Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

ื‘ืจื•ื›ื™ื ื”ื‘ืื™ื ืœืคื•ืกื˜ ื”ืฉืœื™ืฉื™ ื‘ืกื“ืจืช Cisco ISE. ืœื”ืœืŸ ืงื™ืฉื•ืจื™ื ืœื›ืœ ื”ืžืืžืจื™ื ื‘ืกื“ืจื”:

  1. Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1

  2. Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2

  3. Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

ื‘ืคื•ืกื˜ ื”ื–ื”, ืชืฆืœืœื• ืœื’ื™ืฉื” ืœืื•ืจื—ื™ื, ื›ืžื• ื’ื ืžื“ืจื™ืš ืฉืœื‘ ืื—ืจ ืฉืœื‘ ืœืฉื™ืœื•ื‘ Cisco ISE ื•-FortiGate ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช FortiAP, ื ืงื•ื“ืช ื’ื™ืฉื” ืž-Fortinet (ื‘ืื•ืคืŸ ื›ืœืœื™, ื›ืœ ืžื›ืฉื™ืจ ืฉืชื•ืžืš RADIUS CoA - ืฉื™ื ื•ื™ ื”ืจืฉืื”).

ืžืฆื•ืจืคื™ื ื”ืžืืžืจื™ื ืฉืœื ื•. Fortinet - ืžื‘ื—ืจ ื—ื•ืžืจื™ื ืฉื™ืžื•ืฉื™ื™ื.

ืฉื™ื ืœื‘ืช: ื”ืชืงื ื™ Check Point SMB ืื™ื ื ืชื•ืžื›ื™ื ื‘-RADIUS CoA.

ื ึดืคืœึธื ืžึทื ื”ึดื™ื’ื•ึผืช ืžืชืืจ ื‘ืื ื’ืœื™ืช ื›ื™ืฆื“ ืœื™ืฆื•ืจ ื’ื™ืฉืช ืื•ืจื— ื‘ืืžืฆืขื•ืช Cisco ISE ื‘-Cisco WLC (ื‘ืงืจ ืืœื—ื•ื˜ื™). ื‘ื•ืื• ื ื‘ื™ืŸ ืืช ื–ื”!

1. ืžื‘ื•ื

ื’ื™ืฉืช ืื•ืจื— (ืคื•ืจื˜ืœ) ืžืืคืฉืจืช ืœืš ืœืกืคืง ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ืื• ืœืžืฉืื‘ื™ื ืคื ื™ืžื™ื™ื ืœืื•ืจื—ื™ื ื•ืœืžืฉืชืžืฉื™ื ืฉืื™ื ืš ืจื•ืฆื” ืœื”ื›ื ื™ืก ืœืจืฉืช ื”ืžืงื•ืžื™ืช ืฉืœืš. ื™ืฉื ื 3 ืกื•ื’ื™ื ืžื•ื’ื“ืจื™ื ืžืจืืฉ ืฉืœ ืคื•ืจื˜ืœ ืื•ืจื—ื™ื (ืคื•ืจื˜ืœ ืื•ืจื—ื™ื):

  1. ืคื•ืจื˜ืœ ืื•ืจื— Hotspot - ื’ื™ืฉื” ืœืจืฉืช ื ื™ืชื ืช ืœืื•ืจื—ื™ื ืœืœื ื ืชื•ื ื™ ื”ืชื—ื‘ืจื•ืช. ืžืฉืชืžืฉื™ื ื ื“ืจืฉื™ื ื‘ื“ืจืš ื›ืœืœ ืœืงื‘ืœ ืืช "ืžื“ื™ื ื™ื•ืช ื”ืฉื™ืžื•ืฉ ื•ื”ืคืจื˜ื™ื•ืช" ืฉืœ ื”ื—ื‘ืจื” ืœืคื ื™ ื”ื’ื™ืฉื” ืœืจืฉืช.

