Enterasys Networks 9034385 Plumbing Product User Manual


 
Scenario 4: VPN Remote Access
3-12 Use Scenarios
Figure 3-6 VPN Remote Access
Scenario 4 Implementation
IntheVPNremoteaccessusescenario,thefiveNACfunctionsareimplementedinthefollowing
mannerwiththedeploymentoftheNACControllerforinlinenetworkaccesscontrol.
1.Detection‐TheuserʹsendsystemsuccessfullyestablishesaVPNtunnelwiththeVPN
concentrator,andtheVPNconcentratortransmitsunencrypted
datatrafficontothenetworkthat
traversestheNACController.ThistrafficissourcedfromanIPaddressnotpreviouslyseenbythe
controller.
2.Authentication‐AuthenticationismostlikelydisabledaltogetherontheNACController,
trustingthatthedownstreamVPNconcentratorauthenticatedtheconnectinguser.
3.Assessment‐TheNACControllerrequests
anassessmentoftheendsystemaccordingto
predefinedsecuritypolicyparameters.Theassessmentcanbeagentbasedoragentless,andis
executedlocallybytheNACControllerʹsassessmentfunctionalityand/orremotelybyapoolof
assessmentservers.
4.Authorization‐Onceauthenticationandassessmentarecomplete,theNACController
allocatestheappropriatenetworkresourcestotheendsystembasedonauthenticationand/or
assessmentresults.ThisisimplementedlocallyontheNACControllerbyassigningapolicyto
trafficsourcedfromtheendsystem.Ifauthenticationfailsand/ortheassessmentresultsindicatea
noncompliantendsystem,theNACControllercan
eitherdenytheendsystemaccesstothe
network,orquarantinetheendsystembyassigningaparticularpolicyonthecontroller.
1
3
3
5
Enterasys
NAC Manager
NAC
Controller
(inline appliance)
Assessment
Server
Role=Quarantine
1
2
3
4
5
NAC Functions
Detect
Authenticate
Assess
Authorize
Remediate
VPN Concentrator
Remediation
Web Page
3
4