Enterasys-networks 9034385 Manual de usuario Pagina 88

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 87
Out-of-Band NAC Design Procedures
5-24 Design Procedures
6. VLAN Configuration
ThisstepisforNACdeploymentsthatuseRFC3580compliantswitchesintheintelligentedgeof
thenetworktoimplementdynamicVLANassignmentofconnectingdevices.
NACleveragesVLANTunnelRADIUSattributemodificationinRADIUSauthentication
messagesfornetworkresourceallocationtoendsystemsconnectedtotheseRFC3580compliant
switches.ThisrequiresthatbeforeNACisdeployedonthenetwork,eachRFC3580compliant
switchintheintelligentedgeofthenetworkisconfiguredwiththeappropriateVLANsthatmay
bereturnedfromtheNACGateways.AlistofVLANsthatmaybeassignedtoconnectingend
systemsforeach
SecurityDomainmustbegeneratedbyanalyzingtheAcceptPolicy,Assessment
Policy,FailsafePolicy,andQuarant inePolicyofthefollowing NACconfigurations:
•TheSecurityDomains’defaultNACconfigurations
•MACoverridesfortheSecurityDomains
•UseroverridesfortheSecurityDomains
•GlobalMACanduseroverrides
7. Policy Role Configuration
ThisstepisforNACdeploymentsthatuseEnterasyspolicyenabledswitchesintheintelligent
edgeofthenetworktoimplementdynamicpolicyassignmentofconnectingdevices.
NACleveragesFilterIDRADIUSattributemodificationinRADIUSauthenticationmessagesfor
networkresourceallocationtoendsystemsconnectedtotheseEnterasysswitches.Therefore,
beforeNACisdeployedonthenetwork,eachEnterasysswitchintheintelligentedgeofthe
networkmustbeconfiguredwiththeappropriatepolicyrolesthatmaybereturnedfromtheNAC
Gateways.AlistofpolicyrolesthatmaybeassignedtoconnectingendsystemsforeachSecurity
Domain
canbegeneratedbyanalyzingtheAcceptPolicy,AssessmentPolicy,FailsafePolicy,and
QuarantinePolicyofthefollowingNACconfigurations:
•TheSecurityDomains’defaultNACconfiguration
•MACoverridesfortheSecurityDomains
•UseroverridesfortheSecurityDomains
•GlobalMACanduseroverrides
8. Define NAC Access Policies
AccesspoliciesdefinetheauthorizationlevelthatNACassignstoaconnectingendsystembased
ontheendsystemʹsauthenticationand/orassessmentresults.Therearefouraccesspoliciesused
inNACManager:FailsafePolicy,AcceptPolicy,QuarantinePolicy,andAssessmentPolicy.Inyour
securitydomainandoverrideconfigurations,theseaccess
policiesdefineasetofnetworkaccess
servicesthatdetermineexactlyhowanendsystemʹstrafficisauthorizedonthenetwork.
WhenEnterasyspolicyenabledswitchesaredeployedintheintelligentedgeofthenetworkto
authenticateandauthorizeconnectingendsystems,theseswitchesmustbeconfiguredwith
access
policiesbeforeNACisdeployed.NetSightPolicyManagerenablestheenterprisewide
deploymentofpolicyrolestoEnterasyspolicyenabledswitches,withasingleclick.
Inadditiontotheenterpriseʹsbusinessspecificroles,suchas“Faculty”or“Sales,”NACpolicy
rolesmustbedefined,configured,andenforcedtothenetwork
forNAC.Allpolicyroles
Vista de pagina 87
1 2 ... 83 84 85 86 87 88 89 90 91 92 93 ... 97 98

Comentarios a estos manuales

Sin comentarios