Specifications

Summary
1-10 Overview
NetSight Console
NetSightConsoleisusedtomonitorthehealthandstatusofinfrastructuredevicesinthenetwork,
includingswitches,routers,EnterasysNACappliances(NACGatewaysandNACControllers)as
wellasothersecurityappliances.NetSightNACManagerisaplugintoNetSightConsole,and
NetSightConsolemustbeinstalledonaserver
withNACManagerfortheEnterasysNAC
solution.
NetSight Policy Manager
TheNetSightPolicyManagerapplicationprovidestheabilitytocentrallydefineandconfigurethe
authorizationlevelsor“policies”forcertainNACdeployments.PolicyManagerisrequiredfor
inlineNACdeployments,andprovidestheabilitytoconfigureandmanagepoliciesontheNAC
Controllerappliance.PolicyManagerisrecommendedforoutof
bandNACdeploymentsthat
includeEnterasyspolicyenabledswitchesintheaccesslayer,andprovidestheabilitytocentrally
managepoliciesontheseswitches.ThiscentraladministrationofpoliciesusingPolicyManager
includesdistributionofthe“EnterpriseUser,”“A s se s s i n g , “Quarantine,”and“Failsafe”policy
rolestothepolicyenforcementpoints.
NetSight Inventory Manager
TheNetSightInventoryManagerapplicationisanoptionalcomponentoftheNACsolution,
providingcomprehensivenetworkinventoryandchangemanagementcapabilitiesforyour
networkinfrastructure.
RADIUS Server
ARADIUSserverwithbackenddirectoryservicesmustbeimplementedintheNACsolutionif
802.1Xorwebbased(PWA)authenticationofendsystemsisutilizedwithoutofbandnetwork
accesscontrol.
Furthermore,ifRADIUSisutilizedforauthenticatingmanagementloginsforinfrastructure
devices,aRADIUSservermustbedeployed
onthenetwork.
Assessment Server
IftheNACdeploymentmodelincludesvulnerabilityassessment,oneormoreassessmentservers
mustbedeployedontheenterprisenetworkeitherasintegratedcomponentsoftheNAC
applianceorasexternalassessmentservices.
Summary
TheEnterasysNACsolutionsupportsthefivekeynetworkaccesscontrolfunctions:detection,
authentication,assessment,authorization,andremediation.FourNACdeploymentmodels
providesupportfordiverseenterpriseenvironments,witheachmodelimplementingparticular
aspectsofNACfunctionality.
•Model1:EndSystemDetectionandTracking‐Implementsdetectiontoprovidevisibilityinto
what
devicesareconnectingtothenetwork,whoisusingthesedevices,andwherethe
devicesareconnected.
•Model2:EndSystemAuthorization‐Implementsdetection,authentication,andauthorizationto
providenetworkaccesscontrolbasedonuserandendsystemidentityandlocation.