Enterasys-networks 9034385 Manuale Utente Pagina 90

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 98
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 89
Out-of-Band NAC Design Procedures
5-26 Design Procedures
Figure 5-6 Policy Role Configuration in NetSight Policy Manager
Assessment Policy
TheAssessmentPolicymaybeusedtotemporarilyallocate asetofnetworkresourcestoend
systemswhiletheyarebeingassessed.ForEnterasyspolicyenabledswitches,acorresponding
policyrole(createdinPolicyManager)shouldallocatetheappropriatesetofnetworkresources
neededbytheassessmentservertosuccessfullycomplete
itsendsystemassessment,while
restrictingtheendsystemʹsaccesstothenetwork.Forexample,iftheassessmentserveris
configuredtoscanforFTPvulnerabilities,andtheAssessmentPolicydoesnotallowFTPtr affic
fromtheendsystemontothenetwork,thentheassessmentserverwillnotdetect
theFTP
vulnerabilitiesontheendsystem.
Toachievethistradeoff,theAssessingpolicyrolecanbeconfiguredbydefaulttodenyalltraffic,
andbeassociatedtoclassificationrulesthatpermittraffictoallassessmentservers,using
destinationIPaddressPermitclassificationrules,asshowninFigure57.
Therefore,alltraffic
involvedwiththeendsystemʹsassessmentisallowedontothenetwork.Inaddition,otherbasic
networkservicessuchasARP,DHCP,andDNSareallowedontothenetworksotheendsystem
canestablishIPconnectivityinthenetworkwhilebeingassessed.
TheAssessmentPolicycanalso
beconfiguredtoimplementwebnotificationduringtheexecution
oftheassessment,toinformtheenduserthataccesstothenetworkhasbeentemporarily
restrictedwhiletheassessmenttakesplace.ThisisimplementedbyallowingHTTPtrafficontothe
networkinadditiontotheotherservicespreviouslydescribe d.
Vedere la pagina 89
1 2 ... 85 86 87 88 89 90 91 92 93 94 95 96 97 98

Commenti su questo manuale

Nessun commento