Enterasys-networks 9034385 Manual de usuario Pagina 54

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 53
Survey the Network
4-2 Design Planning
accesstoawebbrowsertosafelyremediatetheirquarantinedendsystemwithoutimpacting
IToperations.
Onceadeploymentmodelisselected,thecurrentnetworkinfrastructuremustbeexaminedto
identifythetechnicaldependenciesandrequirementsimposedbytheNACsolution.
Survey the Network
Thestepsinthissectionwillhelpyouidentifyandevaluatethecurrentnetworkinfrastructureso
thatyoucanmakedesigndecisionsregardingNACcomponentrequirements.
1. Identify the Intelligent Edge of the Network
Thefirststepinsurveyingyournetworkistodeterminewhetherornotyournetworkhasan
“intelligentedge.”ThisinformationwillhelpyoudecidewhethertheNACGatewayorNAC
Controllerappliancebestsuitsyournetworkinfrastructure.
Theterm“intelligent”referstoanetworktopologywheretheaccessedgeis
composedof
Enterasyspolicyenabledswitchescapableofsupportingauthenticationandpolicyenforcement,
orthirdpartyswitchescapableofsupportingauthenticationanddynamicVLAN assignmentas
definedinRFC3580.
Nonintelligentinfrastructuredevices,suchasrepeatersandhubs,arenotcapableofsupporting
authenticationand/orauthorizat ion ofendsystems,and
simplyprovideconnectivitytothe
infrastructure.
AnintelligentedgeisrequiredwhentheNACGatewayisutilizedforimplementingoutofband
NAC.TheNACGatewayapplianceleveragestheintelligentedgeof thenetworktoimplementthe
authenticationandauthorizationofconnectingendsystems.TheNACGatewayeffectsthe
assignmentof
policiesorVLANsonEnterasysswitchesorRFC3580capableswitcheslocatedat
edgeofthenetwork,toauthorizealevelofnetworkaccesstoconnectingendsystems.These
assignmentsarebasedonvariousparameters,suchasthelocationoftheendsystemandsecurity
postureassessmentresults.Theintelligentedge
ofthenetworkalsoimplementsanauthentication
method(802.1X,webbased,orMACauthentication)forvalidatingthedeviceand/oruseridentity
ofconnectingendsystems.
However,innetworkswithnonintelligentdevicesattheaccessedge,itisnotnecessarytoreplace
thesenonintelligentdevicestobeabletoimplement
outofbandNACwiththeNACGateway.
Instead,theEnterasysMatrixNseriesswitchcanbepositionedupstreamfromnonintelligent
devices(suchasinthedistributionlayer)toimplementtheauthenti cationandauthorization
functionsfordownstreamconnecteddevices.MatrixNSeriesdevicessupportMultiUser
Authentication(MUA)which
enablestheswitchtoindividuallyauthenticateanduniquely
authorizemultipleendsystemsconnectedtothesamephysicalport.MUAontheMatrixNseries
Platinumsupportstheconcurrentauthenticationandauthorizationofover1000endsystemsona
singleportwiththeallocationofdisparatenetworkresourcestoeachendsystem.
Inthiscase,the
MatrixNseriesswitchistheintelligentedgeofthenetworkalthoughitisnotphysicallylocatedin
theaccesslayer.ByutilizingtheMatrixNseriesinthistypeofconfiguration,mostofthebenefits
ofoutofbandNACcanbeobtainedwithoutupgrading
theedgeofthenetwork.
Vista de pagina 53
1 2 ... 49 50 51 52 53 54 55 56 57 58 59 ... 97 98

Comentarios a estos manuales

Sin comentarios