Enterasys-networks 9034385 Manual de usuario Pagina 87

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 86
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-23
Itisimportanttonotethatonly theNACGatewaysthatareconfiguredwithremediationand
registrationfunctionalityneedtobepositionedinsuchamanner.AllotherNACGatewaysmay
bepositionedatanylocationonthenetwork,withtheonlyrequirementbeingthataccesslayer
switchesareableto
communicatetothegateways.Typically ,theNACGatewaywithremediation
andregistrationfunctionalityispositionedonanetworksegmentdirectlyconnectedtothe
distributionlayerroutersontheenterprisenetwork,sothatanyHTTPtrafficsourcedfrom
quarantinedendsystemsthatareconnectedtothenetworkʹsaccesslayercan
beredirectedtothat
NACGateway.Asanalternative,theNACGatewaymaybepositionedonanetworksegment
directlyconnectedtotherouterprovidingconnectivitytotheInternetorinternalwebserverfarm.
Inthisscenario,theHTTPtrafficsourcedfromquarantinedendsystemswouldberedirectedto
theNAC
GatewaybeforereachingtheInternetorinternalwebservers.
4. Identify Backend RADIUS Server Interaction
IfaNACGatewayisreceiving802.1Xand/orwebbasedauthenticationrequestsforconnecting
endsystems,thenabackendRADIUSservermustbeconfiguredtovalidateendusercredentials
intheauthenticationprocess.ForeachNACGateway,aprimaryandsecondaryRADIUSserver
canbespecifiedforthevalidationofuser/device
networklogincredentialsonthenetwork.
If802.1X,webbased,orRADIUSauthenticationforswitchmanagementloginsisimplemented,a
RADIUSserverwithbackenddirectoryservicesmustbedeployedonthenetwork.ARADIUS
serverisnotnecessaryifonlyMACauthenticationisdeployedonthenetwork.
AllRADIUSserverssupporting
RFC2865andsubsequentRADIUSstandardsaresupportedby
EnterasysNACapplianceswhenproxyingRADIUSauthenticationrequests.Testshavebeen
conductedonthefollowingRADIUSservers:
FreeRADIUS
•MicrosoftIAS
•FunkSteelbeltedRADIUS
•CiscoACS
5. Determine End-System Mobility Restrictions
WhileSecurityDomainspecificMACanduseroverridescanbeconfiguredtocontrolendsystem
andendusermobilityacrossthenetworkandbetweenSecurityDomains,the“LockMAC”
featureallowsthenetworkadministratortorestrictnetworkaccessforspecificendsystemtoa
switchportorswitch.Theendsystem
canbedeniednetworkaccesswithaRADIUSAccessReject
messagereturnedtotheswitch,orassignedaspecificpolicyorVLANwhenconnectingtothe
networkinarestrictedarea.HerearesomeexamplesofhowtheLockMACfeaturecanbeused:
•Aprinter,server,orotherendsystem
couldbeallowednetworkaccessonlywhenitis
connectedtoaports p ecifiedbyIToperations.Thispreventssecurityissuesthatcouldresultif
thedevicewasmovedtoadifferentareaofthenetwork.
•AnIPphonewithaMACoverridecouldbelockedtoaspecificporton
aswitch.Thiswould
allowexactidentificationofthephoneʹslocationincaseanemergency(911)callwasplaced
fromthephone.
Vista de pagina 86
1 2 ... 82 83 84 85 86 87 88 89 90 91 92 ... 97 98

Comentarios a estos manuales

Sin comentarios