Enterasys-networks 9034385 Manual de usuario Pagina 26

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 25
Model 2: End-System Authorization
2-4 NAC Deployment Models
deviceidentity,useridentity,and/orlocationinformationisusedtoauthorizetheconnectingend
systemwithacertainlevelofnetworkaccess.Itisimportanttonotethatinthismodel,network
accessisnotbeingcontrolledbasedonendsystemassessmentresults.Assessmentwillbe
introducedinthenextNAC
deploymentmodel.
Implementation
InModel2,endsystemscanbedetected,authenticated,andauthorizedindifferentways
dependingonwhetherinlineoroutofbandnetworkaccesscontrolisimplemented.
Out-of-Band NAC
ForoutofbandNACutilizingtheNACGateway,NACfunctionsareimplementedinthe
followingway:
Detection‐End systemsaredetectedviathereceiptofRADIUSpacketsfromanaccessedge
switchattempting toauthenticateanendsystem.
Authentication‐Iftheendsystemis802.1Xorwebauthenticatingtothenetwork,
theNAC
GatewayproxiestheRADIUSauthenticationrequesttoabackend authentication(RADIUS)
servertovalidatetheidentityoftheuser/deviceconnectingtothenetwork.Forendsystemsthat
areMACauthenticatingtothenetwork,theNACGatewaycanbeconfiguredtoeitherproxythe
MACauthenticationrequeststoa
RADIUSserverorlocallyauthorizeMACauthentication
requestsattheNACGateway.IfonlyMACauthenticationisdeployedonthenetworkandthe
NACGatewayisconfiguredtolocallyauthorizeMA C a uthenti cationrequests,thenabackend
RADIUSserverisnotrequiredfortheEnterasysNACsolution.
Authorization‐TheNACGatewayallocates
theappropriatenetworkresourcestotheendsystem
basedondeviceidentity,useridentity,andlocation.ForEnterasyspolicyenablededgeswitches,
theNACGatewayformatsinformationintheRADIUSauthenticationmessagesthatdirectsthe
edgeswitchtodynamicallyassignaparticularpolicytotheconnectingendsystem.ForRFC3580
capableedgeswitches,theNACGatewayformatsinformationintheRADIUSauthentication
messages(intheformofRFC3580VLANTunnelattributes)thatdirectstheedgeswitchto
dynamicallyassignaparticularVLANtotheconnectingendsystem.TheNACGatewaymay
denytheendsystemaccesstothenetwork
bysendingaRADIUSAccessRejectmessagetothe
edgeswitchorassigntheendsystemasetofnetworkresourcesbyspecifyingaparticularpolicy
orVLANtoassigntotheauthenticatedendsystemontheedgeswitch.
Inline NAC
ForinlineNACutilizingtheLayer2orLayer3NACController,NACfunctionsareimplemented
inthefollowingway:
Detection‐End systemsaredetectedviathereceiptofRADIUSpacketsfromanaccessedge
switchattempting toauthenticateanendsystem.
Authentication‐Oneoftwoauthenticationconfigurationscanbeimplementedon
theNAC
Controller.Authenticationcanbedisabledaltogether,trustingthatthedownstreaminfrastructure
devicesauthenticatedtheendsystemandpermittednetworkaccess.Alternately,MAC
registrationcanbeimplementedfornewdevicesconnectingtothenetwork,whereausername
andpasswordand/orasponsorusernameandpasswordmustbevalidatedagainst
abackend
LDAPcompliantdatabasebeforenetworkaccessispermitted.
Authorization‐TheNACControllerallocatestheappropriatenetworkresourcestotheend
systembyassigningapolicylocallyonthecontrollertothetrafficsourcedfromtheendsystem.
Vista de pagina 25
1 2 ... 21 22 23 24 25 26 27 28 29 30 31 ... 97 98

Comentarios a estos manuales

Sin comentarios