  2. ืคื•ืจื˜ืœ ืื•ืจื— ืžืžื•ืžืŸ - ื’ื™ืฉื” ืœืจืฉืช ื•ื ืชื•ื ื™ ื”ืชื—ื‘ืจื•ืช ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ืžื•ื ืคืงืช ืขืœ ื™ื“ื™ ื ื•ืชืŸ ื”ื—ืกื•ืช - ื”ืžืฉืชืžืฉ ื”ืื—ืจืื™ ืœื™ืฆื™ืจืช ื—ืฉื‘ื•ื ื•ืช ืื•ืจื—ื™ื ื‘-Cisco ISE.

  3. ืคื•ืจื˜ืœ ืื•ืจื—ื™ื ืจืฉื•ื ืขืฆืžื™ - ื‘ืžืงืจื” ื–ื”, ื”ืื•ืจื—ื™ื ืžืฉืชืžืฉื™ื ื‘ืคืจื˜ื™ ื”ืชื—ื‘ืจื•ืช ืงื™ื™ืžื™ื, ืื• ื™ื•ืฆืจื™ื ืœืขืฆืžื ื—ืฉื‘ื•ืŸ ืขื ืคืจื˜ื™ ื”ืชื—ื‘ืจื•ืช, ืืš ื ื“ืจืฉ ืื™ืฉื•ืจ ืกืคื•ื ืกืจ ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืœืจืฉืช.

ื ื™ืชืŸ ืœืคืจื•ืก ืžืกืคืจ ืคื•ืจื˜ืœื™ื ื‘-Cisco ISE ื‘ื•-ื–ืžื ื™ืช. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื‘ืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื, ื”ืžืฉืชืžืฉ ื™ืจืื” ืืช ื”ืœื•ื’ื• ืฉืœ ืกื™ืกืงื• ื•ื‘ื™ื˜ื•ื™ื™ื ื ืคื•ืฆื™ื ืกื˜ื ื“ืจื˜ื™ื™ื. ื›ืœ ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžื•ืชืื ืื™ืฉื™ืช ื•ืืคื™ืœื• ืœื”ื’ื“ื™ืจ ืœื”ืฆื™ื’ ืžื•ื“ืขื•ืช ื—ื•ื‘ื” ืœืคื ื™ ืงื‘ืœืช ื’ื™ืฉื”.

ื ื™ืชืŸ ืœื—ืœืง ืืช ื”ื’ื“ืจืช ื”ื’ื™ืฉื” ืœืื•ืจื—ื™ื ืœ-4 ืฉืœื‘ื™ื ืขื™ืงืจื™ื™ื: ื”ื’ื“ืจืช FortiAP, ืงื™ืฉื•ืจื™ื•ืช Cisco ISE ื•-FortiAP, ื™ืฆื™ืจืช ืคื•ืจื˜ืœ ืื•ืจื—ื™ื ื•ื”ื’ื“ืจืช ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื”.

2. ื”ื’ื“ืจืช FortiAP ื‘-FortiGate

FortiGate ื”ื•ื ื‘ืงืจ ื ืงื•ื“ืช ื’ื™ืฉื” ื•ื›ืœ ื”ื”ื’ื“ืจื•ืช ืžืชื‘ืฆืขื•ืช ื‘ื•. ื ืงื•ื“ื•ืช ื’ื™ืฉื” ืฉืœ FortiAP ืชื•ืžื›ื•ืช ื‘-PoE, ื›ืš ืœืื—ืจ ืฉื—ื™ื‘ืจืช ืื•ืชื” ืœืจืฉืช ื‘ืืžืฆืขื•ืช Ethernet, ืชื•ื›ืœ ืœื”ืชื—ื™ืœ ืืช ื”ืชืฆื•ืจื”.

