Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1

1. ืžื‘ื•ื

ืœื›ืœ ื—ื‘ืจื”, ืืคื™ืœื• ื”ืงื˜ื ื” ื‘ื™ื•ืชืจ, ื™ืฉ ืฆื•ืจืš ื‘ืื™ืžื•ืช, ื”ืจืฉืื” ื•ื—ืฉื‘ื•ืŸ ืžืฉืชืžืฉ (ืžืฉืคื—ืช ืคืจื•ื˜ื•ืงื•ืœื™ื AAA). ื‘ืฉืœื‘ ื”ืจืืฉื•ื ื™, AAA ืžื™ื•ืฉื ื”ื™ื˜ื‘ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ื ื›ื’ื•ืŸ RADIUS, TACACS+ ื•-DIAMETER. ืขื ื–ืืช, ื›ื›ืœ ืฉืžืกืคืจ ื”ืžืฉืชืžืฉื™ื ื•ื”ื—ื‘ืจื” ื’ื“ืœื™ื, ื’ื“ืœ ื’ื ืžืกืคืจ ื”ืžืฉื™ืžื•ืช: ื ืจืื•ืช ืžืงืกื™ืžืœื™ืช ืฉืœ ืžืืจื—ื™ื ื•ืžื›ืฉื™ืจื™ BYOD, ืื™ืžื•ืช ืจื‘-ื’ื•ืจืžื™, ื™ืฆื™ืจืช ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื” ืจื‘-ืฉื›ื‘ืชื™ืช ื•ืขื•ื“ ื•ืขื•ื“.

ืขื‘ื•ืจ ืžืฉื™ืžื•ืช ื›ืืœื”, ืกื•ื’ ื”ืคืชืจื•ื ื•ืช ืฉืœ NAC (ื‘ืงืจืช ื’ื™ืฉื” ืœืจืฉืช) ื”ื•ื ืžื•ืฉืœื - ื‘ืงืจืช ื’ื™ืฉื” ืœืจืฉืช. ื‘ืกื“ืจืช ืžืืžืจื™ื ื”ืžื•ืงื“ืฉืช ืœ Cisco ISE (Identity Services Engine) - ืคืชืจื•ืŸ NAC ืœืืกืคืงืช ื‘ืงืจืช ื’ื™ืฉื” ืžื•ื“ืขืช ืœื”ืงืฉืจ ืœืžืฉืชืžืฉื™ื ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช, ืื ื• ื ืกืชื›ืœ ืžืคื•ืจื˜ืช ืขืœ ื”ืืจื›ื™ื˜ืงื˜ื•ืจื”, ื”ื”ืงืฆืื”, ื”ืชืฆื•ืจื” ื•ื”ืจื™ืฉื•ื™ ืฉืœ ื”ืคืชืจื•ืŸ.

ื”ืจืฉื” ืœื™ ืœื”ื–ื›ื™ืจ ืœืš ื‘ืงืฆืจื” ืฉ-Cisco ISE ืžืืคืฉืจ ืœืš:

  • ืฆื•ืจ ื‘ืžื”ื™ืจื•ืช ื•ื‘ืงืœื•ืช ื’ื™ืฉืช ืื•ืจื— ื‘-WLAN ื™ื™ืขื•ื“ื™;

  • ื–ื™ื”ื•ื™ ื”ืชืงื ื™ BYOD (ืœื“ื•ื’ืžื”, ืžื—ืฉื‘ื™ื ื‘ื™ืชื™ื™ื ืฉืœ ืขื•ื‘ื“ื™ื ืฉื”ื ื”ื‘ื™ืื• ืœืขื‘ื•ื“ื”);

  • ืจื›ื– ื•ืื›ื™ืฃ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ืขืœ ืคื ื™ ืžืฉืชืžืฉื™ ื“ื•ืžื™ื™ืŸ ื•ืžืฉืชืžืฉื™ื ืฉืื™ื ื ื“ื•ืžื™ื™ื ื™ื ื‘ืืžืฆืขื•ืช ืชื•ื•ื™ื•ืช ืงื‘ื•ืฆืช ืื‘ื˜ื—ื” SGT TrustSec);

  • ื‘ื“ื•ืง ืื ื™ืฉ ืชื•ื›ื ื•ืช ืžืกื•ื™ืžื•ืช ื”ืžื•ืชืงื ื•ืช ื‘ืžื—ืฉื‘ื™ื ื•ืชืื™ืžื•ืช ืœืชืงื ื™ื (ื”ืขืžื“ื”);

  • ืกื™ื•ื•ื’ ื•ืคืจื•ืคื™ืœ ื”ืชืงื ื™ ื ืงื•ื“ืช ืงืฆื” ื•ืจืฉืช;

  • ืœืกืคืง ื ืจืื•ืช ืฉืœ ื ืงื•ื“ื•ืช ืงืฆื”;

  • ืฉืœื— ื™ื•ืžื ื™ ืื™ืจื•ืขื™ื ืฉืœ ื›ื ื™ืกื”/ื™ืฆื™ืื” ืฉืœ ืžืฉืชืžืฉื™ื, ื—ืฉื‘ื•ื ื•ืชื™ื”ื (ื–ื”ื•ืชื) ืœ-NGFW ื›ื“ื™ ืœื™ืฆื•ืจ ืžื“ื™ื ื™ื•ืช ืžื‘ื•ืกืกืช ืžืฉืชืžืฉ;

  • ื”ืฉืชืœื‘ ื‘ืื•ืคืŸ ื˜ื‘ืขื™ ืขื Cisco StealthWatch ื•ื”ืกื’ืจ ืžืืจื—ื™ื ื—ืฉื•ื“ื™ื ื”ืžืขื•ืจื‘ื™ื ื‘ืื™ืจื•ืขื™ ืื‘ื˜ื—ื” (ื™ื•ืชืจ);

  • ื•ืชื›ื•ื ื•ืช ืื—ืจื•ืช ืกื˜ื ื“ืจื˜ื™ื•ืช ืขื‘ื•ืจ ืฉืจืชื™ AAA.

ืขืžื™ืชื™ื ื‘ืชืขืฉื™ื™ื” ื›ื‘ืจ ื›ืชื‘ื• ืขืœ Cisco ISE, ืื– ืื ื™ ืžืžืœื™ืฅ ืœืš ืœืงืจื•ื: ืชืจื’ื•ืœ ื™ื™ืฉื•ื Cisco ISE, ื›ื™ืฆื“ ืœื”ืชื›ื•ื ืŸ ืœื™ื™ืฉื•ื Cisco ISE.

2. ืื“ืจื™ื›ืœื•ืช

ืœืืจื›ื™ื˜ืงื˜ื•ืจืช Identity Services Engine ื™ืฉ 4 ื™ืฉื•ื™ื•ืช (ืฆืžืชื™ื): ืฆื•ืžืช ื ื™ื”ื•ืœ (Policy Administration Node), ืฆื•ืžืช ื”ืคืฆืช ืžื“ื™ื ื™ื•ืช (Policy Service Node), ืฆื•ืžืช ื ื™ื˜ื•ืจ (Monitoring Node) ื•ืฆื•ืžืช PxGrid (PxGrid Node). Cisco ISE ื™ื›ื•ืœ ืœื”ื™ื•ืช ื‘ื”ืชืงื ื” ืขืฆืžืื™ืช ืื• ืžื‘ื•ื–ืจืช. ื‘ื’ืจืกืช ื”-Standalone, ื›ืœ ื”ื™ืฉื•ื™ื•ืช ืžืžื•ืงืžื•ืช ื‘ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืื—ืช ืื• ื‘ืฉืจืช ืคื™ื–ื™ (Secure Network Servers - SNS), ื‘ืขื•ื“ ืฉื‘ื’ืจืกื” ื”-Distributed, ื”ืฆืžืชื™ื ืžืคื•ื–ืจื™ื ืขืœ ืคื ื™ ืžื›ืฉื™ืจื™ื ืฉื•ื ื™ื.

ืฆื•ืžืช ื ื™ื”ื•ืœ ืžื“ื™ื ื™ื•ืช (PAN) ื”ื•ื ืฆื•ืžืช ื ื“ืจืฉ ื”ืžืืคืฉืจ ืœืš ืœื‘ืฆืข ืืช ื›ืœ ืคืขื•ืœื•ืช ื”ื ื™ื”ื•ืœ ื‘-Cisco ISE. ื”ื•ื ืžื˜ืคืœ ื‘ื›ืœ ืชืฆื•ืจื•ืช ื”ืžืขืจื›ืช ื”ืงืฉื•ืจื•ืช ืœ-AAA. ื‘ืชืฆื•ืจื” ืžื‘ื•ื–ืจืช (ื ื™ืชืŸ ืœื”ืชืงื™ืŸ ืฆืžืชื™ื ื›ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ื ืคืจื“ื•ืช), ืืชื” ื™ื›ื•ืœ ืœืงื‘ืœ ืœื›ืœ ื”ื™ื•ืชืจ ืฉื ื™ PAN ืœืกื•ื‘ืœื ื•ืช ืชืงืœื•ืช - ืžืฆื‘ ืคืขื™ืœ/ื”ืžืชื ื”.

