Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2

ื‘ืจื•ื›ื™ื ื”ื‘ืื™ื ืฆื• ื“ื™ ืจื’ืข ืคึผืึธืกื˜ืŸ ืื™ืŸ ื“ื™ Cisco ISE ืกืขืจื™ืข. ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืึทืจื˜ื™ืงืœ  ื“ื™ ืึทื“ื•ื•ืึทื ื˜ืึทื’ืขืก ืื•ืŸ ื“ื™ืคืขืจืึทื ืกื™ื– ืคื•ืŸ ื ืขื˜ื•ื•ืึธืจืง ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ (NAC) ืกืึทืœื•ืฉืึทื ื– ืคื•ืŸ ื ืึธืจืžืึทืœ ืึทืึทืึท, ื“ื™ ืื™ื™ื’ื ืืจื˜ื™ืงื™ื™ื˜ ืคื•ืŸ Cisco ISE, ื“ื™ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ ืื•ืŸ ื“ื™ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืคึผืจืึธืฆืขืก ืคื•ืŸ ื“ื™ ืคึผืจืึธื“ื•ืงื˜ ื–ืขื ืขืŸ ื›ื™ื™ืœื™ื™ื˜ื™ื“.

ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ, ืžื™ืจ ื•ื•ืขืœืŸ ื“ืขืœื•ื• ืื™ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึทืงืึทื•ื ืฅ, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก ืื•ืŸ ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ Microsoft Active Directory, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื ื•ืึทื ืกื™ื– ืคื•ืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ PassiveID. ืื™ื™ื“ืขืจ ืœื™ื™ืขื ืขืŸ, ืื™ืš ืฉื˜ืืจืง ืจืขืงืึธืžืขื ื“ื™ืจืŸ ืึทื– ืื™ืจ ืœื™ื™ืขื ืขืŸ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ.

1. ืขื˜ืœืขื›ืข ื˜ืขืจืžื™ื ืึธืœืึธื’ื™ืข

ื‘ืึทื ื™ืฆืขืจ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ - ืึท ื‘ืึทื ื™ืฆืขืจ ื—ืฉื‘ื•ืŸ ื•ื•ืึธืก ื›ึผื•ืœืœ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื“ื–ืฉืขื ืขืจื™ื™ืฅ ื–ื™ื™ืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืคึฟืึทืจ ืึทืงืกืขืก ื“ื™ ื ืขืฅ. ื“ื™ ืคืืœื’ืขื ื“ืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ื˜ื™ืคึผื™ืงืœื™ ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืื™ื“ืขื ื˜ื™ื˜ืขื˜: ื ืืžืขืŸ, ื‘ืœื™ืฆืคึผืึธืกื˜ ืึทื“ืจืขืก, ืคึผืึทืจืึธืœ, ื—ืฉื‘ื•ืŸ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’, ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืข ืื•ืŸ ืจืึธืœืข.

ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก - ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ื–ืขื ืขืŸ ืึท ื–ืึทืžืœื•ื ื’ ืคื•ืŸ ื™ื—ื™ื“ ื™ื•ื–ืขืจื– ื•ื•ืึธืก ื”ืึธื‘ืŸ ืึท ืคึผืจืึธืกื˜ ื’ืึทื ื’ ืคื•ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื•ื•ืึธืก ืœืึธื–ืŸ ื–ื™ื™ ืึทืงืกืขืก ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื’ืึทื ื’ ืคื•ืŸ Cisco ISE ื‘ืึทื“ื™ื ื•ื ื’ืก ืื•ืŸ ืคืึทื ื’ืงืฉืึทื ื–.

ื‘ืึทื ื™ืฆืขืจ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ื’ืจื•ืคึผืขืก - ืคึผืจืขื“ืขืคื™ื ืขื“ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ื•ื•ืึธืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื–ื™ื›ืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ืจืึธืœืขืก. ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืึทื ื™ืฆืขืจ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ื’ืจื•ืคึผืขืก ืขืงืกื™ืกื˜ื™ืจืŸ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ื’ืŸ ื™ื•ื–ืขืจื– ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ืฆื• ื–ื™ื™: ืขืžืคึผืœื•ื™ืขืข (ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ), SponsorAllAccount, SponsorGroupAccounts, SponsorOwnAccounts (ืกืคึผืึธื ืกืึธืจ ืึทืงืึทื•ื ืฅ ืคึฟืึทืจ ืึธื ืคื™ืจื•ื ื’ ื“ื™ ื’ืึทืกื˜ ื˜ื•ื™ืขืจ), ื’ืึทืกื˜ (ื’ืึทืกื˜), ActivatedGuest (ืึทืงื˜ื™ื•ื•ื™ื™ื˜ื™ื“ ื’ืึทืกื˜).

