Enterasys Networks 9034385 Plumbing Product User Manual


 
Inline NAC Design Procedures
5-32 Design Procedures
3. Identify Backend RADIUS Server Interaction
Layer2NACControllersdetectdownstreamendsystemsviaauthentication:MAC,webbased,or
802.1X.Ifwebbasedor802.1X authenticationisimplemented,thenabackendRADIUSserver
mustbeconfiguredtovalidateendusercredentialsintheauthenticationprocess.ForeachLayer2
NACController,primaryandsecondaryRADIUSservers
maybespecifiedforthevalidationof
user/devicenetworklogincredentialsonthenetwork.
4. Define Policy Configuration
PoliciesareassignedtodownstreamendsystemsontheNACControllertoauthorizeconnecting
deviceswithalevelofnetworkaccess.Adefaultsetofpoliciesareautomaticallyconfiguredon
eachNACControllerafterinstallationandinitializationoftheappliance.Thissetofpolicies
includesallpoliciesdefinedbydefaultin
NACManager,suchasEnterpriseUser,Quarantine,
Assessing,Unregistered,andFailsafe.Itisstronglyrecommendedthatthepolicyconfigurations
ofallNACControllersareimportedintoNetSightPolicyManager,reviewed,andappropriately
modified,priortothefullrolloutofinlineNAC.
Failsafe Policy and Accept Policy Configuration
TheFailsafePolicyisassignedtoendsystemswhenanerroroccursintheNACprocess.The
FailsafepolicyroleisconfiguredbydefaultontheNACControllertobeusedastheFailsafe
PolicyinNACManager.Thispolicyisrestrictive,allowingDNSandDHCP,andredirectingweb
trafficto
servebackawebpagestatinganerrorhasoccurredonthenetwork,whilediscardingall
othertypesoftraffic.
Ifitisdesiredtoopennetworkaccesswhenanerrorisencountered,theEnterpriseUserpolicy
rolecanbeselectedastheFailsafePolicyintheNACConfiguration.The
EnterpriseUserpolicy
roleisfairlyopen,permittingmosttypesofcommunicationontothenetwork.Forsecurity
purposestheEnterpriseUserpolicyroledoesdenycommunicationtotheNACControllerover
TCPandUDPports(utilizedforadministrativepurposes,suchasRADIUSandSSH).Inaddition,
theEnterpriseUserpolicydiscards
allcommunicationtoNACManagerʹsIPaddressforfurther
securityhardening.Thispolicyrolecanbealteredtofurthercontrolwhichservicesacompliant
endsystemisallowedtoutilize.
TheAcceptPolicyisassignedtoendsystemswhentheyaredeemedcompliant.TheEnterprise
Userpolicyroleisconfigured
bydefaultontheNACControllertobeusedastheAcceptPolicyin
NACManager.
Assessment Policy and Quarantine Policy Configuration
TheAssessmentPolicyandQuarantinePolicyareusedwhenendsystemassessmentis
implementedintheNACdeployment.TheAssessmentPolicymaybeusedtotemporarilyallocate
asetofnetworkresourcestoendsystemswhiletheyarebeingassessed.TheAssessingpolicyrole
isconfiguredbydefaultonNACControllers
tobeusedastheAssessmentPolicyinNAC
Manager.ThispolicyallowsDNSandDHCP,andanytrafficdestinedtotheIPaddressofthe
assessmentserversdeployedonthenetwork.Thepolicyalsoredirectswebtraffictoservebacka
webpagestatingthattheendsystemhas
beenrestrictedaccesswhileitssecuritypostureisbeing
determined.Allothertypesoftrafficarediscarded.
Ifitisdesiredtoopennetworkaccesswhileanendsystemisbeingassessed,theuseofthe
AssessmentPolicycanbedisabledintheNACconfiguration,ortheEnterpriseUserpolicyrole
canbeselectedastheAssessmentPolicyinstead.ItisimportanttonotethatwheneveraNAC
configurationisenforcedtotheNACController,theAssessmentPolicyisconfiguredtoallow