Policy Service Node (PSN) ื”ื•ื ืฆื•ืžืช ื—ื•ื‘ื” ื”ืžืกืคืง ื’ื™ืฉื” ืœืจืฉืช, ืžืฆื‘, ื’ื™ืฉื” ืœืื•ืจื—ื™ื, ืืกืคืงืช ืฉื™ืจื•ืช ืœืงื•ื—ื•ืช ื•ืคืจื•ืคื™ืœ. PSN ืžืขืจื™ืš ืืช ื”ืžื“ื™ื ื™ื•ืช ื•ืžื™ื™ืฉื ืื•ืชื”. ื‘ื“ืจืš ื›ืœืœ, ืžืกืคืจ PSNs ืžื•ืชืงื ื™ื, ื‘ืžื™ื•ื—ื“ ื‘ืชืฆื•ืจื” ืžื‘ื•ื–ืจืช, ืœืคืขื•ืœื” ืžื™ื•ืชืจืช ื•ืžืคื•ื–ืจืช ื™ื•ืชืจ. ื›ืžื•ื‘ืŸ, ื”ื ืžื ืกื™ื ืœื”ืชืงื™ืŸ ืืช ื”ืฆืžืชื™ื ื”ืœืœื• ื‘ืžืงื˜ืขื™ื ืฉื•ื ื™ื ื›ื“ื™ ืœื ืœืื‘ื“ ืืช ื”ื™ื›ื•ืœืช ืœืกืคืง ื’ื™ืฉื” ืžืื•ืžืชืช ื•ืžื•ืจืฉื™ืช ืœืฉื ื™ื™ื”.

ืฆื•ืžืช ื ื™ื˜ื•ืจ (MnT) ื”ื•ื ืฆื•ืžืช ื—ื•ื‘ื” ื”ืžืื—ืกืŸ ื™ื•ืžื ื™ ืื™ืจื•ืขื™ื, ื™ื•ืžื ื™ื ืฉืœ ืฆืžืชื™ื ืื—ืจื™ื ื•ืžื“ื™ื ื™ื•ืช ื‘ืจืฉืช. ืฆื•ืžืช MnT ืžืกืคืง ื›ืœื™ื ืžืชืงื“ืžื™ื ืœื ื™ื˜ื•ืจ ื•ืคืชืจื•ืŸ ืชืงืœื•ืช, ืื•ืกืฃ ื•ืื•ืกืฃ ื ืชื•ื ื™ื ืฉื•ื ื™ื ื•ื›ืŸ ืžืกืคืง ื“ื•ื—ื•ืช ืžืฉืžืขื•ืชื™ื™ื. Cisco ISE ืžืืคืฉืจ ืœืš ืœื”ื—ื–ื™ืง ืœื›ืœ ื”ื™ื•ืชืจ ืฉื ื™ ืฆืžืชื™ื MnT, ื•ื‘ื›ืš ืœื™ืฆื•ืจ ืกื•ื‘ืœื ื•ืช ืœืชืงืœื•ืช - ืžืฆื‘ ืคืขื™ืœ/ื”ืžืชื ื”. ืขื ื–ืืช, ื™ื•ืžื ื™ื ื ืืกืคื™ื ืขืœ ื™ื“ื™ ืฉื ื™ ื”ืฆืžืชื™ื, ื”ืŸ ืคืขื™ืœื™ื ื•ื”ืŸ ืคืกื™ื‘ื™ื™ื.

PxGrid Node (PXG) ื”ื•ื ืฆื•ืžืช ื”ืžืฉืชืžืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ PxGrid ื•ืžืืคืฉืจ ืชืงืฉื•ืจืช ื‘ื™ืŸ ืžื›ืฉื™ืจื™ื ืื—ืจื™ื ื”ืชื•ืžื›ื™ื ื‘-PxGrid.

PxGrid  โ€” ืคืจื•ื˜ื•ืงื•ืœ ื”ืžื‘ื˜ื™ื— ืฉื™ืœื•ื‘ ืฉืœ ืžื•ืฆืจื™ ืชืฉืชื™ื•ืช IT ื•ืื‘ื˜ื—ืช ืžื™ื“ืข ืžืกืคืงื™ื ืฉื•ื ื™ื: ืžืขืจื›ื•ืช ื ื™ื˜ื•ืจ, ืžืขืจื›ื•ืช ื–ื™ื”ื•ื™ ื•ืžื ื™ืขืช ืคืจื™ืฆื•ืช, ืคืœื˜ืคื•ืจืžื•ืช ืœื ื™ื”ื•ืœ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื•ืคืชืจื•ื ื•ืช ืจื‘ื™ื ืื—ืจื™ื. Cisco PxGrid ืžืืคืฉืจ ืœืš ืœืฉืชืฃ ื”ืงืฉืจ ื‘ืฆื•ืจื” ื—ื“ ื›ื™ื•ื•ื ื™ืช ืื• ื“ื• ื›ื™ื•ื•ื ื™ืช ืขื ืคืœื˜ืคื•ืจืžื•ืช ืจื‘ื•ืช ืœืœื ืฆื•ืจืš ื‘ืžืžืฉืงื™ API, ื•ื‘ื›ืš ืœืืคืฉืจ ืืช ื”ื˜ื›ื ื•ืœื•ื’ื™ื” TrustSec (ืชื’ื™ื•ืช SGT), ืฉื ื” ื•ื”ื—ืœืช ืžื“ื™ื ื™ื•ืช ANC (Adaptive Network Control) ื•ื›ืŸ ื‘ื™ืฆื•ืข ืคืจื•ืคื™ืœื™ื - ืงื‘ื™ืขืช ื“ื’ื ื”ืžื›ืฉื™ืจ, ืžืขืจื›ืช ื”ื”ืคืขืœื”, ื”ืžื™ืงื•ื ื•ืขื•ื“.

