Enterasys-networks 9034385 Bedienungsanleitung Seite 68

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 67
Procedures for Out-of-Band and Inline NAC
5-4 Design Procedures
Figure 5-2 NAC Configuration
Authentication
TheAuthenticationsettingsdefinehowRADIUSrequestsarehandledforauthenticatingend
systems(thisdoesnotapplytoLayer3NACControllers.)Thisincludesidentifying whetherMAC
authenticationrequestsareproxiedupstreamorlocallyauthorized,andwhetherFilterIDand
TunnelRADIUSattributesareaddedtoRADIUSmessagesduringtheauthentication
process.
Assessment
TheAssessmentConfigurationdefinesthefollowingrequirementsforendsystemassessment:
•Whatassessmentteststorun.
TheAssessmentConfigurationdetermineswhattypesofassessmenttestsareexecutedand
whatparametersareused.Forexample,youcanspecifyaNessusassessmentutilizinga
specificNessusconfigurationfilethatdeterminesendsystemcompliancewith
theSANSTop
20vulnerabilities.ThesameNessusservercanbeusedtoassessWindowsmachinesfor
WindowsrelatedvulnerabilitiesandalsoassessMACOSbasedmachinesforMACrelated
vulnerabilities.Inaddition,youcanspecifyNessusaswellasotherassessmentservicesto
jointlydeterminethesecuritypostureof
aconnectingdevice.
•Whatresourcestousetoruntheassessment.
TheAssessmentConfigurationdetermineswhatassessmentserversareusedtoperformthe
assessment.Youcanbalancetheassessmentloadbetweenallyourassessmentservers,oryou
canselectaspecificassessmentserverpooltouse.Forexample,assumingNessusischosen
for
assessment,endsystemsconnectingtothenetworkinthecompanyʹsheadquarterscanbe
assessedwiththeNessusserverdeployedintheheadquarters,whileendsystemsinabranch
officewillbeassessedwithNessusserversdeployedinthebranchoffice,conserving
bandwidthutilizationonthenetwork.
Seitenansicht 67
1 2 ... 63 64 65 66 67 68 69 70 71 72 73 ... 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare