4.3. Enforcement Time
After you define the policy, you decide how and where to enforce your policies. Enforcement gives your network access control policies teeth, so to speak, allowing them to have meaning and purpose on the network.
|
4.3.1. Endpoint
Endpoint enforcement, the most basic form of enforcement, involves the endpoint client enforcing policy that the policy engine pushes. The enforcement can be network-access-based or software-based. For network-access-based enforcement on the endpoint, the endpoint client restricts or changes access for a network user based on a policy that the policy engine sends. Endpoint enforcement can use a couple of different methods, but the most common method uses a software firewall-based approach. The other method of enforcement is software based, which is limited only by your imagination. For example, the software based approach can block certain applications from running or start a virtual desktop.
|
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access