ื‘ืชืฆื•ืจืช ื–ืžื™ื ื•ืช ื’ื‘ื•ื”ื”, ืฆืžืชื™ PxGrid ืžืฉื›ืคืœื™ื ืžื™ื“ืข ื‘ื™ืŸ ืฆืžืชื™ื ื“ืจืš PAN. ืื ื”-PAN ืžื•ืฉื‘ืช, ื”ืฆื•ืžืช PxGrid ืžืคืกื™ืง ืืช ื”ืื™ืžื•ืช, ื”ื”ืจืฉืื” ื•ื”ื—ืฉื‘ื•ืŸ ืขื‘ื•ืจ ืžืฉืชืžืฉื™ื. 

ืœื”ืœืŸ ื™ื™ืฆื•ื’ ืกื›ืžื˜ื™ ืฉืœ ืคืขื•ืœืชื ืฉืœ ื™ืฉื•ื™ื•ืช ืฉื•ื ื•ืช ืฉืœ Cisco ISE ื‘ืจืฉืช ืืจื’ื•ื ื™ืช.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 1. ืืจื›ื™ื˜ืงื˜ื•ืจืช ISE ืฉืœ Cisco

3. ื“ืจื™ืฉื•ืช

ื ื™ืชืŸ ืœื™ื™ืฉื ืืช Cisco ISE, ื›ืžื• ืจื•ื‘ ื”ืคืชืจื•ื ื•ืช ื”ืžื•ื“ืจื ื™ื™ื, ื‘ืื•ืคืŸ ื•ื™ืจื˜ื•ืืœื™ ืื• ืคื™ื–ื™ ื›ืฉืจืช ื ืคืจื“. 

ืžื›ืฉื™ืจื™ื ืคื™ื–ื™ื™ื ื”ืžืจื™ืฆื™ื ืชื•ื›ื ืช Cisco ISE ื ืงืจืื™ื SNS (ืฉืจืช ืจืฉืช ืžืื•ื‘ื˜ื—). ื”ื ืžื’ื™ืขื™ื ื‘ืฉืœื•ืฉื” ื“ื’ืžื™ื: SNS-3615, SNS-3655 ื•-SNS-3695 ืœืขืกืงื™ื ืงื˜ื ื™ื, ื‘ื™ื ื•ื ื™ื™ื ื•ื’ื“ื•ืœื™ื. ื˜ื‘ืœื” 1 ืžืฆื™ื’ื” ืžื™ื“ืข ืž ื˜ื•ืคืก ืžื™ื“ืข SNS.

ื˜ื‘ืœื” 1. ื˜ื‘ืœืช ื”ืฉื•ื•ืื” ืฉืœ SNS ืขื‘ื•ืจ ืกื•ืœืžื•ืช ืฉื•ื ื™ื

ืคืจืžื˜ืจ

SNS 3615 (ืงื˜ืŸ)

SNS 3655 (ื‘ื™ื ื•ื ื™)

SNS 3695 (ื’ื“ื•ืœ)

ืžืกืคืจ ื ืงื•ื“ื•ืช ื”ืงืฆื” ื”ื ืชืžื›ื•ืช ื‘ื”ืชืงื ื” ืขืฆืžืื™ืช

10000

25000

50000

ืžืกืคืจ ื ืงื•ื“ื•ืช ื”ืงืฆื” ื”ื ืชืžื›ื•ืช ืœื›ืœ PSN

10000

25000

100000

ืžืขื‘ื“ (Intel Xeon 2.10 GHz)

8 ืœื™ื‘ื•ืช

12 ืœื™ื‘ื•ืช

12 ืœื™ื‘ื•ืช

RAM 

32 GB (2 x 16 GB)

96 GB (6 x 16 GB)

256 GB (16 x 16 GB)

HDD

1 x 600 GB

4 x 600 GB

8 x 600 GB

RAID ื—ื•ืžืจื”

