Cisco Network Admission Control, Volume I: NAC Framework Architecture and Design
暫譯: 思科網路准入控制,第壹卷:NAC框架架構與設計

Denise Helfrich, Lou Ronnau, Jason Frazier, Paul Forbes

  • 出版商: Cisco Press
  • 出版日期: 2006-12-18
  • 售價: $1,820
  • 貴賓價: 9.5$1,729
  • 語言: 英文
  • 頁數: 244
  • 裝訂: Paperback
  • ISBN: 1587052415
  • ISBN-13: 9781587052415
  • 相關分類: Cisco
  • 立即出貨(限量) (庫存=1)

買這商品的人也買了...

相關主題

商品描述

Description

Cisco Network Admission Control

Volume I: NAC Framework Architecture and Design

 

A guide to endpoint compliance enforcement

 

Today, a variety of security challenges affect all businesses regardless of size and location. Companies face ongoing challenges with the fight against malware such as worms, viruses, and spyware. Today’s mobile workforce attach numerous devices to the corporate network that are harder to control from a security policy perspective. These host devices are often lacking antivirus updates and operating system patches, thus exposing the entire network to infection. As a result, worms and viruses continue to disrupt business, causing downtime and continual patching. Noncompliant servers and desktops are far too common and are difficult to detect and contain. Locating and isolating infected computers is time consuming and resource intensive.

 

Network Admission Control (NAC) uses the network infrastructure to enforce security policy compliance on all devices seeking to access network computing resources, thereby limiting damage from emerging security threats. NAC allows network access only to compliant and trusted endpoint devices (PCs, servers, and PDAs, for example) and can restrict the access of and even remediate noncompliant devices.

 

Cisco Network Admission Control, Volume I, describes the NAC architecture and provides an in-depth technical description for each of the solution components. This book also provides design guidelines for enforcing network admission policies and describes how to handle NAC agentless hosts. As a technical primer, this book introduces you to the NAC Framework solution components and addresses the architecture behind NAC and the protocols that it follows so you can gain a complete understanding of its operation. Sample worksheets help you gather and organize requirements for designing a NAC solution.

 

Denise Helfrich is a technical program sales engineer that develops and supports global online labs for the World Wide Sales Force Development at Cisco®.

 

Lou Ronnau, CCIE® No. 1536, is a technical leader in the Applied Intelligence group of the Customer Assurance Security Practice at Cisco.

 

Jason Frazier is a technical leader in the Technology Systems Engineering group for Cisco.

 

Paul Forbes is a technical marketing engineer in the Office of the CTO, within the Security Technology Group at Cisco. 

 

  • Understand how the various NAC components work together to defend your network
  • Learn how NAC operates and identifies the types of information the NAC solution uses to make its admission decisions
  • Examine how Cisco Trust Agent and NAC-enabled applications interoperate
  • Evaluate the process by which a policy server determines and enforces a policy
  • Understand how NAC works when implemented using NAC-L2-802.1X, NAC-L3-IP, and NAC-L2-IP
  • Prepare, plan, design, implement, operate, and optimize a network admission control solution

  

This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.

 

商品描述(中文翻譯)

**描述**

Cisco 網路存取控制

第一卷:NAC 框架架構與設計

端點合規性執行指南

今天,各種安全挑戰影響所有企業,無論其規模和地點。公司在對抗惡意軟體(如蠕蟲、病毒和間諜軟體)方面面臨持續的挑戰。當今的行動工作力將許多設備連接到企業網路,這些設備從安全政策的角度來看更難以控制。這些主機設備通常缺乏防毒更新和作業系統修補,從而使整個網路暴露於感染的風險中。因此,蠕蟲和病毒持續干擾業務,造成停機和不斷的修補。未合規的伺服器和桌面電腦過於普遍,且難以檢測和控制。定位和隔離受感染的電腦既耗時又資源密集。

網路存取控制(NAC)利用網路基礎設施來強制執行所有尋求訪問網路計算資源的設備的安全政策合規性,從而限制新興安全威脅造成的損害。NAC 只允許合規且受信任的端點設備(例如 PC、伺服器和 PDA)訪問網路,並可以限制甚至修復不合規的設備。

《Cisco 網路存取控制》第一卷描述了 NAC 架構,並為每個解決方案組件提供深入的技術描述。本書還提供了強制執行網路存取政策的設計指南,並描述如何處理無 NAC 代理的主機。作為技術入門書籍,本書介紹了 NAC 框架解決方案組件,並探討了 NAC 背後的架構及其遵循的協議,以便您能夠全面了解其運作。範本工作表幫助您收集和組織設計 NAC 解決方案的需求。

Denise Helfrich 是一名技術計畫銷售工程師,負責開發和支持 Cisco® 全球在線實驗室,服務於全球銷售力發展部門。

Lou Ronnau,CCIE® 編號 1536,是 Cisco 客戶保證安全實踐的應用智能小組中的技術領導者。

Jason Frazier 是 Cisco 技術系統工程小組的技術領導者。

Paul Forbes 是 Cisco 安全技術小組首席技術官辦公室的技術行銷工程師。

- 了解各種 NAC 組件如何協同工作以保護您的網路
- 學習 NAC 如何運作並識別 NAC 解決方案用於做出存取決策的資訊類型
- 檢視 Cisco Trust Agent 和 NAC 啟用應用程式如何互操作
- 評估政策伺服器如何確定和執行政策的過程
- 了解 NAC 在使用 NAC-L2-802.1X、NAC-L3-IP 和 NAC-L2-IP 實施時的運作方式
- 準備、計畫、設計、實施、運作和優化網路存取控制解決方案

本安全書籍是 Cisco Press® 網路技術系列的一部分。Cisco Press 的安全書籍幫助網路專業人員保護關鍵數據和資源,防止和減輕網路攻擊,並建立端到端的自我防禦網路。