Enterasys Networks 9034385 Plumbing Product User Manual


 
Scenario 2: Intelligent Wireless Access Edge
3-8 Use Scenarios
Scenario 2 Implementation
Intheintelligentwirelessaccessedgeusescenario,thefiveNACfunctionsareimplementedinthe
followingmanner:
1.Detection‐Theuserʹsendsystemconnectstothenetwork.ThewirelessswitchorthickAP
sendsaRADIUSauthenticationrequest(802.1X,webbased,orMACauthentication)withthe
associatedcredentialsto
theNACGateway.
2.Authentication‐Iftheendsystemisauthenticatingtothe networkusing802.1Xorwebbased
authentication,theNACGatewayproxiestheRADIUSa uthenti cationrequesttoabackend
authentication(RADIU S)servertovalidatetheidentityoftheenduser/device.Forendsystems
thatareMACauthenticatingtothe
network,theNACGatewaymaybeconfiguredtoeitherproxy
theMACauthenticationrequeststotheRADIUSserver,orlocallyauthorizeMACauthentication
requests.IfonlyMACauthenticationisdeployedonthenetworkandtheNACGatewayis
configuredtolocallyauthorizeMACauthenticationrequests,abackendRADIUSserverisnot
requiredwiththeEnterasysNACsolution.
3.Assessment‐Aftertheidentityoftheendsystemorenduserisvalidatedviaauthentication,
theNACGatewayrequestsanassessmentoftheendsystemaccordingtopredefinedsecurity
policyparameters.Theassessmentcanbeagentbasedoragentless,andisexecutedlocally
bythe
NACGatewayʹsassessmentfunctionalityand/orremotelybyapoolofassessmentservers.
4.Authorization‐Onceauthenticationandassessmentarecomplete,theNACGatewayallocates
theappropriatenetworkresourcestotheendsystembasedonauthenticationand/orassessment
results.ForEnterasyspolicyenabledwirelessswitchesandaccesspoints,the
NACGateway
formatsinformationintheRADIUSauthenticationmessagesthatdirectstheedgeswitchto
dynamicallyassignaparticularpolicytothewirelessendsystemonthewirelessswitchorAP,
dependingonthetypeofwirelessimplementation.ForRFC3580capablewirelessswitchesand
APs,theNACGatewayformats
informationintheRADIUSauthenticationmessages(intheform
ofRFC3580VLANTunnelattribut es)thatdirectstheedgeswitchtodynamicallyassigna
particularVLANtothewirelessendsystem.Ifauthenticationfailsand/ortheassessmentresults
indicateanoncompliantendsystem,theNACGatewaycaneitherdenytheend
systemaccessto
thenetworkbysendingaRADIUSaccessrejectmessage,orquarantinetheendsystemby
assigningaQuarantinepolicyorVLANtothewirelessendsystem.
5.Remediation‐Whenthequarantinedenduseropensawebbrowsertoanywebsite,itstrafficis
dynamicallyredirectedtoa
Remediationwebpagethatdescribesthecomplianceviolationsand
providesremediationsstepsfortheusertoexecuteinordertoachievecompliance.Aftertaking
theappropriateremediationsteps,theenduserclicksonabuttononthewebpagetoreattempt
networkaccess,forcingthereassessmentoftheend
system.Atthispoint,theEnterasysNAC
solutiontransitionstheendsystemthroughtheentireNACcycleofdetection,authentication,
assessment,andauthorization,reassessingthesecuritypostureoftheendsystemtodetermineif
theremediationtechniquesweresuccessfullyfollowed.Iftheendsystemisnowcompliantwith
networksecurity
policy,theNACGatewayauthorizestheendsystemwiththeappropriateaccess
policy.Iftheendsystemisnotcompliant,theendsystemisrestrictedaccesstothenetworkand
theprocessstartsagain.