Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2

ื‘ืจื•ื›ื™ื ื”ื‘ืื™ื ืœืคื•ืกื˜ ื”ืฉื ื™ ื‘ืกื“ืจืช Cisco ISE. ื‘ืจืืฉื•ืŸ ัั‚ะฐั‚ัŒะต  ื”ื•ื“ื’ืฉื• ื”ื™ืชืจื•ื ื•ืช ื•ื”ื”ื‘ื“ืœื™ื ืฉืœ ืคืชืจื•ื ื•ืช ื‘ืงืจืช ื’ื™ืฉื” ืœืจืฉืช (NAC) ืžื”ืชืงืŸ AAA, ื”ื™ื™ื—ื•ื“ื™ื•ืช ืฉืœ Cisco ISE, ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื•ืชื”ืœื™ืš ื”ื”ืชืงื ื” ืฉืœ ื”ืžื•ืฆืจ.

ื‘ืžืืžืจ ื–ื” ื ืชืขืžืง ื‘ื™ืฆื™ืจืช ื—ืฉื‘ื•ื ื•ืช, ื”ื•ืกืคืช ืฉืจืชื™ LDAP ื•ืฉื™ืœื•ื‘ ืขื Microsoft Active Directory, ื›ืžื• ื’ื ืืช ื”ื ื™ื•ืื ืกื™ื ืฉืœ ืขื‘ื•ื“ื” ืขื PassiveID. ืœืคื ื™ ื”ืงืจื™ืื”, ืื ื™ ืžืžืœื™ืฅ ื‘ื—ื•ื ืœืงืจื•ื ื—ืœืง ืจืืฉื•ืŸ.

1. ืงืฆืช ืžื™ื ื•ื—

ื–ื”ื•ืช ืžืฉืชืžืฉ - ื—ืฉื‘ื•ืŸ ืžืฉืชืžืฉ, ื”ืžื›ื™ืœ ืžื™ื“ืข ืขืœ ื”ืžืฉืชืžืฉ ื•ืžื™ื™ืฆืจ ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœื• ืœื’ื™ืฉื” ืœืจืฉืช. ื”ืคืจืžื˜ืจื™ื ื”ื‘ืื™ื ืžืฆื•ื™ื ื™ื ื‘ื“ืจืš ื›ืœืœ ื‘-User Identity: ืฉื ืžืฉืชืžืฉ, ื›ืชื•ื‘ืช ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™, ืกื™ืกืžื”, ืชื™ืื•ืจ ื—ืฉื‘ื•ืŸ, ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื ื•ืชืคืงื™ื“.

ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื - ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ื”ืŸ ืื•ืกืฃ ืฉืœ ืžืฉืชืžืฉื™ื ื‘ื•ื“ื“ื™ื ืฉื™ืฉ ืœื”ื ืงื‘ื•ืฆื” ืžืฉื•ืชืคืช ืฉืœ ื”ืจืฉืื•ืช ื”ืžืืคืฉืจื•ืช ืœื”ื ื’ื™ืฉื” ืœืงื‘ื•ืฆื” ืžืกื•ื™ืžืช ืฉืœ ืฉื™ืจื•ืชื™ื ื•ืคื•ื ืงืฆื™ื•ืช ืฉืœ Cisco ISE.

ืงื‘ื•ืฆื•ืช ื–ื”ื•ืช ืžืฉืชืžืฉ - ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ืžื•ื’ื“ืจื•ืช ืžืจืืฉ ืฉื›ื‘ืจ ื™ืฉ ืœื”ืŸ ืžื™ื“ืข ื•ืชืคืงื™ื“ื™ื ืžืกื•ื™ืžื™ื. ืงื‘ื•ืฆื•ืช ื–ื”ื•ืช ื”ืžืฉืชืžืฉ ื”ื‘ืื•ืช ืงื™ื™ืžื•ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื ื™ืชืŸ ืœื”ื•ืกื™ืฃ ืœื”ืŸ ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื: Employee (ืขื•ื‘ื“), SponsorAllAccount, SponsorGroupAccounts, SponsorOwnAccounts (ื—ืฉื‘ื•ื ื•ืช ื ื•ืชื ื™ ื—ืกื•ืช ืœื ื™ื”ื•ืœ ืคื•ืจื˜ืœ ื”ืื•ืจื—ื™ื), ืื•ืจื— (ืื•ืจื—), ActivatedGuest (ืื•ืจื— ืžื•ืคืขืœ).

