Enterasys-networks 9034385 Bedienungsanleitung Seite 91

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 90
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-27
Figure 5-7 Service for the Assessing Role
NotethatitisnotmandatorytoassigntheAssessmentPolicytoaconnectingendsystemwhileit
isbeingassessed.NACcanbeconfiguredtoassignthepolicyrolereceivedfromtheRADIUS
serverortheAcceptPolicytotheendsystemwhileitisbeingassessed.Inthis
way,theend
systemcanbegrantedimmediatenetworkaccesswithoutmandatingthattheenduserwaitfor
assessmenttobecomplete beforefullnetworkresourceallocationisgranted.IfNACisconfigured
toreturnthepolicyrolereceivedfromtheRADIUSServer,itisnecessarythattheenterpriseʹs
business
specificpolicyrolesareconfiguredtoallowaccesstotheappropriatenetworkresources
forcommunicationwiththeassessmentserversduringassessment.Thiscanbeimplementedby
associatingtheAssessingserviceshowninFigure 57toallbusinessspecificpolicyrolesinthe
NetSightPolicyManagerconfiguration.
Quarantine Policy
TheQuarantinePolicyisusedtorestrictnetworkaccesstoendsystemsthathavefailed
assessment.ForEnterasyspolicyenabledswitches,acorrespondingQuarantinepolicyrole
(createdinPolicyManager)shoulddenyalltrafficbydefaultwhilepermittingaccesstoonly
requirednetworkresourcessuchasbasicnetworkservices(ARP,DHCP,
andDNS).
IftheNACdeploymentimplementsremediation,theservicesassociatedtotheQuarantinePolicy
mustbeconfiguredtoallowallHTTPtrafficontothenetwork,inadditiontootherbasicIP
servicessuchasARP,DNS,and DHCPasshowninFigure 5 8.
Seitenansicht 90
1 2 ... 86 87 88 89 90 91 92 93 94 95 96 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare