Enterasys Networks 9034385 Plumbing Product User Manual


 
Survey the Network
4-2 Design Planning
accesstoawebbrowsertosafelyremediatetheirquarantinedendsystemwithoutimpacting
IToperations.
Onceadeploymentmodelisselected,thecurrentnetworkinfrastructuremustbeexaminedto
identifythetechnicaldependenciesandrequirementsimposedbytheNACsolution.
Survey the Network
Thestepsinthissectionwillhelpyouidentifyandevaluatethecurrentnetworkinfrastructureso
thatyoucanmakedesigndecisionsregardingNACcomponentrequirements.
1. Identify the Intelligent Edge of the Network
Thefirststepinsurveyingyournetworkistodeterminewhetherornotyournetworkhasan
“intelligentedge.”ThisinformationwillhelpyoudecidewhethertheNACGatewayorNAC
Controllerappliancebestsuitsyournetworkinfrastructure.
Theterm“intelligent”referstoanetworktopologywheretheaccessedgeis
composedof
Enterasyspolicyenabledswitchescapableofsupportingauthenticationandpolicyenforcement,
orthirdpartyswitchescapableofsupportingauthenticationanddynamicVLAN assignmentas
definedinRFC3580.
Nonintelligentinfrastructuredevices,suchasrepeatersandhubs,arenotcapableofsupporting
authenticationand/orauthorizat ion ofendsystems,and
simplyprovideconnectivitytothe
infrastructure.
AnintelligentedgeisrequiredwhentheNACGatewayisutilizedforimplementingoutofband
NAC.TheNACGatewayapplianceleveragestheintelligentedgeofthenetworktoimplementthe
authenticationandauthorizationofconnectingendsystems.TheNACGatewayeffectsthe
assignmentof
policiesorVLANsonEnterasysswitchesorRFC3580capableswitcheslocatedat
edgeofthenetwork,toauthorizealevelofnetworkaccesstoconnectingendsystems.These
assignmentsarebasedonvariousparameters,suchasthelocationoftheendsystemandsecurity
postureassessmentresults.Theintelligentedge
ofthenetworkalsoimplementsanauthentication
method(802.1X,webbased,orMACauthentication)forvalidatingthedeviceand/oruseridentity
ofconnectingendsystems.
However,innetworkswithnonintelligentdevicesattheaccessedge,itisnotnecessarytoreplace
thesenonintelligentdevicestobeabletoimplement
outofbandNACwiththeNACGateway.
Instead,theEnterasysMatrixNseriesswitchcanbepositionedupstreamfromnonintelligent
devices(suchasinthedistributionlayer)toimplementtheauthenti cationandauthorization
functionsfordownstreamconnecteddevices.MatrixNSeriesdevicessupportMultiUser
Authentication(MUA)which
enablestheswitchtoindividuallyauthenticateanduniquely
authorizemultipleendsystemsconnectedtothesamephysicalport.MUAontheMatrixNseries
Platinumsupportstheconcurrentauthenticationandauthorizationofover1000endsystemsona
singleportwiththeallocationofdisparatenetworkresourcestoeachendsystem.
Inthiscase,the
MatrixNseriesswitchistheintelligentedgeofthenetworkalthoughitisnotphysicallylocatedin
theaccesslayer.ByutilizingtheMatrixNseriesinthistypeofconfiguration,mostofthebenefits
ofoutofbandNACcanbeobtainedwithoutupgrading
theedgeofthenetwork.