ืชืคืงื™ื“ ืžืฉืชืžืฉ- ืชืคืงื™ื“ ืžืฉืชืžืฉ ื”ื•ื ืงื‘ื•ืฆื” ืฉืœ ื”ืจืฉืื•ืช ืฉืงื•ื‘ืขื•ืช ืื™ืœื• ืžืฉื™ืžื•ืช ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื‘ืฆืข ื•ืœืื™ืœื• ืฉื™ืจื•ืชื™ื ื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื’ืฉืช. ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืชืคืงื™ื“ ืžืฉืชืžืฉ ืžืฉื•ื™ืš ืœืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื.

ื™ืชืจื” ืžื›ืš, ืœื›ืœ ืžืฉืชืžืฉ ื•ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื ื™ืฉ ืชื›ื•ื ื•ืช ื ื•ืกืคื•ืช ื”ืžืืคืฉืจื•ืช ืœื‘ื—ื•ืจ ื•ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืกืคืฆื™ืคื™ ื™ื•ืชืจ ืžืฉืชืžืฉ ื–ื” (ืงื‘ื•ืฆืช ืžืฉืชืžืฉื™ื). ืžื™ื“ืข ื ื•ืกืฃ ื‘ ืœื”ื ื—ื•ืช.

2. ืฆื•ืจ ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื

1) ืœ-Cisco ISE ื™ืฉ ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื ื•ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื” ืื• ืืคื™ืœื• ืœืชืช ืชืคืงื™ื“ ื‘ื ื™ื”ื•ืœ ืžื•ืฆืจ. ื‘ื—ืจ ื ื™ื”ื•ืœ โ† ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ† ื–ื”ื•ื™ื•ืช โ† ืžืฉืชืžืฉื™ื โ† ื”ื•ืกืฃ.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 1: ื”ื•ืกืคืช ืžืฉืชืžืฉ ืžืงื•ืžื™ ืœ-Cisco ISE

2) ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ืฆื•ืจ ืžืฉืชืžืฉ ืžืงื•ืžื™, ืชืŸ โ€‹โ€‹ืœื• ืกื™ืกืžื” ื•ืขื•ื“ ืคืจืžื˜ืจื™ื ื‘ืจื•ืจื™ื.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 2. ื™ืฆื™ืจืช ืžืฉืชืžืฉ ืžืงื•ืžื™ ื‘-Cisco ISE

3) ื ื™ืชืŸ ื’ื ืœื™ื™ื‘ื ืžืฉืชืžืฉื™ื. ื‘ืื•ืชื” ืœืฉื•ื ื™ืช ื ื™ื”ื•ืœ โ† ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ† ื–ื”ื•ื™ื•ืช โ† ืžืฉืชืžืฉื™ื ื‘ื—ืจ ืืคืฉืจื•ืช ืชื‘ื•ืื• ื•ืœื”ืขืœื•ืช ืงื•ื‘ืฅ csv ืื• txt ืขื ื”ืžืฉืชืžืฉื™ื. ื›ื“ื™ ืœืงื‘ืœ ืชื‘ื ื™ืช ื‘ื—ืจ ืฆื•ืจ ืชื‘ื ื™ืช, ืื– ื™ืฉ ืœืžืœื ืื•ืชื• ื‘ืžื™ื“ืข ืขืœ ืžืฉืชืžืฉื™ื ื‘ืฆื•ืจื” ืžืชืื™ืžื”.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 3 ื™ื™ื‘ื•ื โ€‹โ€‹ืžืฉืชืžืฉื™ื ืœืชื•ืš Cisco ISE

3. ื”ื•ืกืคืช ืฉืจืชื™ LDAP

ื”ืจืฉื• ืœื™ ืœื”ื–ื›ื™ืจ ืœื›ื ืฉ-LDAP ื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ืคื•ืคื•ืœืจื™ ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื” ื”ืžืืคืฉืจ ืœื›ื ืœืงื‘ืœ ืžื™ื“ืข, ืœื‘ืฆืข ืื™ืžื•ืช, ืœื—ืคืฉ ื—ืฉื‘ื•ื ื•ืช ื‘ืกืคืจื™ื•ืช ืฉืœ ืฉืจืชื™ LDAP, ืขื•ื‘ื“ ืขืœ ื™ืฆื™ืื” 389 ืื• 636 (SS). ื“ื•ื’ืžืื•ืช ื‘ื•ืœื˜ื•ืช ืœืฉืจืชื™ LDAP ื”ืŸ Active Directory, Sun Directory, Novell eDirectory ื•-OpenLDAP. ื›ืœ ืขืจืš ื‘ืกืคืจื™ื™ืช LDAP ืžื•ื’ื“ืจ ืขืœ ื™ื“ื™ DN (ืฉื ืžื•ื‘ื”ืง) ื•ืžืฉื™ืžืช ืื—ื–ื•ืจ ื”ื—ืฉื‘ื•ื ื•ืช, ืงื‘ื•ืฆื•ืช ื”ืžืฉืชืžืฉื™ื ื•ื”ืชื›ื•ื ื•ืช ืžื•ืขืœื™ืช ืœื™ืฆื™ืจืช ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื”.

ื‘-Cisco ISE ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื’ื™ืฉื” ืœืฉืจืชื™ LDAP ืจื‘ื™ื, ื•ื‘ื›ืš ืœืžืžืฉ ื™ืชื™ืจื•ืช. ืื ืฉืจืช ื”-LDAP ื”ืจืืฉื™ ืื™ื ื• ื–ืžื™ืŸ, ISE ื™ื ืกื” ืœื™ืฆื•ืจ ืงืฉืจ ืขื ื”ืฉืจืช ื”ืžืฉื ื™ ื•ื›ืŸ ื”ืœืื”. ื‘ื ื•ืกืฃ, ืื ื™ืฉ 2 PANs, ืื–ื™ ื ื™ืชืŸ ืœืชืขื“ืฃ LDAP ืื—ื“ ืขื‘ื•ืจ ื”-PAN ื”ืจืืฉื™, ื•-LDAP ืื—ืจ ื™ื›ื•ืœ ืœืงื‘ืœ ืขื“ื™ืคื•ืช ืœ-PAN ื”ืžืฉื ื™.

ISE ืชื•ืžืš ื‘ืฉื ื™ ืกื•ื’ื™ ื—ื™ืคื•ืฉ (ื—ื™ืคื•ืฉ) ื‘ืขื‘ื•ื“ื” ืขื ืฉืจืชื™ LDAP: ื—ื™ืคื•ืฉ ืžืฉืชืžืฉ ื•ื—ื™ืคื•ืฉ ื›ืชื•ื‘ื•ืช MAC. User Lookup ืžืืคืฉืจ ืœืš ืœื—ืคืฉ ืžืฉืชืžืฉ ื‘ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ LDAP ื•ืœืงื‘ืœ ืืช ื”ืžื™ื“ืข ื”ื‘ื ืœืœื ืื™ืžื•ืช: ืžืฉืชืžืฉื™ื ื•ื”ืชื›ื•ื ื•ืช ืฉืœื”ื, ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื. ื—ื™ืคื•ืฉ ื›ืชื•ื‘ื•ืช MAC ืžืืคืฉืจ ืœืš ื’ื ืœื—ืคืฉ ืœืคื™ ื›ืชื•ื‘ืช MAC ื‘ืกืคืจื™ื•ืช LDAP ืœืœื ืื™ืžื•ืช ื•ืœืงื‘ืœ ืžื™ื“ืข ืขืœ ื”ืžื›ืฉื™ืจ, ืงื‘ื•ืฆืช ืžื›ืฉื™ืจื™ื ืœืคื™ ื›ืชื•ื‘ื•ืช MAC ื•ืชื›ื•ื ื•ืช ืกืคืฆื™ืคื™ื•ืช ืื—ืจื•ืช.

ื›ื“ื•ื’ืžื” ืœืื™ื ื˜ื’ืจืฆื™ื”, ื‘ื•ืื• ื ื•ืกื™ืฃ ืืช Active Directory ืœ-Cisco ISE ื›ืฉืจืช LDAP.

1) ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ โ† ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ† ืžืงื•ืจื•ืช ื–ื”ื•ืช ื—ื™ืฆื•ื ื™ื™ื โ† LDAP โ† ื”ื•ืกืฃ. 

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 4. ื”ื•ืกืคืช ืฉืจืช LDAP

2) ื‘ืคืื ืœ ื›ืœืœื™ ืฆื™ื™ืŸ ืืช ื”ืฉื ื•ื”ืกื›ื™ืžื” ืฉืœ ืฉืจืช LDAP (ื‘ืžืงืจื” ืฉืœื ื•, Active Directory). 

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 5. ื”ื•ืกืคืช ืฉืจืช LDAP ืขื ืกื›ื™ืžืช Active Directory

3) ื”ื‘ื ืขื‘ื•ืจ ืืœ ื”ืงืฉืจ ืœืฉื•ื ื™ืช ื•ืœืฆื™ื™ืŸ ืฉื ืžืืจื—/ื›ืชื•ื‘ืช IP ืฉืจืช AD, ื™ืฆื™ืื” (389 - LDAP, 636 - SSL LDAP), ืื™ืฉื•ืจื™ ืžื ื”ืœ ื“ื•ืžื™ื™ืŸ (Admin DN - DN ืžืœื), ื ื™ืชืŸ ืœื”ืฉืื™ืจ ืคืจืžื˜ืจื™ื ืื—ืจื™ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.

ืฉื™ื ืœื‘: ื”ืฉืชืžืฉ ื‘ืคืจื˜ื™ ื“ื•ืžื™ื™ืŸ ื”ื ื™ื”ื•ืœ ื›ื“ื™ ืœืžื ื•ืข ื‘ืขื™ื•ืช ืืคืฉืจื™ื•ืช.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 6 ื”ื–ื ืช ื ืชื•ื ื™ ืฉืจืช LDAP

4) ื‘ื›ืจื˜ื™ืกื™ื™ื” ืืจื’ื•ืŸ ืกืคืจื™ื•ืช ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ืื–ื•ืจ ื”ืกืคืจื™ื™ื” ื“ืจืš ื”-DN ืฉืžืžื ื• ืœืžืฉื•ืš ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 7. ืงื‘ื™ืขืช ืกืคืจื™ื•ืช ืžื”ื™ื›ืŸ ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ื™ื›ื•ืœื•ืช ืœื”ื’ื™ืข

5) ืขื‘ื•ืจ ืืœ ื”ื—ืœื•ืŸ ืงื‘ื•ืฆื•ืช โ† ื”ื•ืกืฃ โ† ื‘ื—ืจ ืงื‘ื•ืฆื•ืช ืžื”ืกืคืจื™ื™ื” ื›ื“ื™ ืœื‘ื—ื•ืจ ืงื‘ื•ืฆื•ืช ืžืฉื™ื›ื” ืžืฉืจืช LDAP.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 8. ื”ื•ืกืคืช ืงื‘ื•ืฆื•ืช ืžืฉืจืช LDAP

6) ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ืœื—ืฅ ืื—ื–ืจ ืงื‘ื•ืฆื•ืช. ืื ื”ืงื‘ื•ืฆื•ืช ื”ื’ื™ืขื•, ืื– ื”ืฉืœื‘ื™ื ื”ืžืงื“ื™ืžื™ื ื”ื•ืฉืœืžื• ื‘ื”ืฆืœื—ื”. ืื—ืจืช, ื ืกื” ืžื ื”ืœ ืžืขืจื›ืช ืื—ืจ ื•ื‘ื“ื•ืง ืืช ื–ืžื™ื ื•ืช ื”-ISE ืขื ืฉืจืช LDAP ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ LDAP.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 9. ืจืฉื™ืžื” ืฉืœ ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ืžื•ืคืขืœื•ืช

7) ื‘ื›ืจื˜ื™ืกื™ื™ื” ืชื›ื•ื ื•ืช ืืชื” ื™ื›ื•ืœ ืœื—ืœื•ืคื™ืŸ ืœืฆื™ื™ืŸ ืื™ืœื• ืชื›ื•ื ื•ืช ืžืฉืจืช LDAP ื™ืฉ ืœืžืฉื•ืš ืœืžืขืœื”, ื•ื‘ื—ืœื•ืŸ ื”ื’ื“ืจื•ืช ืžืชืงื“ืžื•ืช ืืคืฉืจ ืืคืฉืจื•ืช ืืคืฉืจ ืฉื™ื ื•ื™ ืกื™ืกืžื”, ืฉื™ืืœืฅ ืžืฉืชืžืฉื™ื ืœืฉื ื•ืช ืืช ื”ืกื™ืกืžื” ืฉืœื”ื ืื ืคื’ ืชื•ืงืคื” ืื• ืื•ืคืกื”. ื‘ื›ืœ ืžืงืจื” ืœื—ืฅ ื—ืคืฉ ืœื”ืžืฉื™ืš.

8) ืฉืจืช LDAP ืžื•ืคื™ืข ื‘ื›ืจื˜ื™ืกื™ื™ื” ื”ืžืชืื™ืžื” ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ืžืื•ื—ืจ ื™ื•ืชืจ ืœื™ืฆื™ืจืช ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื”.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 10. ืจืฉื™ืžืช ืฉืจืชื™ LDAP ืฉื ื•ืกืคื•

4. ืื™ื ื˜ื’ืจืฆื™ื” ืขื Active Directory

1) ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืฉืจืช Microsoft Active Directory ื›ืฉืจืช LDAP, ืงื™ื‘ืœื ื• ืžืฉืชืžืฉื™ื, ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื, ืืš ืœืœื ื™ื•ืžื ื™ื. ืœืื—ืจ ืžื›ืŸ, ืื ื™ ืžืฆื™ืข ืœื”ื’ื“ื™ืจ ืื™ื ื˜ื’ืจืฆื™ื” ืžืœืื” ืฉืœ AD ืขื Cisco ISE. ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ โ† ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ† ืžืงื•ืจื•ืช ื–ื”ื•ืช ื—ื™ืฆื•ื ื™ื™ื โ† Active Directory โ† ื”ื•ืกืฃ. 

ื”ืขืจื”: ืœืื™ื ื˜ื’ืจืฆื™ื” ืžื•ืฆืœื—ืช ืขื AD, ISE ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื‘ื“ื•ืžื™ื™ืŸ ื•ื‘ืขืœ ืงื™ืฉื•ืจื™ื•ืช ืžืœืื” ืขื ืฉืจืชื™ DNS, NTP ื•-AD, ืื—ืจืช ืœื ื™ื™ืฆื ืžื–ื” ื›ืœื•ื.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 11. ื”ื•ืกืคืช ืฉืจืช Active Directory

2) ื‘ื—ืœื•ืŸ ืฉืžื•ืคื™ืข, ื”ื–ืŸ ืืช ืคืจื˜ื™ ืžื ื”ืœ ื”ื“ื•ืžื™ื™ืŸ ื•ืกืžืŸ ืืช ื”ืชื™ื‘ื” ืื™ืฉื•ืจื™ ื—ื ื•ืช. ื‘ื ื•ืกืฃ, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ OU (ื™ื—ื™ื“ื” ืืจื’ื•ื ื™ืช) ืื ISE ืžืžื•ืงื ื‘-OU ืกืคืฆื™ืคื™. ืœืื—ืจ ืžื›ืŸ, ืชืฆื˜ืจืš ืœื‘ื—ื•ืจ ืืช ืฆืžืชื™ Cisco ISE ืฉื‘ืจืฆื•ื ืš ืœื—ื‘ืจ ืœื“ื•ืžื™ื™ืŸ.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 12. ื”ื–ื ืช ืื™ืฉื•ืจื™ื

3) ืœืคื ื™ ื”ื•ืกืคืช ื‘ืงืจื™ ืชื—ื•ื, ื•ื“ื ื›ื™ ื‘-PSN ื‘ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ โ† ืžืขืจื›ืช โ† ืคืจื™ืกื” ื”ืืคืฉืจื•ืช ืžื•ืคืขืœืช ืฉื™ืจื•ืช ื–ื”ื•ืช ืคืกื™ื‘ื™ืช. ืชืขื•ื“ื” ืžื–ื”ื” ืคืกื™ื‘ื™ืช - ืืคืฉืจื•ืช ื”ืžืืคืฉืจืช ืœืชืจื’ื ืžืฉืชืžืฉ ืœ-IP ื•ืœื”ื™ืคืš. PassiveID ืžืงื‘ืœ ืžื™ื“ืข ืž-AD ื“ืจืš WMI, ืกื•ื›ื ื™ AD ืžื™ื•ื—ื“ื™ื ืื• ื™ืฆื™ืืช SPAN ืขืœ ื”ืžืชื’ (ืœื ื”ืืคืฉืจื•ืช ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ).

