Enterasys Networks 9034385 Plumbing Product User Manual


 
Survey the Network
Enterasys NAC Design Guide 4-7
systematatime, thenitissuggestedthatMAClocking(alsoknownasPortSecurity)beenabled
ontheedgeswitchestorestrictthenumberofconnectingdevices.Ifmultipleendsystem
connectionissupported,thentheintelligentedgeswitchmustsupporttheauthenticationand
authorizationofmultipledevices(possibly
usingmultipleauthenticationmethods)concurrently
onthenetwork.Ifthisisnotsupported,thenasecurityholeexistswhereanoncompliantend
systemcan“piggyback”ontheopennetworkconnectionofacompliantendsystem.
Forexample,NACisoftendeployedonanIPtelephonyconvergednetworkwhereIPphone
handsetsarecascadedwithPCsconnectedtoasingleintelligentedgeinfrastructureport.Ifthe
intelligentedgeinfrastructuredevicesdonotsupporttheauthenticationandauthorizationofboth
thePCandIPphoneconnectedtothesameport,thenanoncompliantPCmaybeallowed
networkaccesswhenthesecurityposture
ofanIPphonethatconnectedtothenetworkfirst,is
deemedcompliant.
Furthermore,iftheauthenticationandauthorization ofmultipledevicesconnectingtoasingle
portisnotsupported,certaindevicesmayloseconnectivitywhenNACisdeployed.Forexample,
anIPphoneʹsnetworkconnectionmaybelostwhen
aPCisquarantinedonthenetwork.
Authentication Support on Enterasys Devices
Followingisinformationontheauthenticati onsupportprovidedbyEnterasysdevices:
•TheMatrixNseriesMultiUserAuthentication(MUA)featureallowstheenablingofany
combinationofauthenticationmethods(802.1X,webbased,and/orMAC)bothgloballyand
perport.WhiletheMatrixNseriesGoldsupportstheauthenticationandauthorizationof
two
users/devicesperport,theMatrixNseriesPlatinumsupportstheauthenticationand
authorizationofover2000usersanddevicesperport,providingthehighestdegreeof
authenticationmethodconfiguration flexibility.
•TheSecureStackC2/C3andB2/B3User+IPPhoneauthenticationallowstheconfigurationof
multipleauthenticationmethodsgloballyandper
port(802.1X,webbased,and/orMAC)with
thelimitationofaPCandanIPphoneauthenticatingonasingleport.
•TheMatrixE1ʹsHybridauthenticationallowstheenablingofboth802.1XandMAC
authenticationonthesameport,andsupportstheauthenticationofasingleendsystemusing
only
oneoftheseauthenticationmethodsatatime.
•Ifwebbasedauthenticationisgloballyenabled onthe MatrixE1andtheMatrixEseries
Generation2/3platforms,eachportontheswitch canonlybeconfiguredtoimplementweb
basedauthentication.
Authentication Considerations
Ifauthenticationiscurrentlydeployedonthenetwork,hereareconsiderationsthatshouldbe
reviewedasyouplanyourNACdeployment:
•EnterasysNACwillseamlesslyintegratewithdeploymentswheretheauthenticatingand
authorizationoftrustedusersisalreadyimplemented.EnterasysNACcanbeconfiguredto
forwardtheRADIUSFilterIDand/or
VLANTunnelattributereturnedfromtheRADIUS
servertotheaccesslayerswitchduringtheauthenticationprocess.
•IfguestaccessisimplementedonthenetworkbyassigningadefaultpolicyorVLANon
certainports(assumingguestuserswillfailauthenticationonthenetwork),theinfrastructure
willneedtobereconfigured
toimplementNACforguestusers.EnterasysNACwillnot
assessorauthorizeendsystemsthatonlyfailauthenticationagainstabackendRADIUS
server.ToenableEnterasysNACtointeractwithguestusersonthenetwork,MAC
authenticationmustbeenabledonportswhereguestusersconnecttothenetwork,and
EnterasysNACmustbeconfiguredtolocallyauthorizeMACauthenticationrequestsand
assigntheappropriateguestauthorizationlevel.Then,guestuserswillbesuccessfullyMAC