Enterasys-networks 9034385 Bedienungsanleitung Seite 90

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 89
Out-of-Band NAC Design Procedures
5-26 Design Procedures
Figure 5-6 Policy Role Configuration in NetSight Policy Manager
Assessment Policy
TheAssessmentPolicymaybeusedtotemporarilyallocate asetofnetworkresourcestoend
systemswhiletheyarebeingassessed.ForEnterasyspolicyenabledswitches,acorresponding
policyrole(createdinPolicyManager)shouldallocatetheappropriatesetofnetworkresources
neededbytheassessmentservertosuccessfullycomplete
itsendsystemassessment,while
restrictingtheendsystemʹsaccesstothenetwork.Forexample,iftheassessmentserveris
configuredtoscanforFTPvulnerabilities,andtheAssessmentPolicydoesnotallowFTPtr affic
fromtheendsystemontothenetwork,thentheassessmentserverwillnotdetect
theFTP
vulnerabilitiesontheendsystem.
Toachievethistradeoff,theAssessingpolicyrolecanbeconfiguredbydefaulttodenyalltraffic,
andbeassociatedtoclassificationrulesthatpermittraffictoallassessmentservers,using
destinationIPaddressPermitclassificationrules,asshowninFigure57.
Therefore,alltraffic
involvedwiththeendsystemʹsassessmentisallowedontothenetwork.Inaddition,otherbasic
networkservicessuchasARP,DHCP,andDNSareallowedontothenetworksotheendsystem
canestablishIPconnectivityinthenetworkwhilebeingassessed.
TheAssessmentPolicycanalso
beconfiguredtoimplementwebnotificationduringtheexecution
oftheassessment,toinformtheenduserthataccesstothenetworkhasbeentemporarily
restrictedwhiletheassessmenttakesplace.ThisisimplementedbyallowingHTTPtrafficontothe
networkinadditiontotheotherservicespreviouslydescribe d.
Seitenansicht 89
1 2 ... 85 86 87 88 89 90 91 92 93 94 95 96 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare