Enterasys Networks 7KR4297-02 Switch User Manual


 
Secure Networks Policy Support
1-4 Introduction
Secure Networks Policy Support
PolicyEnabledNetworkingmanagestheallocationofnetworkinginfrastructureresourcesina
secureandeffectivemanner.UsingSecureNetworksPolicy,anITAdministratorcanpredictably
assignappropriateresourcestotheUsers,Applications,andServicesthatusethenetwork;while
blockingorcontainingaccessforinappropriateorpotentiallydangerousnetworktraffic.Using
thistechnologyitispossible,forthefirsttime,toalignITserviceswiththeneedsofspecificusers
andapplications,andtoleveragethenetworkasakeycomponentoftheorganization’ssecurity
strategy.
TheSecureNetworksPolicyArchitectureconsistsof3components:ClassificationRules,Network
Services,andBehavioralProfiles.
Thesearedefinedasfollows:
ClassificationRulesdeterminehowspecifictrafficflows(identifiedbyLayer2,Layer3,and
Layer4informationinthedatapacket)aretreatedbyeachSwitch orRouter.Ingeneral,
ClassificationRulesareappliedtothenetworkinginfrastructureatthenetworkedge/ingress
point.
•NetworkServicesare
logicalgroupsofClassificationRulesthatidentifyspecificnetworked
applicationsorservices.Usersmaybepermittedordeniedaccesstotheseservicesbasedon
theirrolewithintheorganization.Priorityandbandwidthratelimitingmayalsobecontrolled
usingNetworkServices.
•BehavioralProfiles(orroles)areusedtoassignNetworkServices
togroupsofuserswho
sharecommonneeds–forexampleExecutiveManagers,HumanResourcesPersonnel,or
GuestUsers.Access,resources,andsecurityrestrictionsareappliedasappropriatetoeach
BehavioralProfile.Avarietyofauthenticationmethodsincluding802.1X,EAPTLS,EAP
TTLS,andPEAPmaybeusedtoclassifyandauthorizeeach
individualuser;andtheIT
AdministratormayalsodefineaBehavioralProfiletoapplyintheabsenceofan
authenticationframework.
Standards Compatibility
TheDFEDiamondmodulesarefullycompliantwiththeIEEE802.32002,802.3ae2002,
802.1D1998,and802.1Q1998standards.TheDFEDiamondmoduleprovidesIEEE802.1D1998
SpanningTreeAlgorithm(STA)supporttoenhancetheoverallreliabilityofthenetworkand
protectagainst“loop”conditions.
LANVIEW Diagnostic LEDs
LANVIEWdiagnosticLEDsserveasanimportanttroubleshootingaidbyprovidinganeasyway
toobservethestatusofindividualportsandoverallnetworkoperations.