ื‘ืึทื ื™ืฆืขืจ-ืจืึธืœืข- ื ื‘ืึทื ื™ืฆืขืจ ืจืึธืœืข ืื™ื– ืึท ืกื›ื•ื ืคื•ืŸ ืคึผืขืจืžื™ืฉืึทื ื– ื•ื•ืึธืก ื‘ืึทืฉื˜ื™ืžืขืŸ ื•ื•ืึธืก ื˜ืึทืกืงืก ืึท ื‘ืึทื ื™ืฆืขืจ ืงืขื ืขืŸ ื“ื•ืจื›ืคื™ืจืŸ ืื•ืŸ ื•ื•ืึธืก ืกืขืจื•ื•ื™ืกืขืก ืงืขื ืขืŸ ืึทืงืกืขืก. ืึธืคื˜ ืึท ื‘ืึทื ื™ืฆืขืจ ืจืึธืœืข ืื™ื– ืคืืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืึท ื’ืจื•ืคึผืข ืคื•ืŸ โ€‹โ€‹ื ื™ืฆืขืจืก.

ื“ืขืจืฆื•, ื™ืขื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืข ื”ืื˜ ื ืึธืš ืึทื˜ืจื™ื‘ื™ื•ืฅ ื•ื•ืึธืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืื•ืŸ ืžืขืจ ืกืคึผืึทืกื™ืคื™ืงืœื™ ื“ืขืคื™ื ื™ืจืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ (ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืข). ืžืขืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ืŸ ืคื™ืจืŸ.

2. ืฉืึทืคึฟืŸ ื”ื™ื’ืข ื ื™ืฆืขืจืก

1) Cisco ISE ื”ืื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉืึทืคึฟืŸ ื”ื™ื’ืข ื ื™ืฆืขืจืก ืื•ืŸ ื ื•ืฆืŸ ื–ื™ื™ ืื™ืŸ ืึท ืึทืงืกืขืก ืคึผืึธืœื™ื˜ื™ืง ืึธื“ืขืจ ืืคื™ืœื• ื’ืขื‘ืŸ ืึท ืคึผืจืึธื“ื•ืงื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข ืจืึธืœืข. ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ โ†’ ื™ื•ื–ืขืจื– โ†’ ืœื™ื™ื’.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 1 ืึทื“ื™ื ื’ ืึท ืœืืงืืœืข ื‘ืึทื ื™ืฆืขืจ ืฆื• Cisco ISE

2) ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ื•ื•ืึธืก ืื™ื– ืืจื•ื™ืก, ืฉืึทืคึฟืŸ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ, ืฉื˜ืขืœืŸ ืึท ืคึผืึทืจืึธืœ ืื•ืŸ ืื ื“ืขืจืข ืคืึทืจืฉื˜ื™ื™ื™ืง ืคึผืึทืจืึทืžืขื˜ืขืจืก.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 2. ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืœืืงืืœืข ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ Cisco ISE

3) ื™ื•ื–ืขืจื– ืงืขื ืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ื™ืžืคึผืึธืจื˜ื™ื“. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ โ†’ ื™ื•ื–ืขืจื– ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืึทืŸ ืึธืคึผืฆื™ืข ืึทืจื™ื™ึทื ืคื™ืจ ืื•ืŸ ื•ืคึผืœืึธืึทื“ ืงืกื•ื• ืึธื“ืขืจ ื˜ืงืกื˜ ื˜ืขืงืข ืžื™ื˜ ื™ื•ื–ืขืจื–. ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึท ืžื•ืกื˜ืขืจ ืกืขืœืขืงื˜ื™ืจืŸ ืฉืึทืคึฟืŸ ืึท ืžื•ืกื˜ืขืจ, ื“ืขืžืึธืœื˜ ืขืก ื–ืึธืœ ื–ื™ื™ืŸ ืึธื ื’ืขืคื™ืœื˜ ืžื™ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื ื™ืฆืขืจืก ืื™ืŸ ืึท ืคึผืึทืกื™ืง ืคืึธืจืขื.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 3 ื™ืžืคึผืึธืจื˜ื™ื ื’ ื™ื•ื–ืขืจื– ืื™ืŸ Cisco ISE

3. ืึทื“ื™ื ื’ ืœื“ืึทืคึผ ืกืขืจื•ื•ืขืจืก

ืœืึธื–ืŸ ืžื™ืจ ื“ืขืจืžืึธื ืขืŸ ืื™ืจ ืึทื– LDAP ืื™ื– ืึท ืคืึธืœืงืก ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ื™ืฃ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืžื“ืจื’ื” ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ื“ื•ืจื›ืคื™ืจืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ื–ื•ื›ืŸ ืคึฟืึทืจ ืึทืงืึทื•ื ืฅ ืื™ืŸ ื“ื™ ื“ื™ืจืขืงื˜ืขืจื™ื– ืคื•ืŸ LDAP ืกืขืจื•ื•ืขืจืก, ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืคึผืึธืจื˜ 389 ืึธื“ืขืจ 636 (ืกืก). ื‘ืึทื•ื•ื•ืกื˜ ื‘ื™ื™ืฉืคื™ืœืŸ ืคื•ืŸ LDAP ืกืขืจื•ื•ืขืจืก ื–ืขื ืขืŸ ืึทืงื˜ื™ื•ื• Directory, Sun Directory, Novell eDirectory ืื•ืŸ OpenLDAP. ื™ืขื“ืขืจ ืคึผืึธื–ื™ืฆื™ืข ืื™ืŸ ื“ื™ LDAP ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ื– ื“ื™ืคื™ื™ื ื“ ื“ื•ืจืš ืึท DN (ื“ื™ืกื˜ื™ื ื’ื•ื™ืฉืขื“ ื ืึธืžืขืŸ) ืื•ืŸ ื“ื™ ืึทืจื‘ืขื˜ ืคื•ืŸ ืจื™ื˜ืจื™ื•ื•ื™ื ื’ ืึทืงืึทื•ื ืฅ, ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ืื•ืŸ ืึทื˜ืจื™ื‘ื™ื•ืฅ ืื™ื– ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ืฆื• ืคืึธืจืขื ืึทืŸ ืึทืงืกืขืก ืคึผืึธืœื™ื˜ื™ืง.

