Enterasys-networks 9034385 Manual de usuario Pagina 93

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 98
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 92
Inline NAC Design Procedures
Enterasys NAC Design Guide 5-29
However,theclosertheNACControllerisplacedtotheedgeofthenetwork,themoreNAC
Controllersarerequiredonthenetwork,increasingNACdeploymentcostandcomplexity.
Conversely,whenmovingtheNACControllertowardsthecoreofthenetwork,fewerNAC
Controllersarerequired,decreasingNACdeploymentcostand
complexity, butalsodecreasing
thelevelofsecurity.
ForimplementingNAConwiredandwirelessLANs,itisrecommendedthattheLayer2NAC
Controllerispositionedbetweentheaccesslay eranddistributionlayerbeforethefirstroutedhop
inthenetwork.Asanalternative,theNACControllermaybepositioned
deeperintothenetwork
afterthefirstroutedhopusingtheLayer3configuration.TheLayer3NACControllercanalsobe
positionedafteraVPNconcentratororWANconnectiontoimplementNACforremoteusers.
UnliketheoutofbandNACdesign,theimplementationofremediationand/orMAC(network)
registrationdoesnotaffectthelocationoftheNACController.TheNACControllerwill
appropriatelyinterceptwebtrafficforthepurposeofremediationandregistration.
Lastly,itshouldbeunderstoodthatsomeadva ntagesexistwiththedeploymentofaLayer2NAC
ControlleroveraLayer3NACController,whichmay
affectthedecisionofhowNACControllers
arepositioned.WhileaLayer2NACControlleralwaysknowstheMACaddressofthe
downstreamconnectedendsystem,theLayer3NACControllermaynotbeabletodeterminethe
MACaddressofadownstreamendsystem(denotedas“Unknown”inNACManager.)
TechniquessuchasNetBIOSlookupsandDHCPsnoopingareimplementedtoattempttoresolve
theIPaddressofthedownstreamconnectedendsystems;however,scenariosexistwheretheIP
addressofthedownstreamendsystemmaynotbedetermined.
TheMACaddressofadownstreamendsystemwillbedetermined
bytheNACControllerinthe
followingscenarios:
•EndsystemssupportNetBIOSandahostfirewalldoesnotdropinboundNetBIOS requests
fortheLANconnection.
•DHCPisimplementedandtheDHCPserverexistsupstreamfromtheNACController.
SincetheLayer3NACControllermaynotbeabletodeterminethe
MACaddressofa
downstreamendsystem,“LockMAC”andMACoverridesarenotapplicabletoLayer3NAC
Controllers.Furthermore,MAC(network)registrationmaynotbeimplementedwhentheMAC
addressofadownstreamconnectedendsystemisunknown.Inthiscase,theendsystemis
assignedtheSecurityDomain’s
defaultNACconfiguration.
Vista de pagina 92
1 2 ... 88 89 90 91 92 93 94 95 96 97 98

Comentarios a estos manuales

Sin comentarios