ื”ืขืจื”: ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืžืฆื‘ ืฉืœ ืžื–ื”ื” ืคืกื™ื‘ื™, ื”ืงืœื“ ืืช ืžืกื•ืฃ ISE ื”ืฆื’ ืืช ืกื˜ื˜ื•ืก ื”ื‘ืงืฉื” ื”ื•ื | ื›ื•ืœืœ ืžื–ื”ื” ืคืกื™ื‘ื™.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 13. ื”ืคืขืœืช ื”ืืคืฉืจื•ืช PassiveID

4) ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ โ† ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ† ืžืงื•ืจื•ืช ื–ื”ื•ืช ื—ื™ืฆื•ื ื™ื™ื โ† Active Directory โ† PassiveID ื•ื‘ื—ืจ ื‘ืืคืฉืจื•ืช ื”ื•ืกืฃ DCs. ืœืื—ืจ ืžื›ืŸ, ื‘ื—ืจ ืืช ื‘ืงืจื™ ื”ื“ื•ืžื™ื™ืŸ ื”ื“ืจื•ืฉื™ื ืขื ืชื™ื‘ื•ืช ืกื™ืžื•ืŸ ื•ืœื—ืฅ ืื™ืฉื•ืจ.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 14. ื”ื•ืกืคืช ื‘ืงืจื™ ืชื—ื•ื

5) ื‘ื—ืจ ืืช ื”-DCs ืฉื ื•ืกืคื• ื•ืœื—ืฅ ืขืœ ื”ืœื—ืฆืŸ ืœึทืขึฒืจื•ึนืš. ื ื ืœืฆื™ื™ืŸ FQDN ื”-DC ืฉืœืš, ื›ื ื™ืกื” ื•ืกื™ืกืžื” ืœื“ื•ืžื™ื™ืŸ, ื•ืืคืฉืจื•ืช ืงื™ืฉื•ืจ WMI ืื• ืกื•ึนื›ึตืŸ. ื‘ื—ืจ WMI ื•ืœื—ืฅ ืื™ืฉื•ืจ.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 15. ื”ื–ื ืช ืžื™ื“ืข ืขืœ ื‘ืงืจ ืชื—ื•ื

6) ืื WMI ืื™ื ื” ื”ืฉื™ื˜ื” ื”ืžื•ืขื“ืคืช ืœืชืงืฉื•ืจืช ืขื Active Directory, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืกื•ื›ื ื™ ISE. ืฉื™ื˜ืช ื”ืกื•ื›ืŸ ื”ื™ื ืฉื ื™ืชืŸ ืœื”ืชืงื™ืŸ ืกื•ื›ื ื™ื ืžื™ื•ื—ื“ื™ื ืขืœ ื”ืฉืจืช ืฉื™ื ืคืงื• ืื™ืจื•ืขื™ ื”ืชื—ื‘ืจื•ืช. ืงื™ื™ืžื•ืช 2 ืืคืฉืจื•ื™ื•ืช ื”ืชืงื ื”: ืื•ื˜ื•ืžื˜ื™ืช ื•ื™ื“ื ื™ืช. ื›ื“ื™ ืœื”ืชืงื™ืŸ ืืช ื”ืกื•ื›ืŸ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ื‘ืื•ืชื” ื›ืจื˜ื™ืกื™ื™ื” ืชืขื•ื“ื” ืžื–ื”ื” ืคืกื™ื‘ื™ืช ืœื‘ื—ื•ืจ ื”ื•ืกืฃ ืกื•ื›ืŸ โ† ืคืจื•ืก ืกื•ื›ืŸ ื—ื“ืฉ (ืœ-DC ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜). ืœืื—ืจ ืžื›ืŸ ืžืœื ืืช ื”ืฉื“ื•ืช ื”ื ื“ืจืฉื™ื (ืฉื ืกื•ื›ืŸ, FQDN ืฉืจืช, ื›ื ื™ืกื”/ืกื™ืกืžื” ืฉืœ ืžื ื”ืœ ื“ื•ืžื™ื™ืŸ) ื•ืœื—ืฅ ืขืœ ืื™ืฉื•ืจ.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 16. ื”ืชืงื ื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืกื•ื›ืŸ ISE

7) ื›ื“ื™ ืœื”ืชืงื™ืŸ ื™ื“ื ื™ืช Cisco ISE agent, ืขืœื™ืš ืœื‘ื—ื•ืจ ืจืฉื•ื ืกื•ื›ืŸ ืงื™ื™ื. ืื’ื‘, ืืคืฉืจ ืœื”ื•ืจื™ื“ ืืช ื”ืกื•ื›ืŸ ื‘ืœืฉื•ื ื™ืช ืžืจื›ื–ื™ ืขื‘ื•ื“ื” โ† PassiveID โ† ืกืคืงื™ื โ† ืกื•ื›ื ื™ื โ† ืกื•ื›ืŸ ื”ื•ืจื“ื”.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 17. ื”ื•ืจื“ืช ืกื•ื›ืŸ ISE