ืื™ืŸ Cisco ISE, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ืึทืงืกืขืก ืฆื• ืคื™ืœืข LDAP ืกืขืจื•ื•ืขืจืก, ืื•ืŸ ื“ืขืจืžื™ื˜ ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ื™ื‘ืขืจื™ืงื™ื™ึทื˜. ืื•ื™ื‘ ื“ื™ ืขืจืฉื˜ื™ืง (ืขืจืฉื˜ื™ืง) LDAP ืกืขืจื•ื•ืขืจ ืื™ื– ื ื™ืฉื˜ ื‘ื ื™ืžืฆื, ISE ื•ื•ืขื˜ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืึทืงืกืขืก ื“ื™ ืฆื•ื•ื™ื™ื˜ื™ืง (ืฆื•ื•ื™ื™ื˜ื™ืง) ืื•ืŸ ืึทื–ื•ื™ ืื•ื™ืฃ. ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ 2 PANs, ืื™ื™ื ืขืจ LDAP ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคึผืจื™ื™ืึธืจืึทื˜ื™ื™ื–ื“ ืคึฟืึทืจ ื“ื™ ืขืจืฉื˜ื™ืง PAN ืื•ืŸ ืื ื“ืขืจืŸ LDAP ืคึฟืึทืจ ื“ื™ ืฆื•ื•ื™ื™ื˜ื™ืง PAN.

ISE ืฉื˜ื™ืฆื˜ 2 ื˜ื™ื™ืคึผืก ืคื•ืŸ ืœื•ืงืึทืคึผ (ืœื•ืงืึทืคึผ) ื•ื•ืขืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ LDAP ืกืขืจื•ื•ืขืจืก: ื‘ืึทื ื™ืฆืขืจ ืœื•ืงืึทืคึผ ืื•ืŸ MAC ืึทื“ืจืขืก ืœื•ืงืึทืคึผ. ื‘ืึทื ื™ืฆืขืจ ืœื•ืงืึทืคึผ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื–ื•ื›ืŸ ืคึฟืึทืจ ืึท ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ื“ื™ LDAP ื“ืึทื˜ืึทื‘ื™ื™ืก ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ: ื™ื•ื–ืขืจื– ืื•ืŸ ื–ื™ื™ืขืจ ืึทื˜ืจื™ื‘ื™ื•ืฅ, ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก. MAC ืึทื“ืจืขืก ืœื•ืงืึทืคึผ ืื•ื™ืš ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื–ื•ื›ืŸ ื“ื•ืจืš MAC ืึทื“ืจืขืก ืื™ืŸ LDAP ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืžื™ื˜ืœ, ืึท ื’ืจื•ืคึผืข ืคื•ืŸ โ€‹โ€‹ื“ืขื•ื•ื™ืกืขืก ื“ื•ืจืš MAC ืึทื“ืจืขืกืขืก ืื•ืŸ ืื ื“ืขืจืข ืกืคึผืขืฆื™ืคื™ืฉ ืึทื˜ืจื™ื‘ื™ื•ืฅ.

ื•ื•ื™ ืึทืŸ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ื‘ื™ื™ืฉืคึผื™ืœ, ืœืึธื–ืŸ ืื•ื ื“ื– ืœื™ื™ื’ืŸ ืึทืงื˜ื™ื•ื•ืข Directory ืฆื• Cisco ISE ื•ื•ื™ ืึท LDAP ืกืขืจื•ื•ืขืจ.

1) ื’ื™ื™ืŸ ืฆื• ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืงื•ื•ืืœืŸ โ†’ ืœื“ืึทืคึผ โ†’ ืœื™ื™ื’. 

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 4. ืึทื“ื™ื ื’ ืึท ืœื“ืึทืคึผ ืกืขืจื•ื•ืขืจ

2) ืื™ืŸ ื˜ืึทืคืœื™ืข ืึทืœื’ืขืžื™ื™ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ LDAP ืกืขืจื•ื•ืขืจ ื ืึธืžืขืŸ ืื•ืŸ ืกื›ืขืžืข (ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคืึทืœ, ืึทืงื˜ื™ื•ื• Directory). 

