Enterasys-networks 9034385 Manual de usuario Pagina 90

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 89
Out-of-Band NAC Design Procedures
5-26 Design Procedures
Figure 5-6 Policy Role Configuration in NetSight Policy Manager
Assessment Policy
TheAssessmentPolicymaybeusedtotemporarilyallocate asetofnetworkresourcestoend
systemswhiletheyarebeingassessed.ForEnterasyspolicyenabledswitches,acorresponding
policyrole(createdinPolicyManager)shouldallocatetheappropriatesetofnetworkresources
neededbytheassessmentservertosuccessfullycomplete
itsendsystemassessment,while
restrictingtheendsystemʹsaccesstothenetwork.Forexample,iftheassessmentserveris
configuredtoscanforFTPvulnerabilities,andtheAssessmentPolicydoesnotallowFTPtr affic
fromtheendsystemontothenetwork,thentheassessmentserverwillnotdetect
theFTP
vulnerabilitiesontheendsystem.
Toachievethistradeoff,theAssessingpolicyrolecanbeconfiguredbydefaulttodenyalltraffic,
andbeassociatedtoclassificationrulesthatpermittraffictoallassessmentservers,using
destinationIPaddressPermitclassificationrules,asshowninFigure57.
Therefore,alltraffic
involvedwiththeendsystemʹsassessmentisallowedontothenetwork.Inaddition,otherbasic
networkservicessuchasARP,DHCP,andDNSareallowedontothenetworksotheendsystem
canestablishIPconnectivityinthenetworkwhilebeingassessed.
TheAssessmentPolicycanalso
beconfiguredtoimplementwebnotificationduringtheexecution
oftheassessment,toinformtheenduserthataccesstothenetworkhasbeentemporarily
restrictedwhiletheassessmenttakesplace.ThisisimplementedbyallowingHTTPtrafficontothe
networkinadditiontotheotherservicespreviouslydescribe d.
Vista de pagina 89
1 2 ... 85 86 87 88 89 90 91 92 93 94 95 96 97 98

Comentarios a estos manuales

Sin comentarios