Enterasys Networks 9034385 Plumbing Product User Manual


 
Summary
Enterasys NAC Design Guide 1-11
•Model3:EndSystemA ut horizationwithAssessment‐Implementsdetection,authentication,
assessment,andauthorizationtoprovidenetworkaccesscontrolbasedonthesecurityposture
ofaconnectingendsystem,aswellasuseranddeviceidentityandlocation.Thismodel
requirestheuseofeitherintegratedassessmentserverfunctionalityor
theabilitytoconnectto
externalassessmentservices,inordertoperformtheendsystemassessment.
•Model4:EndSystemA ut horizationwithAssessmentandRemediation‐Implements
detection,authentication,assessment,authorization,andremediation,providingtheadditional
abilitytoquarantineandremediatenoncompliantdevices.
TheNACapplianceisacorecomponent
oftheEnterasysNACsolutionandisrequiredforall
NACdeploymentmodels.Itprovidestheabilitytodetect,authenticate,andauthorizeenddevices
attemptingtoconnecttothenetwork.Italsointegrateswithorconnectstoassessmentservicesto
performassessmentofendsystemsconnectingtothenetwork.Onceauthentication
and
assessmentarecomplete,theNACapplianceauthorizesdevicesonthenetworkbyallocatingthe
appropriatenetworkresourcestotheendsystembasedonauthenticationand/orassessment
results.TheNACappliancealsoprovidesremediationfunctionality,allowingenduserstosafely
remediatetheirquarantinedendsystemwithoutimpactingIToperations.
Enterasysoffers
twotypesofNACappliances:
•TheNACGatewayapplianceimplementsoutofbandnetworkaccesscontrolandrequires
theimplementationofintelligentwiredorwirelessedgeinfrastructuredevicesonthe
network.
•TheNACControllerapplianceimplementsinlinenetworkaccesscontrolandisapplicableto
scenarioswherenonintelligentwiredorwireless
edgeinfrastructuredevicesaredeployedin
thenetwork.TheNACControllerisalsorequiredinIPSecandSSLVPNdeployments.
TheNACappliancesareconfigured,monitored,andmanagedthroughEnterasysNetSight
managementapplications.NetSightNACManagerandNetSightConsolearerequiredforallfour
NACdeploymentmodels.NACManagerprovides
configurationsfortheassessment,
authentication,authorization,andremediationparametersforallNACappliances,whileNetSight
Consoleisusedtomonitorthehealthandstatusofinfrastructuredevicesinthenetwork,
includingswitches,routers,andEnterasysNACappliances.
NetSightPolicyManagerandNetSightInventoryManagerareoptionalNetSightapplications.
PolicyManagerprovides
theabilitytocentrallydefineandconfiguretheauthorizationlevelsor
“policies”forcertainoutofbandNACdeploymentsandallinlineNACdeployments.Inventory
Managerprovidescomprehensivenetworkinventoryandchangemanagementcapabilitiesfor
yournetworkinfrastructure.
ThenextchapterprovidesamoredetaileddescriptionofthefourNACdeployment
models
includingtheirrequirementsandimplementation.