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 5. ืึทื“ื™ื ื’ ืึทืŸ ืœื“ืึทืคึผ ืกืขืจื•ื•ืขืจ ืžื™ื˜ ืึทืŸ ืึทืงื˜ื™ื•ื•ืข Directory ืกื˜ืฉืขืžืึท

3) ื•ื•ื™ื™ึทื˜ืขืจ ื’ื™ื™ืŸ ืฆื• ืฉื™ื™ึทื›ืขืก ืงื•ื•ื™ื˜ืœ ืื•ืŸ ืกืขืœืขืงื˜ื™ืจืŸ ื”ืึธืกื˜ื ืึทืžืข / IP ืึทื“ืจืขืก ืกืขืจื•ื•ื™ืจืขืจ ืึทื“, ืคึผืึธืจื˜ (389 - ืœื“ืึทืคึผ, 636 - ืกืกืœ ืœื“ืึทืคึผ), ืคืขืœื“ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– (ืึทื“ืžื™ืŸ ื“ืŸ - ืคื•ืœ ื“ืŸ), ืื ื“ืขืจืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœื™ื ืงืก ื•ื•ื™ ืคืขืœื™ืงื™ื™ึทื˜.

ื˜ืึธืŸ: ื ื™ืฆืŸ ื“ื™ ืึทื“ืžื™ืŸ ืคืขืœื“ ื“ืขื˜ืึทื™ืœืก ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ืคึผืึธื˜ืขื ืฆื™ืขืœ ืคึผืจืึธื‘ืœืขืžืก.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 6 ืึทืจื™ื™ึทืŸ LDAP ืกืขืจื•ื•ื™ืจืขืจ ื“ืึทื˜ืึท

4) ืื™ืŸ ืงื•ื•ื™ื˜ืœ Directory ืืจื’ืื ื™ื–ืืฆื™ืข ืื™ืจ ื–ืึธืœ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื’ืขื’ื ื˜ ื“ื•ืจืš ื“ื™ DN ืคื•ืŸ ื•ื•ื• ืฆื• ืฆื™ืขืŸ ื ื™ืฆืขืจืก ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 7. ื‘ืึทืฉื˜ื™ืžื•ื ื’ ืคื•ืŸ ื“ื™ืจืขืงื˜ืขืจื™ื– ืคื•ืŸ ื•ื•ื• ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ืงืขื ืขืŸ ืฆื™ืขืŸ ื–ื™ืš

5) ื’ื™ื™ืŸ ืฆื• ืคึฟืขื ืฆื˜ืขืจ ื’ืจื•ืคึผืขืก โ†’ ืœื™ื™ื’ โ†’ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื’ืจื•ืคึผืขืก ืคึฟื•ืŸ Directory ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ืฆื™ืขืŸ ื’ืจื•ืคึผืขืก ืคื•ืŸ ื“ื™ LDAP ืกืขืจื•ื•ืขืจ.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 8. ืึทื“ื™ื ื’ ื’ืจื•ืคึผืขืก ืคื•ืŸ ื“ื™ ืœื“ืึทืคึผ ืกืขืจื•ื•ืขืจ

6) ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ื™ื–ืŸ, ื’ื™ื˜ ืฆื•ืจื™ืงืงืจื™ื’ืŸ ื’ืจื•ืคึผืขืก. ืื•ื™ื‘ ื“ื™ ื’ืจื•ืคึผืขืก ื”ืึธื‘ืŸ ืคึผื•ืœื“ ืึทืจื•ื™ืฃ, ื“ื™ ืคึผืจื™ืœื™ืžืึทื ืขืจื™ ืกื˜ืขืคึผืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื’ืขืขื ื“ื™ืงื˜ ื”ืฆืœื—ื”. ืึทื ื“ืขืจืฉ, ืคึผืจื•ื‘ื™ืจืŸ ืืŸ ืื ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ื™ ISE ืžื™ื˜ ื“ื™ LDAP ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ื“ื™ LDAP ืคึผืจืึธื˜ืึธืงืึธืœ.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 9. ืจืฉื™ืžื” ืคื•ืŸ ืคึผื•ืœื“ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก

7) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืึทื˜ืจืึทื‘ื™ื•ืฅ ืื™ืจ ืงืขื ืขืŸ ืึธืคึผื˜ื™ืึธื ืึทืœืœื™ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื•ื•ืึธืก ืึทื˜ืจื™ื‘ื™ื•ืฅ ืคื•ืŸ ื“ื™ LDAP ืกืขืจื•ื•ืขืจ ื–ืึธืœ ื–ื™ื™ืŸ ืคึผื•ืœื“ ืึทืจื•ื™ืฃ ืื•ืŸ ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืกืขื˜ื˜ื™ื ื’ืก ื’ืขื‘ืŸ ืึธืคึผืฆื™ืข ื’ืขื‘ืŸ ืคึผืึทืจืึธืœ ื˜ื•ื™ืฉืŸ, ื•ื•ืึธืก ื•ื•ืขื˜ ืฆื•ื•ื™ื ื’ืขืŸ ื ื™ืฆืขืจืก ืฆื• ื˜ื•ื™ืฉืŸ ื–ื™ื™ืขืจ ืคึผืึทืจืึธืœ ืื•ื™ื‘ ืขืก ืื™ื– ืื•ื™ืกื’ืขื’ืื ื’ืขืŸ ืึธื“ืขืจ ื‘ืึทืฉื˜ืขื˜ื™ืง. ืกื™ื™ึท ื•ื•ื™ ืกื™ื™ึท ื’ื™ื˜ ืคืึธืจืœื™ื™ื’ืŸ ืฆื• ื’ื™ื™ืŸ ื•ื•ื™ื™ื˜ืขืจ.

