Enterasys-networks 9034385 Manual do Utilizador Página 53

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 98
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 52
Enterasys NAC Design Guide 4-1
4
Design Planning
ThischapterdescribesthestepsyoushouldtakeasyoubeginplanningyourNACdeployment.
Thefirststepistoidentifythedeploymentmodelthatbestmeetsyourbusinessobjectives.Then,
thecurrentnetworkinfrastructuremustbeevaluatedinordertodetermineNACcomponent
requirements.Basedonthisevaluation,youwill
beabletodecidewhethertodeployinlineorout
ofbandnetworkaccesscontrol.
Identify the NAC Deployment Model
WhenplanningyourNACdeployment,thefirststepistoidentifytheNACdeploymentmodel,or
aphasedimplementationofmultipledeploymentmodels,thatmeetsyourNACbusiness
objectives.Thefourdeploymentmodelsaresummarizedbelow.Formoreindepthinformation on
eachmodel,seeChapter 2,NACDeploymentModels.
•Model
#1:EndSystemDetectionandTracking
EnterasysNACdetectsdevicesastheyconnecttothenetwork,identifyingthelocation,MAC
address,IPaddress,andusernameofthepersonusingtheendsystem.Thisinformationis
maintainedovertimeforeachdeviceonthenetwork,yieldingcompletehistoricalinformation
aboutadevice
asitinteractswiththenetwork.
•Model#2:EndSystemAuthorization
EnterasysNACdetects,authenticates,andauthorizesconnectingendsystems,tocontrol
accesstonetworkresourcesbasedonlocationaswellasuserandendsystemidentity.
•Model#3:EndSystemAuthorizationwithAssessment
EnterasysNACisdeployedwithendsystemassessmentand
authorization(butwithout
remediation),tocontrolaccesstonetworkresourcesbasedonthesecuritypostureofa
connectingendsystem.Compliantendsystemsarepermittedontothenetwork,whileend
systemsthatfailassessmentcanbedynamicallyquarantinedwithrestrictivenetworkaccess.
•Model#4:EndSystemAuthorizationwithAssessmentandRemediation
Inadditiontoendsystemassessmentandauthorization,EnterasysNACisdeployedwith
remediationtodynamicallyinformquarantinedendsystemsofsecuritycompliance
violations.Usingwebbasednotification,assistedremediationallowsendusersthathave
For information about... Refer to page...
Identify the NAC Deployment Model 4-1
Survey the Network 4-2
Identify Inline or Out-of-band NAC Deployment 4-11
Summary 4-11
Vista de página 52
1 2 ... 48 49 50 51 52 53 54 55 56 57 58 ... 97 98

Comentários a estes Manuais

Sem comentários