Enterasys Networks 9034385 Plumbing Product User Manual


 
Model 4: End-System Authorization with Assessment and Remediation
2-14 NAC Deployment Models
Inline NAC
ForinlineEnterasysNACdeploymentsutilizingtheLayer2orLayer3NACController,theNAC
functionsareimplementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐AsdescribedinModel3.
Authorization‐AsdescribedinModel3.
Remediation‐Whenanendsystemis
quarantinedbytheNACController,allwebtrafficsourced
fromthequarantinedendsystemisredirectedtothelocalRemediationWebServicerunningon
theNACController.TheNACControllerthenreturnstheremediationwebpagetothe
noncompliantendsystem.Noadditionalconfigurationsarerequiredonthenetworkbecause
the
NACControllerexistsinlinewiththetrafficfromquarantinedendsystems.
Features and Value
InadditiontothefeaturesandvaluesfoundinModel1,Model2,andModel3,thefollowingare
keypiecesoffunctionalityandvaluepropositionssupportedbyModel4,EndSystem
AuthorizationwithAssessmentandRemediation:
Self-Service Remediation
IfauserʹsPCissuddenlyquarantinedandtheuserisnotabletoaccesstheexpectedtypesof
services,itisnotonlyimportantthatinformationofthiseventisavailabletoIT,butalsothat
theuserisdirectlynotifiedofthecauseofservicedisruption.Ifthey
arenotnotifiedaboutthe
quarantineaction,theuserwilllikelybelievethatthereisanetworkcommunicationproblem.
ImplementingaNACsolutionthatcanquarantineuserswithoutnotification,may
inadvertentlyincreasecallstotheIThelpdeskfromuserswhoarenotabletoaccessneeded
services.
WiththeEnterasys
NACsolution,networkbasednotificationandremediationareintegrated.
Onceanendsystemisputintoaquarantinestate,notificationisachievedbyredirectingthe
noncompliantendsystemʹswebtraffictoaremediationwebpage.Thewebpagecanbe
maintainedbytheITorganizationandcaninclude
detailsaboutwhytheendsystemhasbeen
quarantinedandhowausercanfixissuesthatarecausingthenoncompliantstate.Thelayout
andinformationpresentedonthiswebpageisfullycustomizableincludingchangingheader
andfooterinformation,alteringinformationpresentedtotheuser,andcontrollingtheamount
oftimeorthenumberoftimesanendsystemisallowedtoinitiatereassessmentafter
attemptingremediation.
Althoughtheendsystemmaybeabletoaccessthenetworkandtheremediationwebpage,
communicationisprovisionedthroughasetofpolicyrulestoensurethatthereisnodanger
to
therestofthe network.Inorderforaquarantinedusertoregainaccesstonetworkservices,
theymustfirstremediatetheproblemthatactuallycausedthequarantinetooccurinthefirst
place.However,remediationdoesnotalwayshavetobemadeavailabletotheuser.Consider
thesituation
whereauserisactingmaliciouslyandthreateningthenetworkanditsservices.
Remediationmaynotbedesirable,andinsteadapersistentquarantinepolicymaybeenforced
tokeeptheuserfromcausinganyharm.
Thekeytothisprocessistheabilityofthenetworktoenforceausagepolicy
thatcompletely
protectsallcriticalresourcesandotherusers,butallowsaccesstokeyremediationassetssuch
aswebserverswithsecuritypatches.TheEnterasysNACsolutionallowsaquarantinepolicy
tobeestablishedwithaveryspecificsetofpolicyrulesthatcanfilterandcontrolnetwork