8) LDAP ืกืขืจื•ื•ืขืจ ืื™ื– ืืจื•ื™ืก ืื™ืŸ ื“ื™ ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืงื•ื•ื™ื˜ืœ ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืคืึธืจืขื ืึทืงืกืขืก ืคึผืึทืœืึทืกื™ื– ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 10. ืจืฉื™ืžื” ืคื•ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืœื“ืึทืคึผ ืกืขืจื•ื•ืขืจืก

4. ื™ื ื˜ืขื’ืจืึทื˜ื™ืึธืŸ ืžื™ื˜ ืึทืงื˜ื™ื•ื•ืข Directory

1) ื“ื•ืจืš ืึทื“ื™ื ื’ ื“ื™ Microsoft Active Directory ืกืขืจื•ื•ืขืจ ื•ื•ื™ ืึท LDAP ืกืขืจื•ื•ืขืจ, ืžื™ืจ ื”ืึธื‘ืŸ ื ื™ืฆืขืจืก, ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก, ืึธื‘ืขืจ ืงื™ื™ืŸ ืœืึธื’ืก. ื“ืขืจื ืึธืš, ืื™ืš ืคืึธืจืฉืœืึธื’ืŸ ืฆื• ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ืคื•ืœ-ืคืœืขื“ื–ืฉื“ ืึทื“ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ Cisco ISE. ื’ื™ื™ืŸ ืฆื• ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืงื•ื•ืืœืŸ โ†’ ืึทืงื˜ื™ื•ื• Directory โ†’ ืœื™ื™ื’. 

ื‘ืึทืžืขืจืงื•ื ื’: ืคึฟืึทืจ ืžืฆืœื™ื— ื™ื ื˜ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ AD, ISE ืžื•ื–ืŸ ื–ื™ื™ืŸ ืื™ืŸ ืึท ืคืขืœื“ ืื•ืŸ ื”ืึธื‘ืŸ ืคื•ืœ ืงืึทื ืขืงื˜ื™ื•ื•ื™ื˜ื™ ืžื™ื˜ DNS, NTP ืื•ืŸ AD ืกืขืจื•ื•ืขืจืก, ืึทื ื“ืขืจืฉ ื’ืึธืจื ื™ืฉื˜ ื•ื•ืขื˜ ืงื•ืžืขืŸ ืคื•ืŸ ืขืก.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 11. ืึทื“ื™ื ื’ ืึทืŸ ืึทืงื˜ื™ื•ื•ืข Directory ืกืขืจื•ื•ืขืจ

2) ืื™ืŸ ื“ื™ ืคึฟืขื ืฆื˜ืขืจ ืึทื– ืื•ื™ืก, ืึทืจื™ื™ึทืŸ ื“ื™ ืคืขืœื“ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื“ืขื˜ืึทื™ืœืก ืื•ืŸ ื˜ืฉืขืง ื“ื™ ืงืขืกื˜ืœ ืงืจืึธื ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ืื™ืŸ ื“ืขืจืฆื•, ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึทืŸ ืึธื• (ืึธืจื’ืึทื ืึทื–ื™ื™ืฉืึทื ืึทืœ ื™ื•ื ื™ื˜) ืื•ื™ื‘ ื“ื™ ISE ืื™ื– ืœื™ื’ืŸ ืื™ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืึธื•. ื“ืขืจื ืึธืš ืื™ืจ ื•ื•ืขื˜ ื”ืึธื‘ืŸ ืฆื• ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ Cisco ISE ื ืึธื•ื“ื– ื•ื•ืึธืก ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืคืขืœื“.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 12. ืึทืจื™ื™ึทืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–

3) ืื™ื™ื“ืขืจ ืึทื“ื™ื ื’ ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจื–, ืžืึทื›ืŸ ื–ื™ื›ืขืจ ืึทื– ืื•ื™ืฃ PSN ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืกื™ืกื˜ืขื โ†’ ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืึธืคึผืฆื™ืข ืขื ื™ื™ื‘ืึทืœื“ ืคึผืึทืกื™ื•ื• ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืกืขืจื•ื•ื™ืก. ืคึผืึทืกื™ื•ื• ืฉื™ื™ึทืŸ - ืึทืŸ ืึธืคึผืฆื™ืข ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืื™ื‘ืขืจื–ืขืฆืŸ ื‘ืึทื ื™ืฆืขืจ ืฆื• IP ืื•ืŸ ื•ื•ื™ืฆืข ื•ื•ืขืจืกืึท. PassiveID ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹AD ื“ื•ืจืš WMI, ืกืคึผืขืฆื™ืขืœ ืึทื“ ืึทื’ืขื ืฅ ืึธื“ืขืจ SPAN ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ื™ ื‘ืึทืฉื˜ื™ืžืขืŸ (ื ื™ืฉื˜ ื“ืขืจ ื‘ืขืกื˜ืขืจ ืึธืคึผืฆื™ืข).

