Enterasys-networks 9034385 Bedienungsanleitung Seite 92

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 98
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 91
Inline NAC Design Procedures
5-28 Design Procedures
Figure 5-8 Service for the Quarantine Role
Furthermore,theQuarantinePolicyandothernetworkinfrastructuredevicesmustbeconfigured
toimplementHTTPtrafficredirectionforquarantinedendsystemstoreturnwebnotificationof
thequarantinedstateofanendsystem.
Unregistered Policy
IfMAC(network)registrationisconfiguredintheNACdeployment,an“Unregistered”policy
canbeassignedtoconnectingendsystemswhiletheyareunregisteredonthenetwork.This
policymustbeconfiguredtoallowbasicservicessuchasARP,DNS,DHCP,andtoimplement
HTTPtrafficredirectiontoreturnwebbased
notificationforunregist eredendsystems.(Because
thisconfigurationissimilartotheQuarantinePolicyandtheAssessmentPolicy,thosepolicies
couldbeassignedtounregisteredendsystems,ifdesired).
Inline NAC Design Procedures
ThefollowingsectioncontinuestheEnterasysNACdesignprocedurewithstepsspecifically
relatingtotheimplementationofinline NACwiththeNACController.
1. Determine NAC Controller Location
BecausetheNACControllerisplacedinlinewithtrafficsourcedfromconnectingendsystems,the
locationofNACControllersisdirectlydependentonthenetworktopology.NACControllersare
typicallyplacedbetweentheedgewhereendsystemsconnecttothenetwork(forexample,the
wiredandwirelessaccessedge,orthe
remoteaccessedgebehindaVPNconcentrator)andthe
networkʹscoreanddatacenterwheremissioncriticalinfrastructureresourcesreside.Thisway,
noncompliantendsystemscanberestrictedfromcommunicatingtomissioncriticalresources.
WiththeNACControlleractingastheauthorizationpointfortrafficenforcementwithinline
NAC,there
isafundamentaltradeoffwhenpositioningtheNACControllerinthenetwork
topology:theclosertheNACControllerisplacedtotheedgeofthenetwork,thehigherthelevel
ofsecurityisachieved,inthatendsystemsareauthorizedclosertothepointofconnectionand
endsystems
deemednoncomplianthaveaccesstoasmallersetofnetworkresources.
Seitenansicht 91
1 2 ... 87 88 89 90 91 92 93 94 95 96 97 98

Kommentare zu diesen Handbüchern

Keine Kommentare