ื—ืฉื•ื‘: PassiveID ืœื ืงื•ืจื ืื™ืจื•ืขื™ื ื”ืชื ืชืงื•ืช! ื”ืคืจืžื˜ืจ ื”ืื—ืจืื™ ืœืคืกืง ื”ื–ืžืŸ ื ืงืจื ื–ืžืŸ ื”ื”ื–ื“ืงื ื•ืช ืฉืœ ื”ืคืขืœืช ื”ืžืฉืชืžืฉ ื•ืฉื•ื•ื” ืœ-24 ืฉืขื•ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืœื›ืŸ, ืขืœื™ืš ืœื”ืชื ืชืง ื‘ืขืฆืžืš ื‘ืกื•ืฃ ื™ื•ื ื”ืขื‘ื•ื“ื”, ืื• ืœื›ืชื•ื‘ ืกืงืจื™ืคื˜ ื›ืœืฉื”ื• ืฉื™ื ืชืง ืื•ื˜ื•ืžื˜ื™ืช ืืช ื›ืœ ื”ืžืฉืชืžืฉื™ื ื”ืžื—ื•ื‘ืจื™ื. 

ืœืžื™ื“ืข ื”ืชื ืชืงื•ืช ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘"ื‘ื“ื™ืงื•ืช ืงืฆื”" - ื‘ื“ื™ืงื•ืช ืงืฆื”. ื™ืฉื ื ืžืกืคืจ ื‘ื“ื™ืงื•ืช ื ืงื•ื“ืช ืงืฆื” ื‘-Cisco ISE: RADIUS, SNMP Trap, SNMP Query, DHCP, DNS, HTTP, Netflow, NMAP Scan. ืจึทื“ึดื™ื•ึผืก ื‘ื“ื™ืงื” ื‘ืืžืฆืขื•ืช CoA ื—ื‘ื™ืœื•ืช (ืฉื™ื ื•ื™ ื”ืจืฉืื•ืช) ืžืกืคืงื•ืช ืžื™ื“ืข ืขืœ ืฉื™ื ื•ื™ ื–ื›ื•ื™ื•ืช ืžืฉืชืžืฉ (ื–ื” ืžืฆืจื™ืš ืžืฉื•ื‘ืฅ 802.1X), ื•ืžื•ื’ื“ืจ ืขืœ ืžืชื’ื™ ื’ื™ืฉื” SNMP, ื™ืกืคืง ืžื™ื“ืข ืขืœ ื”ืชืงื ื™ื ืžื—ื•ื‘ืจื™ื ื•ืžื ื•ืชืงื™ื.

ืœื”ืœืŸ ื“ื•ื’ืžื” ืจืœื•ื•ื ื˜ื™ืช ืœืชืฆื•ืจืช Cisco ISE + AD ืœืœื 802.1X ื•-RADIUS: ื”ืžืฉืชืžืฉ ืžื—ื•ื‘ืจ ื‘ืžื—ืฉื‘ Windows, ืžื‘ืœื™ ืœื‘ืฆืข ื”ืชื ืชืงื•ืช, ื”ืชื—ื‘ืจ ืžืžื—ืฉื‘ ืื—ืจ ื‘ืืžืฆืขื•ืช WiFi. ื‘ืžืงืจื” ื–ื”, ื”ื”ืคืขืœื” ื‘ืžื—ืฉื‘ ื”ืจืืฉื•ืŸ ืขื“ื™ื™ืŸ ืชื”ื™ื” ืคืขื™ืœื” ืขื“ ืฉื™ืชืจื—ืฉ ืคืกืง ื–ืžืŸ ืื• ืฉืชืชืจื—ืฉ ื™ืฆื™ืื” ืžืื•ืœืฆืช. ืœืื—ืจ ืžื›ืŸ, ืื ืœืžื›ืฉื™ืจื™ื ื™ืฉ ื–ื›ื•ื™ื•ืช ืฉื•ื ื•ืช, ื”ืžื›ืฉื™ืจ ื”ืื—ืจื•ืŸ ืฉื ื›ื ืก ืœื—ืฉื‘ื•ืŸ ื™ื—ื™ืœ ืืช ื”ื–ื›ื•ื™ื•ืช ืฉืœื•.

