
5.1 NAC Overview
Network access control (NAC) is an end-to-end access security framework and includes Web
authentication, 802.1x authentication, and MAC address authentication.
Traditional network security technologies focus on threats from external computers but not
threats from internal computers. Current network devices cannot prevent attacks initiated by
devices on internal networks. NAC protects terminal security, thus providing end-to-end
network security.
Figure 5-1
Typical NAC networking
User
NAD
ACS
AAA
server
Remediation server
Directory
server
PVS & AUDIT
server
As shown in
, NAC is a control scheme for network access security, and involves the
following entities:
l
User: Access user who must be authenticated. If 802.1x authentication is used, users must
install the client software.
l
NAD: Network access device (NAD). An NAD authenticates and authorizes access users.
The NAD works with an AAA server to prevent unauthorized terminals from accessing the
network, minimize the threats brought by insecure terminals, prevent unauthorized access
requests from authorized terminals, and protect core resources.
l
ACS: Access control server (ACS). An ACS checks terminal security and manage policies,
manages user behaviors and audits rule violations, and prevents malicious attacks from
terminals.
5.2 NAC Features Supported by the AR1200-S
The AR1200-S supports multiple authentication and control methods to control user authorities
and access areas.
The AR1200-S functions as a network access device (NAD) and supports 802.1x authentication,
MAC address authentication, and Web authentication.
802.1x Authentication
The Institute of Electrical and Electronics Engineers (IEEE) 802.1x standard, 802.1x for short,
is an interface-based network access control protocol. 802.1x authentication authenticates and
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
5 NAC Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
98