Enterasys-networks 9034385 Manual do Utilizador Página 87

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 98
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 86
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-23
Itisimportanttonotethatonly theNACGatewaysthatareconfiguredwithremediationand
registrationfunctionalityneedtobepositionedinsuchamanner.AllotherNACGatewaysmay
bepositionedatanylocationonthenetwork,withtheonlyrequirementbeingthataccesslayer
switchesareableto
communicatetothegateways.Typically ,theNACGatewaywithremediation
andregistrationfunctionalityispositionedonanetworksegmentdirectlyconnectedtothe
distributionlayerroutersontheenterprisenetwork,sothatanyHTTPtrafficsourcedfrom
quarantinedendsystemsthatareconnectedtothenetworkʹsaccesslayercan
beredirectedtothat
NACGateway.Asanalternative,theNACGatewaymaybepositionedonanetworksegment
directlyconnectedtotherouterprovidingconnectivitytotheInternetorinternalwebserverfarm.
Inthisscenario,theHTTPtrafficsourcedfromquarantinedendsystemswouldberedirectedto
theNAC
GatewaybeforereachingtheInternetorinternalwebservers.
4. Identify Backend RADIUS Server Interaction
IfaNACGatewayisreceiving802.1Xand/orwebbasedauthenticationrequestsforconnecting
endsystems,thenabackendRADIUSservermustbeconfiguredtovalidateendusercredentials
intheauthenticationprocess.ForeachNACGateway,aprimaryandsecondaryRADIUSserver
canbespecifiedforthevalidationofuser/device
networklogincredentialsonthenetwork.
If802.1X,webbased,orRADIUSauthenticationforswitchmanagementloginsisimplemented,a
RADIUSserverwithbackenddirectoryservicesmustbedeployedonthenetwork.ARADIUS
serverisnotnecessaryifonlyMACauthenticationisdeployedonthenetwork.
AllRADIUSserverssupporting
RFC2865andsubsequentRADIUSstandardsaresupportedby
EnterasysNACapplianceswhenproxyingRADIUSauthenticationrequests.Testshavebeen
conductedonthefollowingRADIUSservers:
FreeRADIUS
•MicrosoftIAS
•FunkSteelbeltedRADIUS
•CiscoACS
5. Determine End-System Mobility Restrictions
WhileSecurityDomainspecificMACanduseroverridescanbeconfiguredtocontrolendsystem
andendusermobilityacrossthenetworkandbetweenSecurityDomains,the“LockMAC”
featureallowsthenetworkadministratortorestrictnetworkaccessforspecificendsystemtoa
switchportorswitch.Theendsystem
canbedeniednetworkaccesswithaRADIUSAccessReject
messagereturnedtotheswitch,orassignedaspecificpolicyorVLANwhenconnectingtothe
networkinarestrictedarea.HerearesomeexamplesofhowtheLockMACfeaturecanbeused:
•Aprinter,server,orotherendsystem
couldbeallowednetworkaccessonlywhenitis
connectedtoaports p ecifiedbyIToperations.Thispreventssecurityissuesthatcouldresultif
thedevicewasmovedtoadifferentareaofthenetwork.
•AnIPphonewithaMACoverridecouldbelockedtoaspecificporton
aswitch.Thiswould
allowexactidentificationofthephoneʹslocationincaseanemergency(911)callwasplaced
fromthephone.
Vista de página 86
1 2 ... 82 83 84 85 86 87 88 89 90 91 92 ... 97 98

Comentários a estes Manuais

Sem comentários