ืœื

RAID 10, ื ื•ื›ื—ื•ืช ืฉืœ ื‘ืงืจ RAID

RAID 10, ื ื•ื›ื—ื•ืช ืฉืœ ื‘ืงืจ RAID

ืžืžืฉืงื™ ืจืฉืช

2 x 10Gbase-T

4 x 1Gbase-T 

2 x 10Gbase-T

4 x 1Gbase-T 

2 x 10Gbase-T

4 x 1Gbase-T

ืœื’ื‘ื™ ื™ื™ืฉื•ืžื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื, ื”ื”ื™ืคืจื•ื•ื™ื–ื•ืจื™ื ื”ื ืชืžื›ื™ื ื”ื VMware ESXi (ืžื•ืžืœืฆืช ืžื™ื ื™ืžื•ื VMware ื’ืจืกื” 11 ืขื‘ื•ืจ ESXi 6.0), Microsoft Hyper-V ื•-Linux KVM (RHEL 7.0). ื”ืžืฉืื‘ื™ื ืฆืจื™ื›ื™ื ืœื”ื™ื•ืช ื‘ืขืจืš ื›ืžื• ื‘ื˜ื‘ืœื” ืœืžืขืœื”, ืื• ื™ื•ืชืจ. ืขื ื–ืืช, ื”ื“ืจื™ืฉื•ืช ื”ืžื™ื ื™ืžืœื™ื•ืช ืขื‘ื•ืจ ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืœืขืกืงื™ื ืงื˜ื ื™ื ื”ืŸ: ืžืขื‘ื“ 2 ืขื ืชื“ืจ ืฉืœ 2.0 GHz ื•ืžืขืœื”, 16 ื’'ื™ื’ื” ื–ื™ื›ืจื•ืŸ RAM ะธ 200 GB HDD. 

ืœืคืจื˜ื™ ืคืจื™ืกื” ืื—ืจื™ื ืฉืœ Cisco ISE, ืื ื ืฆื•ืจ ืงืฉืจ ืื•ืชื ื• ืื• ืœ ืžืฉืื‘ ืžืก' 1, ืžืฉืื‘ ืžืก' 2.

4. ื”ืชืงื ื”

ื›ืžื• ืจื•ื‘ ืžื•ืฆืจื™ Cisco ื”ืื—ืจื™ื, ื ื™ืชืŸ ืœื‘ื“ื•ืง ืืช ISE ื‘ื›ืžื” ื“ืจื›ื™ื:

  • dcloud - ืฉื™ืจื•ืช ืขื ืŸ ืฉืœ ืคืจื™ืกื•ืช ืžืขื‘ื“ื” ืžื•ืชืงื ื•ืช ืžืจืืฉ (ื“ืจื•ืฉ ื—ืฉื‘ื•ืŸ ืกื™ืกืงื•);

  • ื‘ืงืฉืช GVE - ื‘ืงืฉื” ืž ัะฐะนั‚ะฐ ืกื™ืกืงื• ืฉืœ ืชื•ื›ื ื•ืช ืžืกื•ื™ืžื•ืช (ืฉื™ื˜ื” ืœืฉื•ืชืคื™ื). ืืชื” ื™ื•ืฆืจ ืžืงืจื” ืขื ื”ืชื™ืื•ืจ ื”ื˜ื™ืคื•ืกื™ ื”ื‘ื: ืกื•ื’ ืžื•ืฆืจ [ISE], ISE Software [ise-2.7.0.356.SPA.x8664], ืชื™ืงื•ืŸ ISE [ise-patchbundle-2.7.0.356-Patch2-20071516.SPA.x8664];

  • ืคืจื•ื™ืงื˜ ืคื™ื™ืœื•ื˜ - ืฆื•ืจ ืงืฉืจ ืขื ื›ืœ ืฉื•ืชืฃ ืžื•ืจืฉื” ืœื‘ื™ืฆื•ืข ืคืจื•ื™ืงื˜ ืคื™ื™ืœื•ื˜ ื‘ื—ื™ื ื.

1) ืœืื—ืจ ื™ืฆื™ืจืช ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช, ืื ื‘ื™ืงืฉืช ืงื•ื‘ืฅ ISO ื•ืœื ืชื‘ื ื™ืช OVA, ื™ืงืคื•ืฅ ื—ืœื•ืŸ ืฉื‘ื• ISE ื“ื•ืจืฉ ืžืžืš ืœื‘ื—ื•ืจ ื”ืชืงื ื”. ืœืฉื ื›ืš, ื‘ืžืงื•ื ื”ื›ื ื™ืกื” ื•ื”ืกื™ืกืžื” ืฉืœืš, ืขืœื™ืš ืœื›ืชื•ื‘ "ื”ืชืงื ื”"!

ื”ืขืจื”: ืื ืคืจืกืช ISE ืžืชื‘ื ื™ืช OVA, ืื– ืคืจื˜ื™ ื”ื›ื ื™ืกื” admin/MyIseYPass2 (ื–ื” ื•ืขื•ื“ ื”ืจื‘ื” ื™ื•ืชืจ ืžืฆื•ื™ืŸ ื‘ืจืฉืžื™ ืœื”ื ื—ื•ืช).

