Specifications
How Can I Implement Policy?
May 18, 2009 Page 2 of 32
Securitycanbeenhancedbyallowingonlyintendedusersanddevicesaccesstonetwork
protocolsandcapabilities.Someexamplesare:
•EnsuringthatonlyapprovedstationscanuseSNMP,preventingunauthorizedstationsfrom
viewing,reading,andwritingnetworkmanagementinformation
•Preventingedgeclientsfromattachingnetworkservicesthatareappropriatelyrestrictedto
data
centersandmanagedbytheenterpriseITorganizationsuchasDHCPandDNSservices
• IdentifyingandrestrictingroutingtolegitimateroutingIPaddressestopreventDoS,
spoofing,dataintegrityandotherroutingrelatedsecurityissues
•EnsuringthatFTP/TFTPfiletransfersandfirmwareupgradesonlyoriginatefromauthorized
fileandconfigurationmanagement
servers
•PreventingclientsfromusinglegacyprotocolssuchasIPX,AppleTalk,andDECnetthat
shouldnolongerberunningonyournetwork
EnterasysNetSightPolicyManagerprovidesacentralizedpointandclickconfiguration,andone
clickpushingofdefinedpolicyouttoallnetworkelements.UsetheEnterasy sNetSightPolicy
Managerfor
easeofinitialconfigurationandresponsetosecurityandprovisioningissuesthat
maycomeupduringreal‐timenetworkoperation.
How Can I Implement Policy?
Toimplementpolicy:
•Identifytherolesofusersanddevicesinyourorganizationthataccessthenetwork
• Createapolicyroleforeachidentifieduserrole
• Associateclassificationrulesandadministrativeprofileswitheachpolicyrole
• Optionally,configureaclassofserviceandassociateitdirectlywiththepolicyroleorthrough
a
classificationrule
• Optionally,enablehybridauthentication,whichallowsRADIUSfilter‐IDandtunnel
attributestobeusedtodynamicallyassignpolicyrolesandVLANstoauthenticatingusers
• Optionally,setdeviceresponsetoinvalidpolicy
Policy Overview
Introduction
Thissectionprovidesanoverviewofpolicyconfiguration.PolicyisimplementedonanEnterasys
platformbyassociatingusersanddevicesinthenetworkwithdefinedenterpriseroles(suchas
sales,engineering,oradministration)thatareconfiguredinapolicyrole.Thepolicyroleis
associatedwithrulesthatdefinehownetwork
resourceswillbeprovisionedandcontrolledfor
rolemembers,aswellashowsecuritywillbeappliedtotherolemember.Anadministrative
profileassociatesaspecificrolemembertrafficclassificationwithapolicyrole.
Note: In a CLI configuration context, the policy role is configured within a policy profile using the set
policy profile command. Through out this discussion, policy role and policy profile mean the same
thing.