Enterasys Networks 9034385 Plumbing Product User Manual


 
Out-of-Band NAC Design Procedures
Enterasys NAC Design Guide 5-23
Itisimportanttonotethatonly theNACGatewaysthatareconfiguredwithremediationand
registrationfunctionalityneedtobepositionedinsuchamanner.AllotherNACGatewaysmay
bepositionedatanylocationonthenetwork,withtheonlyrequirementbeingthataccesslayer
switchesareableto
communicatetothegateways.Typically ,theNACGatewaywithremediation
andregistrationfunctionalityispositionedonanetworksegmentdirectlyconnectedtothe
distributionlayerroutersontheenterprisenetwork,sothatanyHTTPtrafficsourcedfrom
quarantinedendsystemsthatareconnectedtothenetworkʹsaccesslayercan
beredirectedtothat
NACGateway.Asanalternative,theNACGatewaymaybepositionedonanetworksegment
directlyconnectedtotherouterprovidingconnectivitytotheInternetorinternalwebserverfarm.
Inthisscenario,theHTTPtrafficsourcedfromquarantinedendsystemswouldberedirectedto
theNAC
GatewaybeforereachingtheInternetorinternalwebservers.
4. Identify Backend RADIUS Server Interaction
IfaNACGatewayisreceiving802.1Xand/orwebbasedauthenticationrequestsforconnecting
endsystems,thenabackendRADIUSservermustbeconfiguredtovalidateendusercredentials
intheauthenticationprocess.ForeachNACGateway,aprimaryandsecondaryRADIUSserver
canbespecifiedforthevalidationofuser/device
networklogincredentialsonthenetwork.
If802.1X,webbased,orRADIUSauthenticationforswitchmanagementloginsisimplemented,a
RADIUSserverwithbackenddirectoryservicesmustbedeployedonthenetwork.ARADIUS
serverisnotnecessaryifonlyMACauthenticationisdeployedonthenetwork.
AllRADIUSserverssupporting
RFC2865andsubsequentRADIUSstandardsaresupportedby
EnterasysNACapplianceswhenproxyingRADIUSauthenticationrequests.Testshavebeen
conductedonthefollowingRADIUSservers:
FreeRADIUS
•MicrosoftIAS
•FunkSteelbeltedRADIUS
•CiscoACS
5. Determine End-System Mobility Restrictions
WhileSecurityDomainspecificMACanduseroverridescanbeconfiguredtocontrolendsystem
andendusermobilityacrossthenetworkandbetweenSecurityDomains,the“LockMAC”
featureallowsthenetworkadministratortorestrictnetworkaccessforspecificendsystemtoa
switchportorswitch.Theendsystem
canbedeniednetworkaccesswithaRADIUSAccessReject
messagereturnedtotheswitch,orassignedaspecificpolicyorVLANwhenconnectingtothe
networkinarestrictedarea.HerearesomeexamplesofhowtheLockMACfeaturecanbeused:
•Aprinter,server,orotherendsystem
couldbeallowednetworkaccessonlywhenitis
connectedtoaportspecifiedbyIToperations.Thispreventssecurityissuesthatcouldresultif
thedevicewasmovedtoadifferentareaofthenetwork.
•AnIPphonewithaMACoverridecouldbelockedtoaspecificporton
aswitch.Thiswould
allowexactidentificationofthephoneʹslocationincaseanemergency(911)callwasplaced
fromthephone.