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 2. ื”ืชืงื ืช Cisco ISE

2) ืœืื—ืจ ืžื›ืŸ ืขืœื™ืš ืœืžืœื ืืช ื”ืฉื“ื•ืช ื”ื ื“ืจืฉื™ื ื›ื’ื•ืŸ ื›ืชื•ื‘ืช IP, DNS, NTP ื•ืื—ืจื™ื.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 3. ืืชื—ื•ืœ Cisco ISE

3) ืœืื—ืจ ืžื›ืŸ, ื”ืžื›ืฉื™ืจ ื™ืืชื—ืœ ืžื—ื“ืฉ, ื•ืชื•ื›ืœื• ืœื”ืชื—ื‘ืจ ื“ืจืš ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ืช ื”-IP ืฉืฆื•ื™ื ื” ืงื•ื“ื ืœื›ืŸ.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 4. ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ืฉืœ Cisco ISE

4) ื‘ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ืžืขืจื›ืช > ืคืจื™ืกื” ืืชื” ื™ื›ื•ืœ ืœื‘ื—ื•ืจ ืื™ืœื• ืฆืžืชื™ื (ื™ืฉื•ื™ื•ืช) ืžื•ืคืขืœื™ื ื‘ืžื›ืฉื™ืจ ืžืกื•ื™ื. ื”ืฆื•ืžืช PxGrid ืžื•ืคืขืœ ื›ืืŸ.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 5. ื ื™ื”ื•ืœ ื™ืฉื•ื™ื•ืช ืฉืœ Cisco ISE

5) ื•ืื– ื‘ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ืžืขืจื›ืช > ื’ื™ืฉืช ืžื ื”ืœ > ืื™ืžื•ืช ืื ื™ ืžืžืœื™ืฅ ืœื”ื’ื“ื™ืจ ืžื“ื™ื ื™ื•ืช ืกื™ืกืžืื•ืช, ืฉื™ื˜ืช ืื™ืžื•ืช (ืชืขื•ื“ื” ืื• ืกื™ืกืžื”), ืชืืจื™ืš ืชืคื•ื’ื” ืฉืœ ื”ื—ืฉื‘ื•ืŸ ื•ื”ื’ื“ืจื•ืช ืื—ืจื•ืช.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 6. ื”ื’ื“ืจืช ืกื•ื’ ืื™ืžื•ืชCisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 7. ื”ื’ื“ืจื•ืช ืžื“ื™ื ื™ื•ืช ืกื™ืกืžื”Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 8. ื”ื’ื“ืจืช ื›ื™ื‘ื•ื™ ื—ืฉื‘ื•ืŸ ืœืื—ืจ ืชื•ื ื”ื–ืžืŸCisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 9. ื”ื’ื“ืจืช ื ืขื™ืœืช ื—ืฉื‘ื•ืŸ

6) ื‘ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ืžืขืจื›ืช > ื’ื™ืฉืช ืžื ื”ืœ ืžืขืจื›ืช > ืžื ื”ืœื™ ืžืขืจื›ืช > ืžืฉืชืžืฉื™ ื ื™ื”ื•ืœ > ื”ื•ืกืฃ ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืžื ื”ืœ ื—ื“ืฉ.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 10. ื™ืฆื™ืจืช ืžื ื”ืœ ืžืขืจื›ืช ืžืงื•ืžื™ ืฉืœ Cisco ISE

7) ื”ืžื ื”ืœ ื”ื—ื“ืฉ ื™ื›ื•ืœ ืœื”ื™ื•ืช ื—ืœืง ืžืงื‘ื•ืฆื” ื—ื“ืฉื” ืื• ืงื‘ื•ืฆื•ืช ืฉื›ื‘ืจ ืžื•ื’ื“ืจื•ืช ืžืจืืฉ. ืงื‘ื•ืฆื•ืช ืžื ื”ืœื™ื ืžื ื•ื”ืœื•ืช ื‘ืื•ืชื• ื—ืœื•ื ื™ืช ื‘ื›ืจื˜ื™ืกื™ื™ื” ืงื‘ื•ืฆื•ืช ื ื™ื”ื•ืœ. ื˜ื‘ืœื” 2 ืžืกื›ืžืช ืžื™ื“ืข ืขืœ ืžื ื”ืœื™ ISE, ื–ื›ื•ื™ื•ืชื™ื”ื ื•ืชืคืงื™ื“ื™ื”ื.

ื˜ื‘ืœื” 2. ืงื‘ื•ืฆื•ืช ืžื ื”ืœื™ ืžืขืจื›ืช ืฉืœ Cisco ISE, ืจืžื•ืช ื’ื™ืฉื”, ื”ืจืฉืื•ืช ื•ื”ื’ื‘ืœื•ืช

ืฉื ืงื‘ื•ืฆืช ืžื ื”ืœ

ื”ืจืฉืื•ืช

ื”ื’ื‘ืœื•ืช

ืžื ื”ืœ ื”ืชืืžื” ืื™ืฉื™ืช

ื”ืงืžืช ืคื•ืจื˜ืœื™ ืื•ืจื—ื™ื ื•ื—ืกื•ื™ื•ืช, ื ื™ื”ื•ืœ ื•ื”ืชืืžื” ืื™ืฉื™ืช

ื—ื•ืกืจ ื™ื›ื•ืœืช ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ืื• ืœื”ืฆื™ื’ ื“ื•ื—ื•ืช

ืžื ื”ืœ ื“ืœืคืง ืขื–ืจื”

