Enterasys Networks 9034385 Plumbing Product User Manual


 
Scenario 1: Intelligent Wired Access Edge
3-4 Use Scenarios
Scenario 1 Implementation
Intheintelligentwirededgeusescenario,thefiveNACfunctionsareimplementedinthe
followingmanner:
1.Detection‐Theuserʹsendsystemconnectstothenetwork.TheedgeswitchsendsaRADIUS
authenticationrequest(802.1X,webbased,orMACauthentication)withtheassociated
credentialstotheNACGateway.
2.Authentication
‐Iftheendsystemisauthenticatingtothenetworkusing802.1Xorwebbased
authentication,theNACGatewayproxiestheRADIUSa uthenti cationrequesttoabackend
authentication(RADIU S)servertovalidatetheidentityoftheenduser/device.Forendsystems
thatareMACauthenticatingtothenetwork,theNACGateway
canbeconfiguredtoeitherproxy
theMACauthenticationrequeststotheRADIUSserverorlocallyauthorizeMACauthentication
requests.IfonlyMACauthenticationisdeployedonthenetwork,andtheNACGatewayis
configuredtolocallyauthorizeMACauthenticationrequests,abackendRADIUSserverisnot
requiredfortheEnterasys
NACsolution.
3.Assessment‐Aftertheidentityoftheendsystemorenduserisvalidatedviaauthentication,
theNACGatewayrequestsanassessmentoftheendsystemaccordingtopredefinedsecurity
policyparameters.Theassessmentcanbeagentbasedoragentless,andisexecutedlocallybythe
NACGateway
ʹsassessmentfunctionalityand/orremotelybyapoolofassessmentservers.
4.Authorization‐Onceauthenticationandassessmentarecomplete,theNACGatewayallocates
theappropriatenetworkresourcestotheendsystembasedonauthenticationand/orassessment
results.ForEnterasyspolicyenablededgeswitches,theNACGatewayformatsinformationinthe
RADIUS
authenticationmessagesthatdirectstheedgeswitchtodynamicallyassignaparticular
policytotheconnectingendsystem.ForRFC3580capableedgeswitches,theNACGateway
formatsinformationintheRADIUSauthenticationmessages(intheformofRFC3580VLAN
Tunnelattributes)thatdirectstheedgeswitchtodynamically
assignaparticularVLANtothe
connectingendsystem.Ifauthenticationfailsand/ortheassessmentresultsindicatea
noncompliantendsystem,theNACGatewaycaneitherdenytheendsystemaccesstothe
networkbysendingaRADIUSaccessrejectmessagetotheedgeswitch,orquarantinethe end
systemby
assigningaQuarantinepolicyorVLANtotheendsystemontheedgeswitch.
5.Remediation‐Whenthequarantinedenduseropensawebbrowsertoanywebsite,itstrafficis
dynamicallyredirectedtoaRemediationwebpagethatdescribesthecomplianceviolationsand
providesremediationsstepsfortheuser
toexecuteinordertoachievecompliance.Aftertaking
theappropriateremediationsteps,theenduserclicksonabuttononthewebpagetoreattempt
networkaccess,forcingthereassessmentoftheendsystem.Atthispoint,theEnterasysNAC
solutiontransitionstheendsystemthroughtheentire
NACcycleofdetection,authentication,
assessment,andauthorization,reassessingthesecuritypostureoftheendsystemtodetermineif
theremediationstepsweresuccessfullyfollowed.Iftheendsystemisnowcompliantwith
networksecuritypolicy,theNACGatewayauthorizestheendsystemwiththeappropriatepolicy
orVLAN.If
theendsystemisnotcompliant,theendsystemisrestrictedaccesstothenetwork
andtheprocessstartsagain.
Itisimportanttonotethatifthewirededgeofthenetworkisnonintelligent(unmanaged
switchesandhubs)andisnotcapableofauthenticatingandauthorizinglocallyconnectedend
systems,itispossibletoaugmentthenetworktopologytoallowimplementationofoutofband
NACwiththeNACGateway.Thiscanbeaccomplishedwithoutreplacingthephysicaledgeofthe
network,byaddinganintelligentedgeswitchthatpossessesspecializedauthenticationand
authorizationfeatures.
TheEnterasysMatrixN
seriesswitchiscapableofauthenticatingandauthorizingnumerousend
systemsconnectedonasingleportthroughitsMultiUserAuthentication(MUA)functionality
andmaybepositionedupstreamfromnonintelligentthirdpartyedgedevicestoactasthe