Enterasys Networks 9034385 Plumbing Product User Manual


 
Enterasys NAC Design Guide 1-1
1
Overview
ThischapterprovidesanoverviewoftheEnterasysNetworkAccessControl(NAC)solution,
includingadescriptionofkeyNACfunctionsanddeploymentmodels.Italsointroducesthe
requiredandoptionalcomponentsoftheEnterasysNACsolution,andpresentsacomparison
betweentheinlineNACControllerforimplementationofinlinenetworkaccess
controlandthe
outofbandNACGatewayforimplementationofoutofbandnetworkaccesscontrol.
NAC Solution Overview
EnterasysNACisacentralizednetworkaccesscontrolsolutionthatcombinesauthentication,
vulnerabilityassessment,andlocationservicestoauthorizenetworkaccessanddeterminethe
appropriatelevelofserviceforanendsystem.TheNACsolutionensuresthatonlyvalidusers
anddevicesconnectingattheproperlocation,attherighttime,
andwithappropriatesecurity
postures,aregrantedaccesstoyournetwork.Forendsys temswhicharenotcompliantwith
definedsecurityguidelines,theNACsolutionprovidesassistedremediation,allowingendusers
toperformselfservicerepairstepsspecifictothedetectedcomplianceviolation.
Key Functionality
TheEnterasysNACsolutionsupportsthefivekeynetworkaccesscontrolfunctions:detection,
authentication,assessment,authorization,andremediation.Thesefivefunctionscanbedeployed
invariouscombinations,asdescribedinthefollowing sectionondeploymentmodels.
HereisadescriptionofthefivekeyNACfunctions:
Detection
Identifywhenandwhereadeviceconnectstothenetwork.
Authentication
Verifytheidentityoftheuserordeviceconnectingtothenetwork.EnterasysNACsupportsthe
“passthrough”authentication(proxyingtoabackendRADIUSserver)of802.1X,webbased
(PWA),andMACauthenticationrequests,aswellaslocalMACauthentication.Thisprovides
accesscontrolforbothusercentricandmachinecentric
endsystemsintheenterprise
environment.
For information about... Refer to page...
NAC Solution Overview 1-1
NAC Solution Components 1-4
Summary 1-10