ื™ื›ื•ืœืช ืœื”ืฆื™ื’ ืืช ืœื•ื— ื”ืžื—ื•ื•ื ื™ื ื”ืจืืฉื™, ื›ืœ ื”ื“ื•ื—ื•ืช, ื”ืœื—ืฆื™ื ื•ื–ืจืžื™ื ืœืคืชืจื•ืŸ ื‘ืขื™ื•ืช

ืื™ื ืš ื™ื›ื•ืœ ืœืฉื ื•ืช, ืœื™ืฆื•ืจ ืื• ืœืžื—ื•ืง ื“ื•ื—ื•ืช, ื”ืชืจืื•ืช ื•ื™ื•ืžื ื™ ืื™ืžื•ืช

ืžื ื”ืœ ื–ื”ื•ืช

ื ื™ื”ื•ืœ ืžืฉืชืžืฉื™ื, ื”ืจืฉืื•ืช ื•ืชืคืงื™ื“ื™ื, ื™ื›ื•ืœืช ืฆืคื™ื™ื” ื‘ื™ื•ืžื ื™ื, ื“ื•ื—ื•ืช ื•ืื–ืขืงื•ืช

ืœื ื ื™ืชืŸ ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ืื• ืœื‘ืฆืข ืžืฉื™ืžื•ืช ื‘ืจืžืช ืžืขืจื›ืช ื”ื”ืคืขืœื”

ืžื ื”ืœ MnT

ื ื™ื˜ื•ืจ ืžืœื, ื“ื•ื—ื•ืช, ืื–ืขืงื•ืช, ื™ื•ืžื ื™ื ื•ื ื™ื”ื•ืœื

ื—ื•ืกืจ ื™ื›ื•ืœืช ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ื›ืœืฉื”ื™

ืžื ื”ืœ ืžื›ืฉื™ืจ ืจืฉืช

ื–ื›ื•ื™ื•ืช ืœื™ืฆื™ืจื” ื•ืฉื™ื ื•ื™ ืฉืœ ืื•ื‘ื™ื™ืงื˜ื™ ISE, ืฆืคื™ื™ื” ื‘ื™ื•ืžื ื™ื, ื“ื•ื—ื•ืช, ืœื•ื— ืžื—ื•ื•ื ื™ื ืจืืฉื™

ืœื ื ื™ืชืŸ ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ืื• ืœื‘ืฆืข ืžืฉื™ืžื•ืช ื‘ืจืžืช ืžืขืจื›ืช ื”ื”ืคืขืœื”

ืžื ื”ืœ ืžื“ื™ื ื™ื•ืช

ื ื™ื”ื•ืœ ืžืœื ืฉืœ ื›ืœ ื”ืžื“ื™ื ื™ื•ืช, ืฉื™ื ื•ื™ ืคืจื•ืคื™ืœื™ื, ื”ื’ื“ืจื•ืช, ืฆืคื™ื™ื” ื‘ื“ื•ื—ื•ืช

ื—ื•ืกืจ ื™ื›ื•ืœืช ืœื‘ืฆืข ื”ื’ื“ืจื•ืช ืขื ืื™ืฉื•ืจื™ื, ืื•ื‘ื™ื™ืงื˜ื™ ISE

ืžื ื”ืœ RBAC

ื›ืœ ื”ื”ื’ื“ืจื•ืช ื‘ืœืฉื•ื ื™ืช ืชืคืขื•ืœ, ื”ื’ื“ืจื•ืช ืžื“ื™ื ื™ื•ืช ANC, ื ื™ื”ื•ืœ ื“ื™ื•ื•ื—ื™ื

ืื™ื ืš ื™ื›ื•ืœ ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ืžืœื‘ื“ ANC ืื• ืœื‘ืฆืข ืžืฉื™ืžื•ืช ื‘ืจืžืช ืžืขืจื›ืช ื”ื”ืคืขืœื”

ืžืฉืชืžืฉ-ืขืœ

ื–ื›ื•ื™ื•ืช ืœื›ืœ ื”ื”ื’ื“ืจื•ืช, ื”ื“ื™ื•ื•ื— ื•ื”ื ื™ื”ื•ืœ, ื™ื›ื•ืœื•ืช ืœืžื—ื•ืง ื•ืœืฉื ื•ืช ืืช ืื™ืฉื•ืจื™ ืžื ื”ืœ ื”ืžืขืจื›ืช

ืœื ื ื™ืชืŸ ืœืฉื ื•ืช, ืžื—ืง ืคืจื•ืคื™ืœ ืื—ืจ ืžืงื‘ื•ืฆืช Super Admin

ืžื ื”ืœ ืžืขืจื›ืช

ื›ืœ ื”ื”ื’ื“ืจื•ืช ื‘ืœืฉื•ื ื™ืช ืชืคืขื•ืœ, ื ื™ื”ื•ืœ ื”ื’ื“ืจื•ืช ืžืขืจื›ืช, ืžื“ื™ื ื™ื•ืช ANC, ืฆืคื™ื™ื” ื‘ื“ื•ื—ื•ืช

ืื™ื ืš ื™ื›ื•ืœ ืœืฉื ื•ืช ืžื“ื™ื ื™ื•ืช ืžืœื‘ื“ ANC ืื• ืœื‘ืฆืข ืžืฉื™ืžื•ืช ื‘ืจืžืช ืžืขืจื›ืช ื”ื”ืคืขืœื”

ืžื ื”ืœ RESTful Services (ERS) ื—ื™ืฆื•ื ื™

ื’ื™ืฉื” ืžืœืื” ืœ-Cisco ISE REST API

ืจืง ืœื”ืจืฉืื”, ื ื™ื”ื•ืœ ืฉืœ ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื, ืžืืจื—ื™ื ื•ืงื‘ื•ืฆื•ืช ืื‘ื˜ื—ื” (SG)

ืžืคืขื™ืœ ื—ื™ืฆื•ื ื™ ืฉืœ RESTful Services (ERS).

ื”ืจืฉืื•ืช ืงืจื™ืื” ืฉืœ Cisco ISE REST API

ืจืง ืœื”ืจืฉืื”, ื ื™ื”ื•ืœ ืฉืœ ืžืฉืชืžืฉื™ื ืžืงื•ืžื™ื™ื, ืžืืจื—ื™ื ื•ืงื‘ื•ืฆื•ืช ืื‘ื˜ื—ื” (SG)

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 11. ืงื‘ื•ืฆื•ืช ืžื ื”ืœื™ ืžืขืจื›ืช ืฉืœ Cisco ISE ืžื•ื’ื“ืจื•ืช ืžืจืืฉ

8) ืื•ืคืฆื™ื•ื ืœื™ ื‘ืœืฉื•ื ื™ืช ื”ืจืฉืื” > ื”ืจืฉืื•ืช > ืžื“ื™ื ื™ื•ืช RBAC ืืชื” ื™ื›ื•ืœ ืœืขืจื•ืš ืืช ื”ื–ื›ื•ื™ื•ืช ืฉืœ ืžื ื”ืœื™ ืžืขืจื›ืช ืžื•ื’ื“ืจื™ื ืžืจืืฉ.

Cisco ISE: ืžื‘ื•ื, ื“ืจื™ืฉื•ืช, ื”ืชืงื ื”. ื—ืœืง 1ืื™ื•ืจ 12. ื ื™ื”ื•ืœ ื–ื›ื•ื™ื•ืช ืคืจื•ืคื™ืœ ืžื•ื’ื“ืจ ืžืจืืฉ ืฉืœ Cisco ISE Administrator

9) ื‘ื›ืจื˜ื™ืกื™ื™ื” ื ื™ื”ื•ืœ > ืžืขืจื›ืช > ื”ื’ื“ืจื•ืช ื›ืœ ื”ื’ื“ืจื•ืช ื”ืžืขืจื›ืช ื–ืžื™ื ื•ืช (DNS, NTP, SMTP ื•ืื—ืจื•ืช). ืืชื” ื™ื›ื•ืœ ืœืžืœื ืื•ืชื ื›ืืŸ ืื ืคืกืคืกืช ืื•ืชื ื‘ืžื”ืœืš ืืชื—ื•ืœ ื”ืžื›ืฉื™ืจ ื”ืจืืฉื•ื ื™.

5. ืžืกืงื ื”

ื‘ื›ืš ืžืกืชื™ื™ื ื”ืžืืžืจ ื”ืจืืฉื•ืŸ. ื“ื ื• ื‘ื™ืขื™ืœื•ืชื• ืฉืœ ืคืชืจื•ืŸ Cisco ISE NAC, ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ืฉืœื•, ื“ืจื™ืฉื•ืช ื”ืžื™ื ื™ืžื•ื ื•ืืคืฉืจื•ื™ื•ืช ื”ืคืจื™ืกื” ื•ื”ื”ืชืงื ื” ื”ืจืืฉื•ื ื™ืช.

ื‘ืžืืžืจ ื”ื‘ื, ื ื‘ื—ืŸ ื™ืฆื™ืจืช ื—ืฉื‘ื•ื ื•ืช, ืฉื™ืœื•ื‘ ืขื Microsoft Active Directory ื•ื™ืฆื™ืจืช ื’ื™ืฉืช ืื•ืจื—.

ืื ื™ืฉ ืœืš ืฉืืœื•ืช ื‘ื ื•ืฉื ื–ื” ืื• ืฉืืชื” ื–ืงื•ืง ืœืขื–ืจื” ื‘ื‘ื“ื™ืงืช ื”ืžื•ืฆืจ, ืื ื ืฆื•ืจ ืงืฉืจ ืงืฉืจ.

ื”ื™ืฉืืจ ืžืขื•ื“ื›ืŸ ืœืขื“ื›ื•ื ื™ื ื‘ืขืจื•ืฆื™ื ืฉืœื ื• (ืžื‘ืจืงืคื™ื™ืกื‘ื•ืงVKื‘ืœื•ื’ ืคืชืจื•ื ื•ืช TSื™ืื ื“ืงืก ื–ืŸ).

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”