Enterasys-networks 9034385 Manual do Utilizador Página 59

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 98
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 58
Survey the Network
Enterasys NAC Design Guide 4-7
systematatime, thenitissuggestedthatMAClocking(alsoknownasPortSecurity)beenabled
ontheedgeswitchestorestrictthenumberofconnectingdevices.Ifmultipleendsystem
connectionissupported,thentheintelligentedgeswitchmustsupporttheauthenticationand
authorizationofmultipledevices(possibly
usingmultipleauthenticationmethods)concurrently
onthenetwork.Ifthisisnotsupported,thenasecurityholeexistswhereanoncompliantend
systemcan“piggyback”ontheopennetworkconnectionofacompliantendsystem.
Forexample,NACisoftendeployedonanIPtelephonyconvergednetworkwhereIPphone
handsetsarecascadedwithPCsconnectedtoasingleintelligentedgeinfrastructureport.Ifthe
intelligentedgeinfrastructuredevicesdonotsupporttheauthenticationandau thorizationofboth
thePCandIPphoneconnectedtothesameport,thenanoncompliantPCmaybeallowed
networkaccesswhenthesecurityposture
ofanIPphonethatconnectedtothenetworkfirst,is
deemedcompliant.
Furthermore,iftheauthenticationandauthorization ofmultipledevicesconnectingtoasingle
portisnotsupported,certaindevicesmayloseconnectivitywhenNACisdeployed.Forexample,
anIPphoneʹsnetworkconnectionmaybelostwhen
aPCisquarantinedonthenetwork.
Authentication Support on Enterasys Devices
Followingisinformationontheauthenticati onsupportprovidedbyEnterasysdevices:
•TheMatrixNseriesMultiUserAuthentication(MUA)featureallowstheenablingofany
combinationofauthenticationmethods(802.1X,webbased,and/orMAC)bothgloballyand
perport.WhiletheMatrixNseriesGoldsupportstheauthenticationandauthorizationof
two
users/devicesperport,theMatrixNseriesPlatinumsupportstheauthenticationand
authorizationofover2000usersanddevicesperport,providingthehighestdegreeof
authenticationmethodconfiguration flexibility.
•TheSecureStackC2/C3andB2/B3User+IPPhoneauthenticationallowsthe conf igurationof
multipleauthenticationmethodsgloballyandper
port(802.1X,webbased,and/orMAC)with
thelimitationofaPCandanIPphoneauthenticatingonasingleport.
•TheMatrixE1ʹsHybridauthenticationallowstheenablingofboth802.1X andMAC
authenticationonthesameport,andsupportstheauthenticationofasingleendsystemusing
only
oneoftheseauthenticationmethodsatatime.
•IfwebbasedauthenticationisgloballyenabledontheMatrixE1andtheMatrixEseries
Generation2/3platforms,eachportontheswitch canonlybeconfiguredtoimplementweb
basedauthentication.
Authentication Considerations
Ifauthenticationiscurrentlydeployedonthenetwork,hereareconsiderationsthatshouldbe
reviewedasyouplanyourNACdeployment:
•EnterasysNACwillseamlesslyintegratewithdeploymentswheretheauthenticatingand
authorizationoftrustedusersisalreadyimplemented.EnterasysNACcanbeconfiguredto
forwardtheRADIUSFilterIDand/or
VLANTunnelattributereturnedfromtheRADIUS
servertotheaccesslayerswitchduringtheauthenticationprocess.
•Ifguestaccess isimplementedonthenetworkbyassigningadefaultpolicyorVLANon
certainports(assumingguestuserswillfailauthenticationonthenetwork),theinfrastructure
willneedtobereconfigured
toimplementNACforguestusers.EnterasysNACwillnot
assessorauthorizeendsystemsthatonlyfailauthenticationagainstabackendRADIUS
server.ToenableEnterasysNACtointeractwithguestusersonthenetwork,MAC
authenticationmustbeenabledonportswhereguestusersconnecttothenetwork,and
EnterasysNACmustbeconfiguredtolocallyauthorizeMACauthenticationrequestsand
assigntheappropriateguestauthorizationlevel.Then,guestuserswillbesuccessfullyMAC
Vista de página 58
1 2 ... 54 55 56 57 58 59 60 61 62 63 64 ... 97 98

Comentários a estes Manuais

Sem comentários