1) ื‘-FortiGate, ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” Wi-Fi ื•ื‘ืงืจ ืžืชื’ > FortiAPs ืžื ื•ื”ืœื™ื > ืฆื•ืจ ื—ื“ืฉ > AP ืžื ื•ื”ืœ. ื‘ืืžืฆืขื•ืช ื”ืžืกืคืจ ื”ืกื™ื“ื•ืจื™ ื”ื™ื™ื—ื•ื“ื™ ืฉืœ ื ืงื•ื“ืช ื”ื’ื™ืฉื”, ื”ืžื•ื“ืคืก ืขืœ ื ืงื•ื“ืช ื”ื’ื™ืฉื” ืขืฆืžื”, ื”ื•ืกืฃ ืื•ืชื” ื›ืื•ื‘ื™ื™ืงื˜. ืื• ืฉื”ื•ื ื™ื›ื•ืœ ืœื”ืจืื•ืช ืืช ืขืฆืžื• ื•ืื– ืœืœื—ื•ืฅ ืœึฐืึทืฉืึตืจ ื‘ืืžืฆืขื•ืช ืœื—ืฆืŸ ื”ืขื›ื‘ืจ ื”ื™ืžื ื™.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

2) ื”ื’ื“ืจื•ืช FortiAP ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ื‘ืจื™ืจืช ืžื—ื“ืœ, ืœืžืฉืœ, ื”ืฉืืจ ื›ืžื• ื‘ืฆื™ืœื•ื ื”ืžืกืš. ืื ื™ ืžืžืœื™ืฅ ื‘ื—ื•ื ืœื”ืคืขื™ืœ ืืช ืžืฆื‘ ื”-5 GHz, ืžื›ื™ื•ื•ืŸ ืฉื—ืœืง ืžื”ืžื›ืฉื™ืจื™ื ืื™ื ื ืชื•ืžื›ื™ื ื‘-2.4 GHz.

3) ื•ืื– ื‘ื›ืจื˜ื™ืกื™ื™ื” Wi-Fi ื•ื‘ืงืจ ืžืชื’ > ืคืจื•ืคื™ืœื™ FortiAP > ืฆื•ืจ ื—ื“ืฉ ืื ื• ื™ื•ืฆืจื™ื ืคืจื•ืคื™ืœ ื”ื’ื“ืจื•ืช ืขื‘ื•ืจ ื ืงื•ื“ืช ื”ื’ื™ืฉื” (ืคืจื•ื˜ื•ืงื•ืœ ื’ืจืกื” 802.11, ืžืฆื‘ SSID, ืชื“ืจ ืขืจื•ืฅ ื•ืžืกืคืจื).

ื“ื•ื’ืžื” ืœื”ื’ื“ืจื•ืช FortiAPCisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

4) ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ื™ืฆื™ืจืช SSID. ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” Wi-Fi ื•ื‘ืงืจ ืžืชื’ > SSIDs > Create New > SSID. ื›ืืŸ ืžื”ื—ืฉื•ื‘ ื™ืฉ ืœื”ื’ื“ื™ืจ:

  • ืžืจื—ื‘ ื›ืชื•ื‘ืช ืขื‘ื•ืจ WLAN ืื•ืจื— - IP/Netmask

  • RADIUS Accounting ื•-Secure Fabric Connection ื‘ืฉื“ื” ื’ื™ืฉื” ืžื ื”ืœืชื™ืช

  • ืืคืฉืจื•ืช ื–ื™ื”ื•ื™ ื”ืชืงื ื™ื

  • ืืคืฉืจื•ืช SSID ื•ืฉื™ื“ื•ืจ SSID

  • ื”ื’ื“ืจื•ืช ืžืฆื‘ ืื‘ื˜ื—ื” > ืคื•ืจื˜ืœ ืฉื‘ื•ื™ 

  • ืคื•ืจื˜ืœ ืื™ืžื•ืช - ื—ื™ืฆื•ื ื™ ื•ื”ื›ื ืก ืงื™ืฉื•ืจ ืœืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื ืฉื ื•ืฆืจ ืž-Cisco ISE ืžืฉืœื‘ 20

  • ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื - ืงื‘ื•ืฆืช ืื•ืจื—ื™ื - ื—ื™ืฆื•ื ื™ืช - ื”ื•ืกืฃ RADIUS ืœ-Cisco ISE (ืขืž' 6 ื•ืื™ืœืš)

ื“ื•ื’ืžื” ืœื”ื’ื“ืจืช SSIDCisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

