Enterasys-networks 9034385 Instrukcja Użytkownika Strona 34

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 98
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 33
Model 4: End-System Authorization with Assessment and Remediation
2-12 NAC Deployment Models
Required and Optional Components
ThissectionsummarizestherequiredandoptionalcomponentsforModel3.
.
TheNACGatewayandNACControlleraretheNACappliancesusedtoimplementtheoutof
bandandinlinenetworkaccesscontrolfunctionalityonthenetwork.
NetSightNACManageristhesoftwareapplicationusedtocentrallymanagetheNACappliances
deployedonthenetwork.
NetSightConsoleisthesoftwareapplicationusedto
monitorthehealthandstatusof
infrastructuredevicesinthenetwork,includingswitches,routers,andEnterasysNACappliances
(NACGatewaysandNACControllers).
Assessmentfunctionalityisrequiredbecauseinthisdeploymentmodel,connectingendsystems
arebeingassessedforsecurityposturecompliance.
ARADIUSserverisonlyrequiredifoutof
bandnetworkaccesscontrolviatheNACGatewayis
implementedwithwebbasedand/or802.1Xauthentication.
NetSightPolicyManagerisrequiredforallinlineNACdeployments,andrecommendedforout
ofbandNACdeploymentsthatutilizeEnterasyspolicycapableswitches.PolicyManager
providestheabilitytocentrallydefineandconfigurethe
authorizationlevelsorpolicies.
NetSightInventoryManagerisanoptionalcomponent,providingcomprehensivenetwork
inventoryandchangemanagementcapabilities.
Model 4: End-System Authorization with Assessment and
Remediation
ThisNACdeploymentmodelimplementsallfiveNACfunctions:detection,authentication,
assessment,authorization,andremediation.InModel3,endsystemsandendusersconnectedto
thenetworkareauthorizedbasedonthedeviceidentity,useridentity,location,and/orsecurity
postureinformation.And,asexplainedinModel3,itwasnotnecessary
toquarantine
noncompliantendsystemswhilephasingintheNACsolutiononthenetwork.However,oncea
restrictiveauthorizationlevelisallocatedtononcompliantendsystems,itisimportanttoinform
theenduseroftherestrictionsandprovidethestepstheycanexecuteforselfrepairofthedevice.
Thisistheprocessofassistedremediation,whichistheNACfunctionintroducedinModel4.
Table 2-3 Component Requirements for Authorization with Assessment
Component
Authorization with
Assessment
NAC Appliance Required
NetSight NAC Manager Required
NetSight Console Required
Assessment Service Required
RADIUS Server Optional
NetSight Policy Manager Optional
NetSight Inventory Manager Optional
Przeglądanie stron 33
1 2 ... 29 30 31 32 33 34 35 36 37 38 39 ... 97 98

Komentarze do niniejszej Instrukcji

Brak uwag