Enterasys-networks 9034385 Manual de usuario Pagina 35

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 34
Model 4: End-System Authorization with Assessment and Remediation
Enterasys NAC Design Guide 2-13
Assistedremediationinformsenduserswhentheirendsystemshavebeenquarantineddueto
networksecuritypolicynoncompliance,andallowsenduserstosafelyremediatetheirnon
compliantendsystemswithoutassistancefromIToperations.Theprocesstakesplacewhenan
endsystemconnectstothenetworkandassessmentis
performed.Enduserswhosesystemsfail
assessmentarenotifiedviawebredirectionthattheirsystemshavebeenquarantined,andare
instructedinhowtoperformselfserviceremediationspecifictothedetectedcompliance
violations.
Oncetheremediationstepshavebeensuccessfullyperformedandtheendsystemiscompliant,
theend
usercaninitiateanondemandreassessmentoftheendsystemandcanbeallocatedthe
appropriatenetworkresources,againwithouttheinterventionofIToperations.
Implementation
InModel4,endsystemscanbedetected,authenticated,assessed,authorized,andremediatedin
differentwaysdependingonthewhetherinlineoroutofbandnetworkaccesscontrolis
implementedintheEnterasysNACsolution.
Out-of-Band NAC
ForoutofbandEnterasysNACdeploymentsutilizingtheNACGateway,NACfunctionsare
implementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐AsdescribedinModel3.
Authorization‐AsdescribedinModel3.
Remediation‐WhenendsystemsarequarantinedbytheNACGateway,
thenetworkmustbe
configuredtodirectalltrafficfromthequarantinedendsystemstotheNACGateway.Thiscanbe
implementedbyconfiguringpolicybasedroutingonarouterinlinewiththetrafficsourcedfrom
quarantinedendsystems.Thisrouterwouldbeconfiguredtosendallwebtrafficfrom
quarantined
endsystemstotheNACGateway,whichthenservesbacktheremediationwebpage
totheenduser.
Thewaytherouteridentifiesthetrafficfromquarantinedendsystemsdiffersbetweenanetwork
composedofpolicyenabledswitchesintheaccessedgeoranetworkcomposedofswitches
implementingRFC
3580dynamicVLANassignmentintheaccessedge.ForanEnterasyspolicy
enablededge,theQuarantinepolicycanbeconfiguredtorewritetheTypeofService(ToS)valueof
HTTPtraffictoaparticularsettingthatmatchesthepolicybasedroutingconfiguration.Foran
RFC3580capableedge,thepolicybased
routingwouldbeconfiguredtomatchthesourceIP
addressoftheHTTPtrafficbeinggeneratedfromthesubnetsthatcorrespondstotheQuarantine
and/orAssessingVLAN.Ineithercase,bydirectingtheHTTPtrafficfromquarantinedend
systemsovertotheNACGateway,theNACGatewaywillserveback
theremediationwebpageto
thenoncompliantendsy stem.
Vista de pagina 34
1 2 ... 30 31 32 33 34 35 36 37 38 39 40 ... 97 98

Comentarios a estos manuales

Sin comentarios