportsonaparticular
switch(forexample,astackofSecureStackC2switchesoraMatrixN7chassis)canonlybe
associatedtooneSecurityDomain.Likewise,aNACControllercanonlybeassignedtoone
SecurityDomain.
Seitenansicht 65
1 2 ... 61 62 63 64 65 66 67 68 69 70 71 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare