Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống
1
/ 571 trang
THÔNG TIN TÀI LIỆU
Thông tin cơ bản
Định dạng
Số trang
571
Dung lượng
22,19 MB
Nội dung
[...]... Solution 15 CiscoNAC Integrated Implementation CiscoNACAppliance Overview CiscoNAC Return on Investment Summary 16 16 17 18 Part II The Blueprint: Designing a CiscoNACAppliance Solution 21 Chapter 3 The Building Blocks in a CiscoNACAppliance Design 23 CiscoNACAppliance Solution Components 23 CiscoNACAppliance Manager 24 CiscoNACAppliance Server 25 CiscoCleanAccess Agent 28 CiscoNAC Appliance. .. ApplianceHostSecurity Policy 123 What Makes Up a CiscoNACApplianceHostSecurity Policy? 123 HostSecurity Policy Checklist 124 Involving the Right People in the Creation of the HostSecurity Policy 124 xiii Determining the High-Level Goals for HostSecurity Common High-Level HostSecurity Goals 127 Defining the Security Domains 126 129 Understanding and Defining NACAppliance User Roles Built-In... Appliance Network Scanner 29 CiscoNACAppliance Minimum Requirements 30 CiscoNACAppliance Manager and Server Requirements CiscoCleanAccess Agent Requirements 32 Scalability and Performance of CiscoNACAppliance Summary Chapter 4 31 33 33 Making Sense of All the CiscoNACAppliance Design Options 35 NAC Design Considerations 35 Single-Sign-On Capabilities 36 In-Band Versus Out-of-Band Overview 36 7 9... L3 OOB 75 Client Certification and Post-Certification Steps in L3 OOB 76 Advantages of Using Out-of-Band Mode 77 Disadvantage of Using Out-of-Band Mode 78 xii Where You Can Use Out-of-Band Mode and Where You Cannot Switches Supported by NACAppliance Out-of-Band 78 CleanAccess Agent and Web Login with Network Scanner Summary Chapter 5 78 81 85 Advanced CiscoNACAppliance Design Topics 87 External Authentication... Admission Control (NAC) ApplianceCiscoNAC Appliance, formerly known as CiscoClean Access, provides a powerful hostsecurity policy inspection and enforcement mechanism designed to meet these new challenges CiscoNACAppliance allows organizations to enforce their hostsecurity policies on all hosts (managed and unmanaged) as they enter the interior of the network, regardless of their access method,... Traffic Policies 226 IP-Based Traffic Control Policy 227 Host- Based Traffic Control Policy 229 Bandwidth Policies 230 219 xv Customizing User Pages and Guest Access Login Pages 232 Guest Access 236 API for Guest Access 236 Summary Chapter 9 232 237 Host Posture Validation and Remediation: CiscoCleanAccess Agent and Network Scanner 239 Understanding CiscoNACAppliance Setup CiscoNACAppliance Updates... Strict Mode for CleanAccess Agent 41 How to Choose a Network Mode 42 Virtual Gateway Mode 42 Real IP Gateway Mode 43 In-Band Mode 43 The Certification Process in In-Band Mode 44 Certification Steps for HostwithCleanAccess Agent 44 Steps for Client to Acquire an IP Address 44 CleanAccess Agent Authentication Steps 45 CleanAccess Agent HostSecurity Posture Assessment Steps 45 CleanAccess Agent Network... Port (eth1) of NACAppliance Server 283 Configuring Fa1/0/5—The Interface Connecting the Host 283 Configuring Simple Network Management Protocol 283 Step 2: Configuring NACAppliance Manager 284 Step 3: Configuring NACAppliance Server 286 Step 4: Logging In to NACAppliance Manager 288 Step 5: Adding NACAppliance Server to NACAppliance Manager 289 Step 6: Editing Network Settings on NACAppliance Server... I The HostSecurity Landscape 3 Chapter 1 The Weakest Link: Internal Network Security 5 Security Is a Weakest-Link Problem 6 Hard Outer Shell with a Chewy Inside: Dealing with Internal Security Risks The Software Update Race: Staying Ahead of Viruses, Worms, and Spyware Summary Chapter 2 10 Introducing Cisco Network Admission Control Appliance 13 CiscoNAC Approaches 13 NAC as an Appliance 13 NAC as... Manager and Server 411 Adding NACAppliance Managers in High Availability Mode 412 Adding a CA-Signed Certificate to the Primary NACAppliance Manager 413 Generating a Self-Signed Temporary Certificate on the Primary NACAppliance Manager 414 Adding a Certificate to the Secondary NACAppliance Manager 415 Configuring High Availability for NACAppliance Managers 416 Adding NACAppliance Servers in High . Components 23 Cisco NAC Appliance Manager 24 Cisco NAC Appliance Server 25 Cisco Clean Access Agent 28 Cisco NAC Appliance Network Scanner 29 Cisco NAC Appliance Minimum Requirements 30 Cisco NAC Appliance. Introducing Cisco Network Admission Control Appliance 13 Cisco NAC Approaches 13 NAC as an Appliance 13 NAC as an Embedded Solution 15 Cisco NAC Integrated Implementation 16 Cisco NAC Appliance. V Cisco NAC Appliance Deployment Best Practices 443 Chapter 13 Deploying Cisco NAC Appliance 445 Part VI Cisco NAC Appliance Monitoring and Troubleshooting 461 Chapter 14 Understanding Cisco NAC