Enterasys-networks 9034385 Instrukcja Użytkownika Strona 15

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 98
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 14
NAC Solution Components
Enterasys NAC Design Guide 1-5
EnterasysofferstwotypesofNACappliances:theNACGatewayapplianceimplementsoutof
bandnetworkaccesscontrol,andtheNACControllerapplianceimplementsinlinenetworkaccess
control.ThefollowingsectiondescribeshoweachNACapplianceimplementsnetworkaccess
controlforconnectingendsystems.
NAC Gateway Appliance
TheNACGatewayisutilizedtoimplementoutofbandnetworkaccesscontrolforconnecting
endsystems.WiththeNACGateway,connectingendsystemsaredetectedonthenetwork
throughtheirRADIUSauthenticationinterchange.Basedontheassessmentandauthentication
resultsforaconnectingdevice,RADIUSattributesareaddedormodified
duringthe
authenticationprocesstoauthorizetheendsystemontheauthenticatingedgeswitch.Therefore,
theNACGatewaycanbepositionedanywhereinthenetworktopologywiththeonly
requirementbeingthatIPconnectivitybetweentheauthenticatingedgeswitchesandtheNAC
Gatewaysisoperational.
TheNACGatewayrequirestheimplementation
ofintelligentwiredorwirelessedge
infrastructuredevicesastheauthorizat ion pointforconnectingendsystems.Intelligentedge
devicesarecapableofsupportingauthenticationandauthorizationbasedontheauthentication
messageinterchange.Dependingontheappliancemodel,theNACGatewayprovideseither
integratedassessmentserverfunctionalityand/ortheabilityto
connecttoexternalassessment
services,todeterminethesecuritypostureofendsystemsconnectingtothenetwork.
ThreeNACGatewaymodelsareavailabletomeettheneedsofdifferentsizedimplementa tions
andassessmentserverrequirements.
SNSTAGITAsupportsupto3000concurrentendsystemsandprovidesintegrated
assessmentservers.(A
separatelicenseisrequiredforintegratedassessment.)Thisintegrated
NACGatewaysupportsbothagentless(networkbased)andagentbasedassessment.In
additiontohavingthecapabilitytorunasanintegratedappliance,italsohasthecapabilityto
runasanassessmentserver(scanner)only.TheSNSTAGITAalso
supportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGHPAsupportsupto3000concurrentendsystemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGLPAsupportsupto2000concurrentend
systemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
NAC Controller Appliance
TheNACControllerisutilizedtoimplementinlinenetworkaccesscontrolforconnectingend
systems.WiththeNACController,connectingendsystemsaredetectedthroughthereceiptofa
packetfromanewendsystem.Basedontheassessmentandauthenticationresultsfora
connectingdevice,theauthorizationoftheend
systemisimplementedlocallyontheNAC
Controllerappliancebyassigningasetoftrafficforwardingrules,referredtoas“policy,”toall
trafficsourcedbytheendsystem.TheNACControllerapplianceispositionedstrategicallyinthe
networktopologywithintheenduserLANsegmentoracrossroutedboundaries,
inlinewithdata
trafficsourcedfromendsystems.Sincethisapplianceexistsinthedata pathofnetworked
devices,ithasbeendesignedtoachievemultigigabitthroughputwithhardwarebasedtraffic
forwarding,byleveragingcustomizedEnterasysbuiltApplicationSpecificIntegratedCircuits
(ASICs).
TheNACControllerisapplicabletoscenarioswhere
nonintelligentwiredorwirelessedge
infrastructuredevicesaredeployedinthenetwork.Nonintelligentedgedevicesarenotcapable
Przeglądanie stron 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 97 98

Komentarze do niniejszej Instrukcji

Brak uwag