Enterasys Networks 9034385 Plumbing Product User Manual


 
Model 3: End-System Authorization with Assessment
Enterasys NAC Design Guide 2-9
serverisrunningoriftheHTTPserverisoutofdate)and clientsidechecks(running
applications,softwareconfigurations,installedoperatingsystempatches)providedendsystem
administrativecredentialsareavailableforremotelogintoconnectingdevices.Additionally,the
NACGatewayʹslocalassessmentservicesalsoincludeagentbasedassessmentusing
aJavaWeb
Startbasedclientapplicationthatallowsexecutionofserversideandclientsidecheckswithout
requiringadministrativecredentialsorspecialhostfirewallconfigurations.
TheNACGatewayʹsremoteassessmentservicesincludeagentlessandagentbasedassessment
onotherNACGatewaysdeployedonthenetworkand/orthird
partyvulnerabilityscannerssuch
asNessusandLockdownEnforcer.Asendsystemsconnecttothenetwork,assessmentscanbe
loadbalancedamongalloftheconfiguredassessmentservicesoradefinedpool.Thisprovides
maximumscalabilityandflexibility,andminimizes theamountoftimenecessarytocompletean
endsystemassessment.
Authorization‐TheNACGatewayallocatestheappropriatenetworkresourcestotheendsystem
basedonauthentication,location,and/orassessmentresults.For Enterasyspolicyenablededge
switches,theNACGatewayformatsinformationintheRADIUSauthenticationmessagesthat
directstheedgeswitchtodynamicallyassignaparticularpolicytotheconnectingend
system.For
RFC3580capableedgeswitches,theNACGatewayformatsinformationintheRADIUS
authenticationmessagesintheformofRFC3580VLANTunnelattributesthat directstheedge
switchtodynam icallyassignaparticularVLANtotheconnectingendsystem.Ifauthentication
failsand/ortheassessmentresultsindicate
anoncompliantendsystem,theNACGatewaycan
eitherdenytheendsystemaccesstothenetworkbysendingaRADIUSaccessrejectmessageto
theedgeswitchorquarantinetheendsystemwithahighlyrestrictivesetofnetworkresources(or
possiblypermitnetworkaccess)byspecifyingaparticularpolicy
orVLANtoassigntothe
authenticatedendsystemontheedgeswitch.
Inline NAC
ForinlineEnterasysNACdeploymentsutilizingtheLayer2orLayer3NACController,theNAC
functionsareimplementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐TheNACControllercanleverageeitherlocalassessmentservicesand/orremote
assessmentservicesdeployedonthe
network,aspreviouslydescribedfortheNACGateway.The
NACControllerʹslocalassessmentservicesincludeagentlessassessmentwhichcanexecute
variousserversidechecksandclientsidechecks.Localassessmentservicesalsoincludeagent
basedassessmentusingaJavaWebStartbasedclientapplicationthatallowsexecutionofserver
sideandclientsidechecks.TheNACControllerʹsremoteassessmentservicesincludeagentless
andagentbasedassessmentwithNACGatewaysand/orthirdpartyvulnerabilityscannerssuch
asNessusandLockdownEnforcer.Asendsystemsconnecttothenetwork,assessmentcanbe
loadbalancedamongalloftheconfigured
assessmentservicestoprovidemaximumscalability
andflexibilitywhileminimizingassessmenttimes.
Authorization‐TheNACControllerallocatestheappropriatenetworkresourcestotheend
systembasedonauthenticationand/orassessmentresults.Thisisimplementedbyassigninga
policytotrafficsourcedfromtheendsystemlocallyonthecontroller.Ifauthentication
failsand/
ortheassessmentresultsindicateanoncompliantendsystem,theNACControllercaneither
denytheendsystemaccesstothenetwork,quarantinetheendsystemwithahighlyrestrictiveset
ofnetworkresources,orpermitnetworkaccessbyspecifyingaparticularpolicy.