ื‘ืึทืžืขืจืงื•ื ื’: ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืกื˜ืึทื˜ื•ืก ืคื•ืŸ ื“ื™ ืคึผืึทืกื™ื•ื• ืฉื™ื™ึทืŸ, ืึทืจื™ื™ึทืŸ ื“ื™ ISE ืงืึทื ืกืึธื•ืœ ื•ื•ื™ื™ึทื–ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืกื˜ืึทื˜ื•ืก ืื™ื– | ืึทืจื™ื™ึทื ื ืขืžืขืŸ PassiveID.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 13. ืขื ื™ื™ื‘ืึทืœื™ื ื’ ื“ื™ ืคึผืึทืกื™ื•ื•ื™ื“ ืึธืคึผืฆื™ืข

4) ื’ื™ื™ืŸ ืฆื• ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืงื•ื•ืืœืŸ โ†’ ืึทืงื˜ื™ื•ื• Directory โ†’ PassiveID ืื•ืŸ ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื ืึธืคึผืฆื™ืข ืœื™ื™ื’ ื“ืงืก. ื•ื•ื™ื™ึทื˜ืขืจ, ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจื– ืžื™ื˜ ื˜ืฉืขืงืงื‘ืึธืงืกืขืก ืื•ืŸ ื’ื™ื˜ ื’ื•ื˜.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 14. ืึทื“ื™ื ื’ ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจื–

5) ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ืงืก ืื•ืŸ ื’ื™ื˜ ื“ื™ ืงื ืขืคึผืœ ืจืขื“ืึทื’ื™ืจืŸ. ืึธื ื•ื•ื™ื™ึทื–ืŸ ืคืงื“ืŸ ื“ื™ื™ืŸ ื“ืง, ืคืขืœื“ ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืึทืจืึธืœ, ืื•ืŸ ืึท ืœื™ื ืง ืึธืคึผืฆื™ืข ื•ื•ืžื™ ืึธื“ืขืจ ืึทื’ืขื ื˜. ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ WMI ืื•ืŸ ื’ื™ื˜ ื’ื•ื˜.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 15 ืึทืจื™ื™ึทืŸ ืคืขืœื“ ืงืึธื ื˜ืจืึธืœืœืขืจ ื“ืขื˜ืึทื™ืœืก

6) ืื•ื™ื‘ WMI ืื™ื– ื ื™ืฉื˜ ื“ืขืจ ื‘ื™ืœื›ืขืจ ื•ื•ืขื’ ืฆื• ื™ื‘ืขืจื’ืขื‘ืŸ ืžื™ื˜ Active Directory, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ISE ืื’ืขื ื˜ืŸ. ื“ืขืจ ืึทื’ืขื ื˜ ืื•ืคึฟืŸ ืื™ื– ืึทื– ืื™ืจ ืงืขื ืขืŸ ื™ื ืกื˜ืึทืœื™ืจืŸ ืกืคึผืขืฆื™ืขืœ ืื’ืขื ื˜ืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจืก ื•ื•ืึธืก ื•ื•ืขื˜ ืึทืจื•ื™ืกืœืึธื–ืŸ ืœืึธื’ื™ืŸ ื’ืขืฉืขืขื ื™ืฉืŸ. ืขืก ื–ืขื ืขืŸ 2 ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืึธืคึผืฆื™ืขืก: ืึธื˜ืึทืžืึทื˜ื™ืง ืื•ืŸ ืžืึทื ื•ืึทืœ. ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ืึทื’ืขื ื˜ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืงื•ื•ื™ื˜ืœ ืคึผืึทืกื™ื•ื• ืฉื™ื™ึทืŸ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื ื•ืžืขืจ ืœื™ื™ื’ ืึทื’ืขื ื˜ โ†’ ืฆืขื•ื•ื™ืงืœืขืŸ ื ื™ื• ืึทื’ืขื ื˜ (ื“ืง ืžื•ื–ืŸ ื”ืึธื‘ืŸ ืื™ื ื˜ืขืจื ืขื˜ ืึทืงืกืขืก). ื“ืขืจื ืึธืš ืคึผืœืึธืžื‘ื™ืจืŸ ื“ื™ ืคืืจืœืื ื’ื˜ ืคืขืœื“ืขืจ (ืึทื’ืขื ื˜ ื ืึธืžืขืŸ, ืกืขืจื•ื•ืขืจ FQDN, ืคืขืœื“ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืœืึธื’ื™ืŸ / ืคึผืึทืจืึธืœ) ืื•ืŸ ื’ื™ื˜ ื’ื•ื˜.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 16. ืึธื˜ืึทืžืึทื˜ื™ืง ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ื™ืกืข ืึทื’ืขื ื˜