5) ืœืื—ืจ ืžื›ืŸ ืขืœื™ืš ืœื™ืฆื•ืจ ื›ืœืœื™ื ื‘ืžื“ื™ื ื™ื•ืช ื”ื’ื™ืฉื” ื‘-FortiGate. ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ืžื“ื™ื ื™ื•ืช ื•ืื•ื‘ื™ื™ืงื˜ื™ื > ืžื“ื™ื ื™ื•ืช ื—ื•ืžืช ืืฉ ื•ืฆื•ืจ ื›ืœืœ ื›ื–ื”:

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

3. ื”ื’ื“ืจืช RADIUS

6) ืขื‘ื•ืจ ืืœ ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Cisco ISE ืืœ ื”ื›ืจื˜ื™ืกื™ื™ื” ืžื“ื™ื ื™ื•ืช > ืจื›ื™ื‘ื™ ืžื“ื™ื ื™ื•ืช > ืžื™ืœื•ื ื™ื > ืžืขืจื›ืช > ืจื“ื™ื•ืก > ืกืคืงื™ RADIUS > ื”ื•ืกืฃ. ื‘ืœืฉื•ื ื™ืช ื–ื•, ื ื•ืกื™ืฃ ืืช Fortinet RADIUS ืœืจืฉื™ืžืช ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ื”ื ืชืžื›ื™ื, ืžื›ื™ื•ื•ืŸ ืฉื›ืžืขื˜ ืœื›ืœ ืกืคืง ื™ืฉ ืชื›ื•ื ื•ืช ืกืคืฆื™ืคื™ื•ืช ืžืฉืœื• - VSA (ืชื›ื•ื ื•ืช ืกืคืฆื™ืคื™ื•ืช ืœืกืคืง).

ื ื™ืชืŸ ืœืžืฆื•ื ืจืฉื™ืžื” ืฉืœ ืชื›ื•ื ื•ืช Fortinet RADIUS ื›ืืŸ. VSAs ื ื‘ื“ืœื™ื ืขืœ ื™ื“ื™ ืžืกืคืจ ื–ื™ื”ื•ื™ ื”ืกืคืง ื”ื™ื™ื—ื•ื“ื™ ืฉืœื”ื. ืœืคื•ืจื˜ื™ื ื˜ ื™ืฉ ืืช ื”ืžื–ื”ื” ื”ื–ื” = 12356... ืžืœื ัะฟะธัะพะบ ื”-VSA ืคื•ืจืกื ืขืœ ื™ื“ื™ IANA.

7) ื”ื’ื“ืจ ืืช ืฉื ื”ืžื™ืœื•ืŸ, ืฆื™ื™ืŸ ืžื–ื”ื” ืกืคืง (12356) ื•ืœื—ืฅ ืฉืœื—.

8) ืื—ืจื™ ืฉื ืœืš ืœ ื ื™ื”ื•ืœ > ืคืจื•ืคื™ืœื™ ื”ืชืงืŸ ืจืฉืช > ื”ื•ืกืฃ ื•ืœื™ืฆื•ืจ ืคืจื•ืคื™ืœ ืžื›ืฉื™ืจ ื—ื“ืฉ. ื‘ืฉื“ื” RADIUS Dictionaries, ื‘ื—ืจ ืืช ืžื™ืœื•ืŸ Fortinet RADIUS ืฉื ื•ืฆืจ ื‘ืขื‘ืจ ื•ื‘ื—ืจ ืืช ืฉื™ื˜ื•ืช ื”-CoA ืœืฉื™ืžื•ืฉ ืžืื•ื—ืจ ื™ื•ืชืจ ื‘ืžื“ื™ื ื™ื•ืช ISE. ื‘ื—ืจืชื™ ื‘-RFC 5176 ื•ื‘-Port Bounce (ื›ื™ื‘ื•ื™/ืœืœื ื›ื™ื‘ื•ื™ ืžืžืฉืง ืจืฉืช) ื•ื‘-VSAs ื”ืชื•ืืžื™ื: 

Fortinet-Access-Profile=ืงืจื™ืื”-ื›ืชื™ื‘ื”

Fortinet-Group-Name = fmg_faz_admins

9) ืœืื—ืจ ืžื›ืŸ, ื”ื•ืกืฃ ืืช FortiGate ืœืงื™ืฉื•ืจื™ื•ืช ืขื ISE. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ืขื‘ื•ืจ ืืœ ื”ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ืžืฉืื‘ื™ ืจืฉืช > ืคืจื•ืคื™ืœื™ ื”ืชืงืŸ ืจืฉืช > ื”ื•ืกืฃ. ืฉื“ื•ืช ืฉื™ืฉ ืœืฉื ื•ืช ืฉื, ืกืคืง, ืžื™ืœื•ื ื™ RADIUS (ื›ืชื•ื‘ืช ื”-IP ืžืฉืžืฉืช ืืช FortiGate, ืœื ืืช FortiAP).

ื“ื•ื’ืžื” ืœื”ื’ื“ืจืช RADIUS ืžื”ืฆื“ ืฉืœ ISECisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

10) ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช RADIUS ื‘ืฆื“ FortiGate. ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ FortiGate, ืขื‘ื•ืจ ืืœ ืžืฉืชืžืฉ ื•ืื™ืžื•ืช > ืฉืจืชื™ RADIUS > ืฆื•ืจ ื—ื“ืฉ. ืฆื™ื™ืŸ ืืช ื”ืฉื, ื›ืชื•ื‘ืช ื”-IP ื•ื”ืกื•ื“ ื”ืžืฉื•ืชืฃ (ืกื™ืกืžื”) ืžื”ืคืกืงื” ื”ืงื•ื“ืžืช. ื”ืงืœื™ืง ื”ื‘ื ื‘ื“ื•ืง ืืช ืื™ืฉื•ืจื™ ื”ืžืฉืชืžืฉ ื•ื”ื–ืŸ ืืช ื›ืœ ื”ืื™ืฉื•ืจื™ื ืฉื ื™ืชืŸ ืœืฉืœื•ืฃ ื“ืจืš RADIUS (ืœื“ื•ื’ืžื”, ืžืฉืชืžืฉ ืžืงื•ืžื™ ื‘-Cisco ISE).

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

11) ื”ื•ืกืฃ ืฉืจืช RADIUS ืœ-Guest-Group (ืื ื”ื•ื ืœื ืงื™ื™ื) ื•ื›ืŸ ืžืงื•ืจ ื—ื™ืฆื•ื ื™ ืฉืœ ืžืฉืชืžืฉื™ื.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

12) ืืœ ืชืฉื›ื— ืœื”ื•ืกื™ืฃ ืืช ืงื‘ื•ืฆืช ื”ืื•ืจื—ื™ื ืœ-SSID ืฉื™ืฆืจื ื• ืžื•ืงื“ื ื™ื•ืชืจ ื‘ืฉืœื‘ 4.

4. ื”ื’ื“ืจืช ืื™ืžื•ืช ืžืฉืชืžืฉ

13) ืœื—ืœื•ืคื™ืŸ, ื ื™ืชืŸ ืœื™ื™ื‘ื ืื™ืฉื•ืจ ืœืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื ืฉืœ ISE ืื• ืœื™ืฆื•ืจ ืื™ืฉื•ืจ ื‘ื—ืชื™ืžื” ืขืฆืžื™ืช ื‘ื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื—ื™ื > ื ื™ื”ื•ืœ > ื”ืกืžื›ื” > ืื™ืฉื•ืจื™ ืžืขืจื›ืช.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

14) ืœืื—ืจ ื‘ื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื— > ืงื‘ื•ืฆื•ืช ื–ื”ื•ืช > ืงื‘ื•ืฆื•ืช ื–ื”ื•ืช ืžืฉืชืžืฉ > ื”ื•ืกืฃ ืฆื•ืจ ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื ื—ื“ืฉื” ืœื’ื™ืฉื” ืœืื•ืจื—ื™ื, ืื• ื”ืฉืชืžืฉ ื‘ื‘ืจื™ืจืช ื”ืžื—ื“ืœ.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

15) ื‘ื”ืžืฉืš ื”ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ื–ื”ื•ื™ื•ืช ืฆื•ืจ ืžืฉืชืžืฉื™ื ืื•ืจื—ื™ื ื•ื”ื•ืกืฃ ืื•ืชื ืœืงื‘ื•ืฆื•ืช ืžื”ืคืกืงื” ื”ืงื•ื“ืžืช. ืื ื‘ืจืฆื•ื ืš ืœื”ืฉืชืžืฉ ื‘ื—ืฉื‘ื•ื ื•ืช ืฉืœ ืฆื“ ืฉืœื™ืฉื™, ื“ืœื’ ืขืœ ืฉืœื‘ ื–ื”.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

16) ืœืื—ืจ ืฉื ืขื‘ื•ืจ ืœื”ื’ื“ืจื•ืช ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื— > ื–ื”ื•ื™ื•ืช > ืจืฆืฃ ืžืงื•ืจ ื–ื”ื•ืช > ืจืฆืฃ ืคื•ืจื˜ืœ ืื•ืจื— โ€” ื–ื”ื• ืจืฆืฃ ื”ืื™ืžื•ืช ื”ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื ืื•ืจื—ื™ื. ื•ื’ื ื‘ืฉื˜ื— ืจืฉื™ืžืช ื—ื™ืคื•ืฉ ืื™ืžื•ืช ื‘ื—ืจ ืืช ืกื“ืจ ืื™ืžื•ืช ื”ืžืฉืชืžืฉ.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

17) ื›ื“ื™ ืœื”ื•ื“ื™ืข โ€‹โ€‹ืœืื•ืจื—ื™ื ืขื ืกื™ืกืžื” ื—ื“ ืคืขืžื™ืช, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืกืคืงื™ SMS ืื• ืฉืจืช SMTP ืœืžื˜ืจื” ื–ื•. ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื—ื™ื > ื ื™ื”ื•ืœ > ืฉืจืช SMTP ืื• ืกืคืงื™ ืฉืขืจ SMS ืขื‘ื•ืจ ื”ื’ื“ืจื•ืช ืืœื•. ื‘ืžืงืจื” ืฉืœ ืฉืจืช SMTP, ืขืœื™ืš ืœื™ืฆื•ืจ ื—ืฉื‘ื•ืŸ ืขื‘ื•ืจ ISE ื•ืœืฆื™ื™ืŸ ืืช ื”ื ืชื•ื ื™ื ื‘ื›ืจื˜ื™ืกื™ื™ื” ื–ื•.

18) ืขื‘ื•ืจ ื”ืชืจืื•ืช SMS, ื”ืฉืชืžืฉ ื‘ื›ืจื˜ื™ืกื™ื™ื” ื”ืžืชืื™ืžื”. ืœ-ISE ื™ืฉ ืคืจื•ืคื™ืœื™ื ืžื•ืชืงื ื™ื ืžืจืืฉ ืฉืœ ืกืคืงื™ SMS ืคื•ืคื•ืœืจื™ื™ื, ืื‘ืœ ืขื“ื™ืฃ ืœื™ืฆื•ืจ ืคืจื•ืคื™ืœื™ื ืžืฉืœืš. ื”ืฉืชืžืฉ ื‘ืคืจื•ืคื™ืœื™ื ืืœื” ื›ื“ื•ื’ืžื” ืœื”ื’ื“ืจื” ืฉืขืจ ืื™ืžื™ื™ืœ SMSy ืื• SMS HTTP API.

