
Secure Networks Policy Support
Enterasys NAC Controller Hardware Installation Guide 1-7
Standalone or Rack Mountable Chassis
TheEnterasys NAC Controllercanbeinstalledasafreestandingunitonashelfortable.Itcanalso
bemountedintoastandard48.26‐centimeter(19‐inch)equipmentrack.Referto“SiteGuidelines”
onpage 2‐1forrequirementsonventilationandcooling.
Secure Networks Policy Support
AfundamentalconceptthatiskeytotheimplementationoftheEnterasysSecureNetworks
methodologyispolicy‐enablednetworking.Thisapproachprovidesusersofthenetworkwiththe
resourcestheyneed‐inasecurefashion–whileatthesametimedenyingaccesstoapplicationsor
protocolsthataredeemedinappropriate
basedontheuser’sfunctionwithintheorganization.By
adoptingsucha“user‐personalized”model,itispossibleforbusinesspoliciestobetheguidelines
inestablishingthetechnologyarchitectureoftheenterprise.Twomajorobjectivesareachievedin
thisway:ITservicesarematchedappropriatelywithindividualusers;and
thenetworkitself
becomesanactiveparticipantintheorganization’ssecuritystrategy.TheSecureNetworks
architectureconsistsofthreetiers:
• Classificationrulesmakeupthefirstorbottomtier.TherulesapplytodevicesintheSecure
Networksenvironment,suchasswitchesandrouters.Therulesaredesignedtobe
implemented
atorneartheuser’spointofentrytothenetwork.Rulesmaybewrittenbased
oncriteriadefinedintheLayer2,Layer3orLayer4informa tionofthedataframe.
•ThemiddletierisServices,whicharecollectionsofindividualclassificationrules,grouped
logicallytoeitherpermit
ordenyaccesstoprotocolsorapplicationsbasedontheuser’srole
withintheorganization.Priorityandbandwidthratelimitingmayalsobedefinedinservices.
•Roles,orbehavioralprofiles,makeupthetoptier.Therolesassignservicestovarious
businessfunctionsordepartments,suchasexecutive,sales,andengineering.
Toenhancesecurityanddeliveratruepolicy‐basedinfrastructure,theEnterasysSecureNetworks
methodologycantakeadvantageofauthenticationmethods,suchas802.1X,usingEAP‐TLS,
EAP‐TTLS,orPEAP,aswellasothertypesofauthentication.Authorizationinformation,attached
totheauthenticationresponse,determinestheapplicationofpolicy.
Authorizationinformationis
communicatedviathepolicynameinaRADIUSFilter‐IDattribute.Anadministratorcanalso
definearoletobeimplementedintheabsenceofanauthenticationframework.Refertothe
releasenotesshippedwiththemodulefordetails.
Standards Compatibility
TheNACControllerPEPsarefullycompliantwiththeIEEE802.3‐2002,802.3ae‐2002,
802.1D‐1998,and802.1Q‐1998standards.TheNACControllerPEPprovidesIEEE802.1D‐1998
SpanningTreeAlgorithm (STA)supporttoenhancetheoverallreliabilityofthenetworkand
protectagainst“loop”conditions.
LANVIEW Diagnostic LEDs
TheNACControllerPEPusesabuilt‐invisualdiagnosticandstatusmonitoringsystemcalled
LANVIEW.TheLANVIEWLEDsallowquickobservationofthenetworkstatustoaidin
diagnosingnetworkproblems.“LANVIEWLEDs”onpage 2‐2for informationaboutusingthe
LEDsfortroubleshooting.