7) ืฆื• ืžืึทื ื™ื•ืึทืœื™ ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ Cisco ISE ืึทื’ืขื ื˜, ืกืขืœืขืงื˜ื™ืจืŸ ื“ืขื ื ื•ืžืขืจ ืจืขื’ื™ืกื˜ืจื™ืจืŸ ืขืงืกื™ืกื˜ื™ื ื’ ืึทื’ืขื ื˜. ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ืื™ืจ ืงืขื ืขืŸ ืืจืืคืงืืคื™ืข ื“ื™ ืึทื’ืขื ื˜ ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทืจื‘ืขื˜ ืกืขื ื˜ืขืจืก โ†’ PassiveID โ†’ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– โ†’ ืึทื’ืขื ืฅ โ†’ ืืจืืคืงืืคื™ืข ืึทื’ืขื ื˜.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 17. ื“ืึทื•ื ืœืึธื•ื“ื™ื ื’ ื“ื™ ื™ืกืข ืึทื’ืขื ื˜

ื•ื•ื™ื›ื˜ื™ืง: PassiveID ืงืขืŸ ื ื™ืฉื˜ ืœื™ื™ืขื ืขืŸ ื’ืขืฉืขืขื ื™ืฉืŸ ื’ื™ื™ ืืจื•ื™ืก! ื“ืขืจ ืคึผืึทืจืึทืžืขื˜ืขืจ ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ื“ื™ ื˜ื™ื™ืžืึทื•ื˜ ืื™ื– ื’ืขืจื•ืคืŸ ื‘ืึทื ื™ืฆืขืจ ืกืขืกื™ืข ื™ื™ื“ื–ืฉื™ื ื’ ืฆื™ื™ึทื˜ ืื•ืŸ ื™ืงื•ื•ืึทืœื– 24 ืฉืขื” ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜. ื“ืขืจื™ื‘ืขืจ, ืื™ืจ ื–ืึธืœ ืึธื“ืขืจ ืœืึธื’ื“ ื–ื™ืš ืื™ืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ ื“ื™ ืึทืจื‘ืขื˜ ื˜ืึธื’, ืึธื“ืขืจ ืฉืจื™ื™ึทื‘ืŸ ืึท ืžื™ืŸ ืคื•ืŸ ืฉืจื™ืคื˜ ื•ื•ืึธืก ื•ื•ืขื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืœืึธื’ื“ ืึทืœืข ืœืึธื’ื“ ืื™ืŸ ื ื™ืฆืขืจืก. 

ืคึฟืึทืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื’ื™ื™ ืืจื•ื™ืก "ืขื ื“ืคึผื•ื™ื ื˜ ืคึผืจืึธื‘ืขืก" ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ - ื•ื•ืึธืงื–ืึทืœ ืคึผืจืึธื‘ืขืก. ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ืขื ื“ืคึผื•ื™ื ื˜ ืคึผืจืึธื‘ืขืก ืื™ืŸ Cisco ISE: RADIUS, SNMP Trap, SNMP Query, DHCP, DNS, HTTP, Netflow, NMAP Scan. ืจืึทื“ื™ื•ืก ื–ืึธื ื“ ื ื™ืฆืŸ ืงืึธืึท (ื˜ื•ื™ืฉืŸ ืึทื•ื˜ื”ืึธืจื™ื–ืึทื˜ื™ืึธืŸ) ืคึผืึทืงืึทื“ื–ืฉืึทื– ื’ืขื‘ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื˜ืฉืึทื ื’ื™ื ื’ ื‘ืึทื ื™ืฆืขืจ ืจืขื›ื˜ (ื“ืึธืก ืจื™ืงื•ื•ื™ื™ืขืจื– ืึทืŸ ืขืžื‘ืขื“ื™ื“ ืงืกื ื•ืžืงืกืงืก), ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ืื•ื™ืฃ ืึทืงืกืขืก ืกื•ื•ื™ื˜ืฉื™ื– SNMP, ื•ื•ืขื˜ ื’ืขื‘ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืงืึธื ื ืขืงื˜ืขื“ ืื•ืŸ ื“ื™ืกืงืึทื ืขืงื˜ื™ื“ ื“ืขื•ื•ื™ืกืขืก.

ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ื™ื™ืฉืคึผื™ืœ ืื™ื– ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืคึฟืึทืจ ืึท Cisco ISE + AD ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืŸ 802.1X ืื•ืŸ RADIUS: ืึท ื‘ืึทื ื™ืฆืขืจ ืื™ื– ืœืึธื’ื“ ืื™ืŸ ืื•ื™ืฃ ืึท Windows ืžืึทืฉื™ืŸ, ืึธืŸ ืœืึธื’ืึธืคืฃ, ืงืœืึธืฅ ืื™ืŸ ืคึฟื•ืŸ ืืŸ ืื ื“ืขืจ ืคึผื™ืกื™ ื“ื•ืจืš WiFi. ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ ืกืขืกื™ืข ืื•ื™ืฃ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคึผื™ืกื™ ื•ื•ืขื˜ ื ืึธืš ื–ื™ื™ืŸ ืึทืงื˜ื™ื•ื• ื‘ื™ื– ืึท ื˜ื™ื™ืžืึทื•ื˜ ืึทืงืขืจื– ืึธื“ืขืจ ืึท ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืœืึธื’ืึธืคืฃ ืึทืงืขืจื–. ืื•ื™ื‘ ื“ื™ ื“ืขื•ื•ื™ืกืขืก ื”ืึธื‘ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืจืขื›ื˜, ื“ื™ ืœืขืฆื˜ืข ืœืึธื’ื“ ืื™ืŸ ืžื™ื˜ืœ ื•ื•ืขื˜ ืฆื•ืœื™ื™ื’ืŸ ื–ื™ื™ืŸ ืจืขื›ื˜.