8) ืื•ืคืฆื™ื•ื ืœื™ ื‘ืœืฉื•ื ื™ืช ื ื™ื”ื•ืœ โ†’ ื ื™ื”ื•ืœ ื–ื”ื•ื™ื•ืช โ†’ ืžืงื•ืจื•ืช ื–ื”ื•ืช ื—ื™ืฆื•ื ื™ื™ื โ†’ Active Directory โ†’ ืงื‘ื•ืฆื•ืช โ†’ ื”ื•ืกืฃ โ†’ ื‘ื—ืจ ืงื‘ื•ืฆื•ืช ืžืชื•ืš ืกืคืจื™ื™ื” ืืชื” ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ืงื‘ื•ืฆื•ืช ืž-AD ืฉื‘ืจืฆื•ื ืš ืœื”ืขืœื•ืช ื‘-ISE (ื‘ืžืงืจื” ืฉืœื ื•, ื–ื” ื ืขืฉื” ื‘ืฉืœื‘ 3 "ื”ื•ืกืคืช ืฉืจืช LDAP"). ื‘ื—ืจ ืืคืฉืจื•ืช ืื—ื–ืจ ืงื‘ื•ืฆื•ืช โ† ืื™ืฉื•ืจ

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 18 ื). ืžืฉื™ื›ืช ืงื‘ื•ืฆื•ืช ืžืฉืชืžืฉื™ื ืž- Active Directory

9) ื‘ื›ืจื˜ื™ืกื™ื™ื” ืžืจื›ื–ื™ ืขื‘ื•ื“ื” โ† PassiveID โ† ืกืงื™ืจื” ื›ืœืœื™ืช โ† ืœื•ื— ืžื—ื•ื•ื ื™ื ืืชื” ื™ื›ื•ืœ ืœืจืื•ืช ืืช ืžืกืคืจ ื”ืคืขืœื•ืช ื”ืคืขื™ืœื•ืช, ืืช ืžืกืคืจ ืžืงื•ืจื•ืช ื”ื ืชื•ื ื™ื, ื”ืกื•ื›ื ื™ื ื•ืขื•ื“.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 19. ื ื™ื˜ื•ืจ ืคืขื™ืœื•ืช ืžืฉืชืžืฉื™ ื”ื“ื•ืžื™ื™ืŸ

10) ื‘ื›ืจื˜ื™ืกื™ื™ื” ืคืขื™ืœื•ื™ื•ืช ื‘ืืชืจ ื”ื”ืคืขืœื•ืช ื”ื ื•ื›ื—ื™ื•ืช ืžื•ืฆื’ื•ืช. ืื™ื ื˜ื’ืจืฆื™ื” ืขื AD ืžื•ื’ื“ืจืช.

Cisco ISE: ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื, ื”ื•ืกืคืช ืฉืจืชื™ LDAP, ืฉื™ืœื•ื‘ ืขื AD. ื—ืœืง 2ืื™ื•ืจ 20. ื”ืคืขืœื•ืช ืคืขื™ืœื•ืช ืฉืœ ืžืฉืชืžืฉื™ ื“ื•ืžื™ื™ืŸ

5. ืžืกืงื ื”

ืžืืžืจ ื–ื” ื›ื™ืกื” ืืช ื”ื ื•ืฉืื™ื ืฉืœ ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื ื‘-Cisco ISE, ื”ื•ืกืคืช ืฉืจืชื™ LDAP ื•ืฉื™ืœื•ื‘ ืขื Microsoft Active Directory. ื”ืžืืžืจ ื”ื‘ื ื™ื“ื’ื™ืฉ ืืช ื’ื™ืฉืช ื”ืื•ืจื—ื™ื ื‘ืฆื•ืจื” ืฉืœ ืžื“ืจื™ืš ืžื™ื•ืชืจ.

ืื ื™ืฉ ืœืš ืฉืืœื•ืช ื‘ื ื•ืฉื ื–ื” ืื• ืฉืืชื” ื–ืงื•ืง ืœืขื–ืจื” ื‘ื‘ื“ื™ืงืช ื”ืžื•ืฆืจ, ืื ื ืฆื•ืจ ืงืฉืจ ืงืฉืจ.

ื”ื™ืฉืืจ ืžืขื•ื“ื›ืŸ ืœืขื“ื›ื•ื ื™ื ื‘ืขืจื•ืฆื™ื ืฉืœื ื• (ืžื‘ืจืง, ืคื™ื™ืกื‘ื•ืง, VK, ื‘ืœื•ื’ ืคืชืจื•ื ื•ืช TS, ื™ืื ื“ืงืก ื–ืŸ).

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”