ื“ื•ื’ืžื” ืœื”ื’ื“ืจืช ืฉืจืช SMTP ื•ืฉืขืจ SMS ืœืกื™ืกืžื” ื—ื“ ืคืขืžื™ืชCisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

5. ื”ืงืžืช ืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื

19) ื›ืคื™ ืฉื”ื•ื–ื›ืจ ื‘ื”ืชื—ืœื”, ื™ืฉื ื 3 ืกื•ื’ื™ื ืฉืœ ืคื•ืจื˜ืœื™ ืื•ืจื—ื™ื ืžื•ืชืงื ื™ื ืžืจืืฉ: Hotspot, ืžืžื•ืžืŸ, Self-Registered. ืื ื™ ืžืฆื™ืข ืœื‘ื—ื•ืจ ื‘ืืคืฉืจื•ืช ื”ืฉืœื™ืฉื™ืช, ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ื”ื ืคื•ืฆื” ื‘ื™ื•ืชืจ. ื›ืš ืื• ื›ืš, ื”ื”ื’ื“ืจื•ืช ื–ื”ื•ืช ื‘ืžื™ื“ื” ืจื‘ื”. ืื– ื‘ื•ื ื ืœืš ืœื›ืจื˜ื™ืกื™ื™ื”. ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื— > ืคื•ืจื˜ืœื™ื ื•ืจื›ื™ื‘ื™ื > ืคื•ืจื˜ืœื™ื ืื•ืจื—ื™ื > ืคื•ืจื˜ืœ ืื•ืจื— ืจืฉื•ื ืขืฆืžื™ (ื‘ืจื™ืจืช ืžื—ื“ืœ). 

20) ืœืื—ืจ ืžื›ืŸ, ื‘ื›ืจื˜ื™ืกื™ื™ื” ื”ืชืืžื” ืื™ืฉื™ืช ืฉืœ ื“ืฃ ืคื•ืจื˜ืœ, ื‘ื—ืจ "ื”ืฆื’ ื‘ืจื•ืกื™ืช - ืจื•ืกื™ืช", ื›ืš ืฉื”ืคื•ืจื˜ืœ ื™ื•ืฆื’ ื‘ืจื•ืกื™ืช. ืืชื” ื™ื›ื•ืœ ืœืฉื ื•ืช ืืช ื”ื˜ืงืกื˜ ืฉืœ ื›ืœ ื›ืจื˜ื™ืกื™ื™ื”, ืœื”ื•ืกื™ืฃ ืืช ื”ืœื•ื’ื• ืฉืœืš ื•ืขื•ื“. ื‘ืฆื“ ื™ืžื™ืŸ ื‘ืคื™ื ื” ื™ืฉ ืชืฆื•ื’ื” ืžืงื“ื™ืžื” ืฉืœ ืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื ืœืชืฆื•ื’ื” ื˜ื•ื‘ื” ื™ื•ืชืจ.

ื“ื•ื’ืžื” ืœื”ื’ื“ืจืช ืคื•ืจื˜ืœ ืื•ืจื— ืขื ืจื™ืฉื•ื ืขืฆืžื™Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

21) ืœื—ืฅ ืขืœ ื‘ื™ื˜ื•ื™ ื›ืชื•ื‘ืช ืืชืจ ืœื‘ื“ื™ืงืช ืคื•ืจื˜ืœ ื•ื”ืขืชืง ืืช ื›ืชื•ื‘ืช ื”ืืชืจ ืฉืœ ื”ืคื•ืจื˜ืœ ืœ-SSID ื‘-FortiGate ื‘ืฉืœื‘ 4. ื›ืชื•ื‘ืช ืืชืจ ืœื“ื•ื’ืžื” https://10.10.30.38:8433/portal/PortalSetup.action?portal=deaaa863-1df0-4198-baf1-8d5b690d4361

ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ื”ื“ื•ืžื™ื™ืŸ ืฉืœืš, ืขืœื™ืš ืœื”ืขืœื•ืช ืืช ื”ืื™ืฉื•ืจ ืœืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื, ืจืื” ืฉืœื‘ 13.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

22) ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื— > ืจื›ื™ื‘ื™ ืžื“ื™ื ื™ื•ืช > ืชื•ืฆืื•ืช > ืคืจื•ืคื™ืœื™ ื”ืจืฉืื” > ื”ื•ืกืฃ ื›ื“ื™ ืœื™ืฆื•ืจ ืคืจื•ืคื™ืœ ื”ืจืฉืื” ืชื—ืช ื”ืคืจื•ืคื™ืœ ืฉื ื•ืฆืจ ืงื•ื“ื ืœื›ืŸ ืคืจื•ืคื™ืœ ืžื›ืฉื™ืจ ืจืฉืช.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

23) ื‘ื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” > ื’ื™ืฉืช ืื•ืจื— > ืขืจื›ื•ืช ืžื“ื™ื ื™ื•ืช ืขืจื•ืš ืืช ืžื“ื™ื ื™ื•ืช ื”ื’ื™ืฉื” ืขื‘ื•ืจ ืžืฉืชืžืฉื™ WiFi.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

24) ื‘ื•ืื• ื ื ืกื” ืœื”ืชื—ื‘ืจ ืœ-SSID ื”ืื•ืจื—. ื–ื” ืžืคื ื” ืื•ืชื™ ืžื™ื“ ืœื“ืฃ ื”ื”ืชื—ื‘ืจื•ืช. ื›ืืŸ ืืชื” ื™ื›ื•ืœ ืœื”ื™ื›ื ืก ืขื ื—ืฉื‘ื•ืŸ ื”ืื•ืจื— ืฉื ื•ืฆืจ ื‘ืื•ืคืŸ ืžืงื•ืžื™ ื‘-ISE, ืื• ืœื”ื™ืจืฉื ื›ืžืฉืชืžืฉ ืื•ืจื—.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

25) ืื ื‘ื—ืจืช ื‘ืืคืฉืจื•ืช ืจื™ืฉื•ื ืขืฆืžื™, ื ื™ืชืŸ ืœืฉืœื•ื— ื ืชื•ื ื™ ื›ื ื™ืกื” ื—ื“-ืคืขืžื™ื™ื ื‘ื“ื•ืืจ, ื‘-SMS ืื• ืœื”ื“ืคื™ืก.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

26) ื‘ื›ืจื˜ื™ืกื™ื™ื” RADIUS > Live Logs ื‘- Cisco ISE, ืชืจืื” ืืช ื™ื•ืžื ื™ ื”ื”ืชื—ื‘ืจื•ืช ื”ืžืชืื™ืžื™ื.

Cisco ISE: ื”ื’ื“ืจืช ื’ื™ืฉื” ืœืื•ืจื—ื™ื ื‘-FortiAP. ื—ืœืง 3

6. ืžืกืงื ื”

ื‘ืžืืžืจ ืืจื•ืš ื–ื”, ื”ื’ื“ืจื ื• ื‘ื”ืฆืœื—ื” ื’ื™ืฉืช ืื•ืจื— ื‘-Cisco ISE, ื›ืืฉืจ FortiGate ืžืฉืžืฉ ื›ื‘ืงืจ ื ืงื•ื“ืช ื”ื’ื™ืฉื”, ื•-FortiAP ืคื•ืขืœ ื›ื ืงื•ื“ืช ื”ื’ื™ืฉื”. ื–ื” ื”ืชื‘ืจืจ ืกื•ื’ ืฉืœ ืื™ื ื˜ื’ืจืฆื™ื” ืœื ื˜ืจื™ื•ื•ื™ืืœื™ืช, ืžื” ืฉืžื•ื›ื™ื— ืฉื•ื‘ ืืช ื”ืฉื™ืžื•ืฉ ื”ื ืจื—ื‘ ื‘-ISE.

ื›ื“ื™ ืœื‘ื“ื•ืง ืืช Cisco ISE, ืฆื•ืจ ืงืฉืจ ืงืฉืจื•ื’ื ื”ื™ืฉืืจื• ืžืขื•ื“ื›ื ื™ื ื‘ืขืจื•ืฆื™ื ืฉืœื ื• (ืžื‘ืจืง, ืคื™ื™ืกื‘ื•ืง, VK, ื‘ืœื•ื’ ืคืชืจื•ื ื•ืช TS, ื™ืื ื“ืงืก ื–ืŸ).

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”