Enterasys Networks 9034385 Plumbing Product User Manual


 
NAC Solution Components
Enterasys NAC Design Guide 1-5
EnterasysofferstwotypesofNACappliances:theNACGatewayapplianceimplementsoutof
bandnetworkaccesscontrol,andtheNACControllerapplianceimplementsinlinenetworkaccess
control.ThefollowingsectiondescribeshoweachNACapplianceimplementsnetworkaccess
controlforconnectingendsystems.
NAC Gateway Appliance
TheNACGatewayisutilizedtoimplementoutofbandnetworkaccesscontrolforconnecting
endsystems.WiththeNACGateway,connectingendsystemsaredetectedonthenetwork
throughtheirRADIUSauthenticationinterchange.Basedontheassessmentandauthentication
resultsforaconnectingdevice,RADIUSattributesareaddedormodified
duringthe
authenticationprocesstoauthorizetheendsystemontheauthenticatingedgeswitch.Therefore,
theNACGatewaycanbepositionedanywhereinthenetworktopologywiththeonly
requirementbeingthatIPconnectivitybetweentheauthenticatingedgeswitchesandtheNAC
Gatewaysisoperational.
TheNACGatewayrequirestheimplementation
ofintelligentwiredorwirelessedge
infrastructuredevicesastheauthorizat ion pointforconnectingendsystems.Intelligentedge
devicesarecapableofsupportingauthenticationandauthorizationbasedontheauthentication
messageinterchange.Dependingontheappliancemodel,theNACGatewayprovideseither
integratedassessmentserverfunctionalityand/ortheabilityto
connecttoexternalassessment
services,todeterminethesecuritypostureofendsystemsconnectingtothenetwork.
ThreeNACGatewaymodelsareavailabletomeettheneedsofdifferentsizedimplementa tions
andassessmentserverrequirements.
SNSTAGITAsupportsupto3000concurrentendsystemsandprovidesintegrated
assessmentservers.(A
separatelicenseisrequiredforintegratedassessment.)Thisintegrated
NACGatewaysupportsbothagentless(networkbased)andagentbasedassessment.In
additiontohavingthecapabilitytorunasanintegratedappliance,italsohasthecapabilityto
runasanassessmentserver(scanner)only.TheSNSTAGITAalso
supportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGHPA supportsupto3000concurrentendsystemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
SNSTAGLPAsupportsupto2000concurrentend
systemsandsupportstheabilityto
connecttomultipleexternalassessmentserversincludingNessu sandLockdownEnforcer.
NAC Controller Appliance
TheNACControllerisutilizedtoimplementinlinenetworkaccesscontrolforconnectingend
systems.WiththeNACController,connectingendsystemsaredetectedthroughthereceiptofa
packetfromanewendsystem.Basedontheassessmentandauthenticationresultsfora
connectingdevice,theauthorizationoftheend
systemisimplementedlocallyontheNAC
Controllerappliancebyassigningasetoftrafficforwardingrules,referredtoas“policy,”toall
trafficsourcedbytheendsystem.TheNACControllerapplianceispositionedstrategicallyinthe
networktopologywithintheenduserLANsegmentoracrossroutedboundaries,
inlinewithdata
trafficsourcedfromendsystems.Sincethisapplianceexistsinthedata pathofnetworked
devices,ithasbeendesignedtoachievemultigigabitthroughputwithhardwarebasedtraffic
forwarding,byleveragingcustomizedEnterasysbuiltApplicationSpecificIntegratedCircuits
(ASICs).
TheNACControllerisapplicabletoscenarioswhere
nonintelligentwiredorwirelessedge
infrastructuredevicesaredeployedinthenetwork.Nonintelligentedgedevicesarenotcapable