8) ืึธืคึผื˜ื™ืึธื ืึทืœ ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข โ†’ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ โ†’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืงื•ื•ืืœืŸ โ†’ ืึทืงื˜ื™ื•ื• Directory โ†’ ื’ืจื•ืคึผืขืก โ†’ ืœื™ื™ื’ โ†’ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื’ืจื•ืคึผืขืก ืคึฟื•ืŸ Directory ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื’ืจื•ืคึผืขืก ืคื•ืŸ AD ื•ื•ืึธืก ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืฆื™ืขืŸ ืึทืจื•ื™ืฃ ืื•ื™ืฃ ISE (ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคืึทืœ, ื“ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขื˜ืืŸ ืื™ืŸ ืฉืจื™ื˜ 3 "ืึทื“ื™ื ื’ ืึท LDAP ืกืขืจื•ื•ืขืจ"). ืงืœื™ื™ึทื‘ืŸ ืึทืŸ ืึธืคึผืฆื™ืข ืฆื•ืจื™ืงืงืจื™ื’ืŸ ื’ืจื•ืคึผืขืก โ†’ ื’ื•ื˜

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 18 ื). ืคึผื•ืœื™ื ื’ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืขืก ืคื•ืŸ ืึทืงื˜ื™ื•ื• Directory

9) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืึทืจื‘ืขื˜ ืกืขื ื˜ืขืจืก โ†’ PassiveID โ†’ ืื™ื‘ืขืจื‘ืœื™ืง โ†’ ื“ืึทืฉื‘ืึธืจื“ ืื™ืจ ืงืขื ืขืŸ ืึธื‘ืกืขืจื•ื•ื™ืจืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืึทืงื˜ื™ื•ื• ืกืขืฉืึทื ื–, ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื“ืึทื˜ืŸ ืงื•ื•ืืœืŸ, ืื’ืขื ื˜ืŸ ืื•ืŸ ืžืขืจ.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 19. ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื“ื™ ื˜ืขื˜ื™ืงื™ื™ื˜ ืคื•ืŸ ืคืขืœื“ ื ื™ืฆืขืจืก

10) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืœืขื‘ืŸ ืกืขืกืฉืึทื ื– ืงืจืึทื ื˜ ืกืขืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขื•ื•ื™ื–ืŸ. ื™ื ื˜ืขื’ืจืึทื˜ื™ืึธืŸ ืžื™ื˜ ืึทื“ ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“.

Cisco ISE: ืงืจื™ื™ื™ื˜ื™ื ื’ ื ื™ืฆืขืจืก, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ AD. ื˜ื™ื™ืœ 2ืคื™ื’ื•ืจืข 20. ืึทืงื˜ื™ื•ื• ืกืขืฉืึทื ื– ืคื•ืŸ ืคืขืœื“ ื ื™ืฆืขืจืก

5. ืžืกืงื ื

ื“ืขืจ ืึทืจื˜ื™ืงืœ ืงืึทื•ื•ืขืจื“ ื“ื™ ื˜ืขืžืขืก ืคื•ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ื”ื™ื’ืข ื™ื•ื–ืขืจื– ืื™ืŸ Cisco ISE, ืึทื“ื™ื ื’ LDAP ืกืขืจื•ื•ืขืจืก ืื•ืŸ ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ Microsoft Active Directory. ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืจื˜ื™ืงืœ ื•ื•ืขื˜ ื”ื•ื™ื›ืคึผื•ื ืงื˜ ื’ืึทืกื˜ ืึทืงืกืขืก ืื™ืŸ ื“ื™ ืคืึธืจืขื ืคื•ืŸ ืึท ื™ื‘ืขืจื™ืง ืคื™ืจืขืจ.

ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืคึฟืจืื’ืŸ ื•ื•ืขื’ืŸ ื“ืขื ื˜ืขืžืข ืึธื“ืขืจ ืื™ืจ ื“ืึทืจืคึฟืŸ ื”ื™ืœืฃ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ืขื ืคึผืจืึธื“ื•ืงื˜, ื‘ื™ื˜ืข ืงืึธื ื˜ืึทืงื˜ ืจื•ื ื’.

ื‘ืœื™ื™ื‘ืŸ ื˜ื•ื ื“ ืคึฟืึทืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื™ืŸ ืื•ื ื“ื–ืขืจ ื˜ืฉืึทื ืึทืœื– (ื˜ืขืœืขื’ืจืึทื, facebook, VK, TS ืœื™ื™ื–ื•ื ื’ ื‘ืœืึธื’, Yandex Zen).

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’