3.2. Taking Inventory
Your users and machines go through the first phase of the NAC lifecycle — assessment — when they attempt to join your network and access network resources, as shown in Figure 3-2.
Typically, this step involves two primary sets of policies:
User or machine identity
Machine security posture
In some instances, you might also want to include other environmental factors related to your policy.
Figure 3.2. The basic steps of NAC implementation.
3.2.1. User and machine identity
Knowing who's on your network is a key advantage of deploying NAC.
In today's environment, mobile users, authorized third parties, and users on non-standard corporate devices make it more and more difficult to figure out exactly who's accessing your corporate resources. NAC allows you to
Determine who's using which machine
Tie that information to specific policies for that user's access
When a user first comes onto the corporate network, the NAC system authenticates him or her.
NOTE
Authentication can take many forms — ranging from a statically defined user name and password, to more complex forms such as biometric identification and X.509 digital certificates. Regardless of the credentials used, the goal of authentication is to prove beyond reasonable doubt that people coming onto your network are who they say they are.
The same authentication holds true for machines, too:
In some cases, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access