Enterasys Networks 9034385 Plumbing Product User Manual


 
Summary
1-10 Overview
NetSight Console
NetSightConsoleisusedtomonitorthehealthandstatusofinfrastructuredevicesinthenetwork,
includingswitches,routers,EnterasysNACappliances(NACGatewaysandNACControllers)as
wellasothersecurityappliances.NetSightNACManagerisaplugintoNetSightConsole,and
NetSightConsolemustbeinstalledonaserver
withNACManagerfortheEnterasysNAC
solution.
NetSight Policy Manager
TheNetSightPolicyManagerapplicationprovidestheabilitytocentrallydefineandconfigurethe
authorizationlevelsor“policies”forcertainNACdeployments.PolicyManagerisrequiredfor
inlineNACdeployments,andprovidestheabilitytoconfigureandmanagepoliciesontheNAC
Controllerappliance.PolicyManagerisrecommendedforoutof
bandNACdeploymentsthat
includeEnterasyspolicyenabledswitchesintheaccesslayer,andprovidestheabilitytocentrally
managepoliciesontheseswitches.ThiscentraladministrationofpoliciesusingPolicyManager
includesdistributionofthe“EnterpriseUser,”“As ses si ng, ”“Quarantine,”and“Failsafe”policy
rolestothepolicyenforcementpoints.
NetSight Inventory Manager
TheNetSightInventoryManagerapplicationisanoptionalcomponentoftheNACsolution,
providingcomprehensivenetworkinventoryandchangemanagementcapabilitiesforyour
networkinfrastructure.
RADIUS Server
ARADIUSserverwithbackenddirectoryservicesmustbeimplementedintheNACsolutionif
802.1Xorwebbased(PWA)authentication ofendsystemsisutilizedwithoutofbandnetwork
accesscontrol.
Furthermore,ifRADIUSisutilizedforauthenticatingmanagementloginsforinfrastructure
devices,aRADIUSservermustbedeployed
onthenetwork.
Assessment Server
IftheNACdeploymentmodelincludesvulnerabilityassessment,oneormoreassessmentservers
mustbedeployedontheenterprisenetworkeitherasintegratedcomponentsoftheNAC
applianceorasexternalassessmentservices.
Summary
TheEnterasysNACsolutionsupportsthefivekeynetworkaccesscontrolfunctions:detection,
authentication,assessment,authorization,andremediation.FourNACdeploymentmodels
providesupportfordiverseenterpriseenvironments,witheachmodelimplementingparticular
aspectsofNACfunctionality.
•Model1:EndSystemDetectionandTracking‐Implementsdetectiontoprovidevisibilityinto
what
devicesareconnectingtothenetwork,whoisusingthesedevices,andwherethe
devicesareconnected.
•Model2:EndSystemAuthorization‐Implementsdetection,authentication,andauthorizationto
providenetworkaccesscontrolbasedonuserandendsystemidentityandlocation.