Introduction To Nac; Web Authentication; Figure 2-1 Typical Networking Of Nac - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

2 NAC Configuration

2.1 Introduction to NAC

This section describes the working principle of NAC.
Traditional network security technologies focus on the threat brought by external computers,
rather than the threat brought by internal computers. In addition, the current network devices
cannot prevent the attacks initiated by the internal devices on the network. Network Access
Control (NAC) is an architecture of secure access, with the end-to-end security concept. NAC
considers the internal network security from the perspective of user terminals, rather than
network devices.

Figure 2-1 Typical networking of NAC

As shown in
the following parts:
l
l
l

2.1.1 Web Authentication

2.1.2 802.1x Authentication
2.1.3 MAC Address Authentication
2.1.1 Web Authentication
Web authentication is also called Portal authentication. When opening a browser for the first
time and entering a URL, users are forcibly re-directed to the authentication page of the Web
2-2
User
Figure
2-1, NAC, as a controlling scheme for network security access, includes
User: Access users who need to be authenticated. If 802.1x is adopted for user
authentication, users need to install client software.
NAD: Network access devices, including routers and switches (hereinafter referred to as
the S9300), which are used to authenticate and authorize users. The NAD needs to work
with the AAA server to prevent unauthorized terminals from accessing the network,
minimize the threat brought by insecure terminals, prevent unauthorized access requests
from authorized terminals, and thus protect core resources.
ACS: Access control server that is used to check terminal security and health, manage
policies and user behaviors, audit rule violations, strengthen behavior audit, and prevent
malicious damages from terminals.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
NAD
S9300
Configuration Guide - Security
ACS
Remediation
server
AAA server
Directory
server
PVS & Aduit
server
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents