Enterasys 2S4082-25-SYS Instalační příručka Strana 27

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 108
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 26
Secure Networks Policy Support
Enterasys NAC Controller Hardware Installation Guide 1-7
Standalone or Rack Mountable Chassis
TheEnterasys NAC Controllercanbeinstalledasafreestandingunitonashelfortable.Itcanalso
bemountedintoastandard48.26centimeter(19inch)equipmentrack.RefertoSiteGuidelines
onpage 21forrequirementsonventilationandcooling.
Secure Networks Policy Support
AfundamentalconceptthatiskeytotheimplementationoftheEnterasysSecureNetworks
methodologyispolicyenablednetworking.Thisapproachprovidesusersofthenetworkwiththe
resourcestheyneed‐inasecurefashionwhileatthesametimedenyingaccesstoapplicationsor
protocolsthataredeemedinappropriate
basedontheusersfunctionwithintheorganization.By
adoptingsucha“userpersonalized”model,itispossibleforbusinesspoliciestobetheguidelines
inestablishingthetechnologyarchitectureoftheenterprise.Twomajorobjectivesareachievedin
thisway:ITservicesarematchedappropriatelywithindividualusers;and
thenetworkitself
becomesanactiveparticipantintheorganization’ssecuritystrategy.TheSecureNetworks
architectureconsistsofthreetiers:
Classificationrulesmakeupthefirstorbottomtier.TherulesapplytodevicesintheSecure
Networksenvironment,suchasswitchesandrouters.Therulesaredesignedtobe
implemented
atorneartheuserspointofentrytothenetwork.Rulesmaybewrittenbased
oncriteriadefinedintheLayer2,Layer3orLayer4informa tionofthedataframe.
•ThemiddletierisServices,whicharecollectionsofindividualclassificationrules,grouped
logicallytoeitherpermit
ordenyaccesstoprotocolsorapplicationsbasedontheusersrole
withintheorganization.Priorityandbandwidthratelimitingmayalsobedefinedinservices.
•Roles,orbehavioralprofiles, makeupthetoptier.Therolesassignservicestovarious
businessfunctionsordepartments,suchasexecutive,sales,andengineering.
Toenhancesecurityanddeliveratruepolicybasedinfrastructure,theEnterasysSecureNetworks
methodologycantakeadvantageofauthenticationmethods,suchas802.1X,usingEAPTLS,
EAPTTLS,orPEAP,aswellasothertypesofauthentication.Authorizationinformation,attached
totheauthenticationresponse,determinestheapplicationofpolicy.
Authorizationinformationis
communicatedviathepolicynameinaRADIUSFilterIDattribute.Anadministratorcanalso
definearoletobeimplementedintheabsenceofanauthenticationframework.Refertothe
releasenotesshippedwiththemodulefordetails.
Standards Compatibility
TheNACControllerPEPsarefullycompliantwiththeIEEE802.32002,802.3ae2002,
802.1D1998,and802.1Q1998standards.TheNACControllerPEPprovidesIEEE802.1D1998
SpanningTreeAlgorithm (STA)supporttoenhancetheoverallreliabilityofthenetworkand
protectagainst“loop”conditions.
LANVIEW Diagnostic LEDs
TheNACControllerPEPusesabuiltinvisualdiagnosticandstatusmonitoringsystemcalled
LANVIEW.TheLANVIEWLEDsallowquickobservationofthenetworkstatustoaidin
diagnosingnetworkproblems.LANVIEWLEDsonpage 22for informationaboutusingthe
LEDsfortroubleshooting.
Zobrazit stránku 26
1 2 ... 22 23 24 25 26 27 28 29 30 31 32 ... 107 108

Komentáře k této Příručce

Žádné komentáře