Enterasys Networks 9034385 Plumbing Product User Manual


 
Model 4: End-System Authorization with Assessment and Remediation
Enterasys NAC Design Guide 2-13
Assistedremediationinformsenduserswhentheirendsystemshavebeenquarantineddueto
networksecuritypolicynoncompliance,andallowsenduserstosafelyremediatetheirnon
compliantendsystemswithoutassistancefromIToperations.Theprocesstakesplacewhenan
endsystemconnectstothenetworkandassessmentis
performed.Enduserswhosesystemsfail
assessmentarenotifiedviawebredirectionthattheirsystemshavebeenquarantined,andare
instructedinhowtoperformselfserviceremediationspecifictothedetectedcompliance
violations.
Oncetheremediationstepshavebeensuccessfullyperformedandtheendsystemiscompliant,
theend
usercaninitiateanondemandreassessmentoftheendsystemandcanbeallocatedthe
appropriatenetworkresources,againwithouttheinterventionofIToperations.
Implementation
InModel4,endsystemscanbedetected,authenticated,assessed,authorized,andremediatedin
differentwaysdependingonthewhetherinlineoroutofbandnetworkaccesscontrolis
implementedintheEnterasysNACsolution.
Out-of-Band NAC
ForoutofbandEnterasysNACdeploymentsutilizingtheNACGateway,NACfunctionsare
implementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐AsdescribedinModel3.
Authorization‐AsdescribedinModel3.
Remediation‐WhenendsystemsarequarantinedbytheNACGateway,
thenetworkmustbe
configuredtodirectalltrafficfromthequarantinedendsystemstotheNACGateway.Thiscanbe
implementedbyconfiguringpolicybasedroutingonarouterinlinewiththetrafficsourcedfrom
quarantinedendsystems.Thisrouterwouldbeconfiguredtosendallwebtrafficfrom
quarantined
endsystemstotheNACGateway,whichthenservesbacktheremediationwebpage
totheenduser.
Thewaytherouteridentifiesthetrafficfromquarantinedendsystemsdiffersbetweenanetwork
composedofpolicyenabledswitchesintheaccessedgeoranetworkcomposedofswitches
implementingRFC
3580dynamicVLANassignmentintheaccessedge.ForanEnterasyspolicy
enablededge,theQuarantinepolicycanbeconfiguredtorewritetheTypeofService(ToS)valueof
HTTPtraffictoaparticularsettingthatmatchesthepolicybasedroutingconfiguration.Foran
RFC3580capableedge,thepolicybased
routingwouldbeconfiguredtomatchthesourceIP
addressoftheHTTPtrafficbeinggeneratedfromthesubnetsthatcorrespondstotheQuarantine
and/orAssessingVLAN.Ineithercase,bydirectingtheHTTPtrafficfromquarantinedend
systemsovertotheNACGateway,theNACGatewaywillserveback
theremediationwebpageto
thenoncompliantendsy stem.