Specifications

How Can I Implement Policy?
May 18, 2009 Page 2 of 32
Securitycanbeenhancedbyallowingonlyintendedusersanddevicesaccesstonetwork
protocolsandcapabilities.Someexamplesare:
•EnsuringthatonlyapprovedstationscanuseSNMP,preventingunauthorizedstationsfrom
viewing,reading,andwritingnetworkmanagementinformation
•Preventingedgeclientsfromattachingnetworkservicesthatareappropriatelyrestrictedto
data
centersandmanagedbytheenterpriseITorganizationsuchasDHCPandDNSservices
IdentifyingandrestrictingroutingtolegitimateroutingIPaddressestopreventDoS,
spoofing,dataintegrityandotherroutingrelatedsecurityissues
•EnsuringthatFTP/TFTPfiletransfersandfirmwareupgradesonlyoriginatefromauthorized
fileandconfigurationmanagement
servers
•PreventingclientsfromusinglegacyprotocolssuchasIPX,AppleTalk,andDECnetthat
shouldnolongerberunningonyournetwork
EnterasysNetSightPolicyManagerprovidesacentralizedpointandclickconfiguration,andone
clickpushingofdefinedpolicyouttoallnetworkelements.UsetheEnterasy sNetSightPolicy
Managerfor
easeofinitialconfigurationandresponsetosecurityandprovisioningissuesthat
maycomeupduringrealtimenetworkoperation.
How Can I Implement Policy?
Toimplementpolicy:
•Identifytherolesofusersanddevicesinyourorganizationthataccessthenetwork
Createapolicyroleforeachidentifieduserrole
Associateclassificationrulesandadministrativeprofileswitheachpolicyrole
Optionally,configureaclassofserviceandassociateitdirectlywiththepolicyroleorthrough
a
classificationrule
Optionally,enablehybridauthentication,whichallowsRADIUSfilterIDandtunnel
attributestobeusedtodynamicallyassignpolicyrolesandVLANstoauthenticatingusers
Optionally,setdeviceresponsetoinvalidpolicy
Policy Overview
Introduction
Thissectionprovidesanoverviewofpolicyconfiguration.PolicyisimplementedonanEnterasys
platformbyassociatingusersanddevicesinthenetworkwithdefinedenterpriseroles(suchas
sales,engineering,oradministration)thatareconfiguredinapolicyrole.Thepolicyroleis
associatedwithrulesthatdefinehownetwork
resourceswillbeprovisionedandcontrolledfor
rolemembers,aswellashowsecuritywillbeappliedtotherolemember.Anadministrative
profileassociatesaspecificrolemembertrafficclassificationwithapolicyrole.
Note: In a CLI configuration context, the policy role is configured within a policy profile using the set
policy profile command. Through out this discussion, policy role and policy profile mean the same
thing.