Aruba Networks Palo Alto Networks Скачать руководство пользователя страница 5

 

Amigopod 

|Technical Note

 

 

Palo Alto Networks User-ID Services

|

5

 

2

 

About Palo Alto Networks User-ID Services 

Overview 

Palo Alto Networks have developed a range of Next Generation firewalls that redefine the 
best practice for controlling and securing today’s networks. Leveraging their core 
strengths of Application, User and Content Identification, Palo Alto Networks provides a 
unique approach to addressing the challenges surrounding Web 2.0 applications and peer 
to peer communications which dominate the concerns of IT Administrators. 

 

Palo Alto Networks define their User-ID technology as offering the following benefits in a 
traditional enterprise environment: 

User-ID seamlessly integrates Palo Alto Networks firewalls with Microsoft Active 
Directory (AD), enabling administrators to tie network activity to users and groups – 
not just IP addresses. When used in  conjunction with App-ID and Content-ID 
technologies, IT organizations can leverage user and group information for visibility, 
policy creation, forensic investigation and reporting on application, threat, web 
surfing and data transfer activity.    

User-ID  helps address the challenge of using IP addresses to monitor and control 
the activity of specific network users – something that was once a fairly simple task, 
but has become difficult as enterprises moved to an Internet and web-centric model.  

Compounding  the visibility problem is an increasingly mobile enterprise, where 
employees access the network from virtually anywhere around the world, internal 
wireless networks re-assign IP addresses as users move from zone to zone, and 
network users are not always company employees. The result is that the IP address 
is now an inadequate mechanism for monitoring and controlling user activity.  

Amigopod, with the introduction of the Palo Alto Networks User-ID Services plugin, can 
now extend this visibility to include non-corporate users typically associated with 
Enterprise Guest Access deployments, Hotels, Conference venues, Airports and other 
Hotspot style deployments. 

 

Содержание Palo Alto Networks

Страница 1: ...Palo Alto Networks User ID Services Unified Visitor Management...

Страница 2: ...es The Open Source code used can be found at this site http www arubanetworks com open_source Legal Notice The use of Aruba Networks Inc switching platforms and software by all individuals or corporat...

Страница 3: ...figuring the Palo Alto Networks User ID Service 9 Check Palo Alto Networks Version and Setup 10 Configuring User ID Agent Definition 11 Enable Zone Based User Identification 12 Configuring User ID Age...

Страница 4: ...t mode and their web based User Interface Document Overview The first section of this document describes how the Amigopod Visitor Management Appliance can be used to provide end user identity visibili...

Страница 5: ...ies IT organizations can leverage user and group information for visibility policy creation forensic investigation and reporting on application threat web surfing and data transfer activity User ID he...

Страница 6: ...d with the source Enterprise user s identity by integrating with Active Directory or Novell eDirectory for example Typical Wired and Wireless Access Controllers have basic firewalling and traffic mana...

Страница 7: ...e Directory integration the User ID Agent is installed on a domain workstation or server and uses a domain account that has access to the Active Directory tree For the Amigopod integration the User ID...

Страница 8: ...ins link to download and install updated plugins It is assumed that the configuration steps required to integrate the chosen Wired or Wireless Access Controller have been completed tested and known to...

Страница 9: ...cess Controller must be configured correctly to support RADIUS accounting otherwise the Palo Alto Networks firewall will not be updated with the real time user identity information 3 Configure the fol...

Страница 10: ...egment by binding two ports together You can install the firewall in any network environment with no configuration of adjacent network devices required If necessary a virtual wire can block or allow t...

Страница 11: ...t the Windows host has an IP Address of 10 0 20 53 A port must also be defined for communications between the Palo Alto Networks firewall and the User ID Agent software on the Windows host Ensure to m...

Страница 12: ...estion and ensure the Enable User Identification option shown below is checked Once you have edited each relevant Zone in your deployment the summary table should look similar to this with the User Id...

Страница 13: ...nt menu option The following start up screen will be displayed Click the Configure option in the left navigation pane to complete the configuration of the Agent software From the Configure screen the...

Страница 14: ...returning to main screen by clicking on the User ID Agent option at the top of the left navigation pane a successful connection from the Palo Alto Networks firewall should be displayed as shown below...

Страница 15: ...details for a new test account and click the Create Guest button to save the account to the Amigopod database Login to Guest Wireless Network Verify Wireless Connection and IP Addressing The next step...

Страница 16: ...ted to a configured landing page or onto your original destination Verify Successful RADIUS Authentication You can now verify the successful RADIUS authentication from the Amigopod interface by going...

Страница 17: ...l to the User ID Agent software to inform the Palo Alto Networks of the new IP Address to User mapping Returning to the main screen of the User ID Agent we can see that the Amigopod has successfully s...

Страница 18: ...ffic analysis You should now see the From User column successfully populated with the user identity of the test user created in Amigopod One of the most powerful sections of the Palo Alto Networks use...

Страница 19: ...d hence initiate at RADIUS stop record being sent from the Access Controller to the Amigopod This will trigger another API update from the Amigopod to the User ID Agent running on the Windows host Ret...

Страница 20: ...egrated solution to both the operational and security requirements of providing network access to non Active Directory users In the corporate environment nontechnical operators can easily provision te...

Отзывы: