Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1

1. ื”ืงื“ืžื”

ื™ืขื“ืขืจ ืคื™ืจืžืข, ืืคื™ืœื• ื“ืขืจ ืงืœืขื ืกื˜ืขืจ, ื”ืื˜ ืึท ื ื•ื™ื˜ ืคึฟืึทืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืื•ืŸ ื‘ืึทื ื™ืฆืขืจ ืึทืงืึทื•ื ื˜ื™ื ื’ (ืึทืึทืึท ืžืฉืคึผื—ื” ืคื•ืŸ ืคึผืจืึธื˜ืึธืงืึธืœืก). ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ ื‘ื™ื ืข, ืึทืึทืึท ืื™ื– ื’ืึทื ืฅ ื’ืขื–ื•ื ื˜ ื™ืžืคึผืœืึทืžืขื ืึทื“ ืžื™ื˜ ืคึผืจืึธื˜ืึธืงืึธืœืก ืึทื–ืึท ื•ื•ื™ RADIUS, TACACS + ืื•ืŸ ื“ื™ืึทืžืขื˜ืขืจ. ืึธื‘ืขืจ, ื•ื•ื™ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื ื™ืฆืขืจืก ืื•ืŸ ื“ื™ ืคื™ืจืžืข ื•ื•ืึทืงืกืŸ, ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื˜ืึทืกืงืก ืื•ื™ืš ื•ื•ืืงืกื˜: ืžืึทืงืกื™ืžื•ื ื•ื•ื™ื–ืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ืžื—ื ื•ืช ืื•ืŸ BYOD ื“ืขื•ื•ื™ืกืขืก, ืžื•ืœื˜ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืžื•ืœื˜ื™-ืžื“ืจื’ื” ืึทืงืกืขืก ืคึผืึธืœื™ื˜ื™ืง ืื•ืŸ ืคื™ืœ ืžืขืจ.

ืคึฟืึทืจ ืึทื–ืึท ื˜ืึทืกืงืก, ื“ื™ NAC (ื ืขื˜ื•ื•ืึธืจืง ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ) ืงืœืึทืก ืคื•ืŸ ืกืึทืœื•ืฉืึทื ื– ืื™ื– ื’ืื ืฅ - ื ืขืฅ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ. ืื™ืŸ ืึท ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ืึทืจื˜ื™ืงืœืขืŸ ื’ืขื•ื•ื™ื“ืžืขื˜ ืฆื• Cisco ISE (Identity Services Engine) - NAC ืœื™ื™ื–ื•ื ื’ ืคึฟืึทืจ ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ืงืึธื ื˜ืขืงืกื˜-ืึทื•ื•ืขืจ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ ืฆื• ื ื™ืฆืขืจืก ืื•ื™ืฃ ื“ื™ ื™ื ืขืจืœืขืš ื ืขืฅ, ืžื™ืจ ื•ื•ืขืœืŸ ื ืขืžืขืŸ ืึท ื“ื™ื˜ื™ื™ืœื“ ืงื•ืง ืื™ืŸ ื“ื™ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ, ืคึผืจืึทื•ื•ื™ื–ืฉืึทื ื–, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื•ืŸ ืœื™ื™ืกืึทื ืกื™ื ื’ ืคื•ืŸ ื“ื™ ืœื™ื™ื–ื•ื ื’.

ืœืึธื–ืŸ ืžื™ืจ ื‘ืขืงื™ืฆืขืจ ื“ืขืจืžืึธื ืขืŸ ืื™ืจ ืึทื– Cisco ISE ืึทืœืึทื•ื– ืื™ืจ ืฆื•:

  • ื’ืขืฉื•ื•ื™ื ื“ ืื•ืŸ ืœื™ื™ื›ื˜ ืฉืึทืคึฟืŸ ื’ืึทืกื˜ ืึทืงืกืขืก ืื•ื™ืฃ ืึท ื“ืขื“ืึทืงื™ื™ื˜ืึทื“ WLAN;

  • ื“ืขื˜ืขืงื˜ BYOD ื“ืขื•ื•ื™ืกืขืก (ืœืžืฉืœ, ืขืžืคึผืœื•ื™ื™ื– ื”ื™ื™ื ืคึผื™ืกื™ ื•ื•ืึธืก ื–ื™ื™ ื’ืขื‘ืจืื›ื˜ ืฆื• ืึทืจื‘ืขื˜ืŸ);

  • ืกืขื ื˜ืจืึทืœื™ื™ื– ืื•ืŸ ื“ื•ืจื›ืคื™ืจืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึทืœืึทืกื™ื– ืฆื•ื•ื™ืฉืŸ ืคืขืœื“ ืื•ืŸ ื ื™ื˜-ืคืขืœื“ ื ื™ืฆืขืจืก ื ื™ืฆืŸ SGT ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืจื•ืคึผืข ืœืึทื‘ืขืœืก TrustSec);

  • ื˜ืฉืขืง ืงืึธืžืคึผื™ื•ื˜ืขืจืก ืคึฟืึทืจ ื–ื™ื›ืขืจ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ืŸ ื”ืขืกืงืขื ืžื™ื˜ ืกื˜ืึทื ื“ืึทืจื“ืก (ืคึผืึธืกื˜ื•ืจื™ื ื’);

  • ืงืœืึทืกื™ืคื™ืฆื™ืจืŸ ืื•ืŸ ืคึผืจืึธืคื™ืœ ืขื ื“ืคึผื•ื™ื ื˜ ืื•ืŸ ื ืขืฅ ื“ืขื•ื•ื™ืกืขืก;

  • ืฆื•ืฉื˜ืขืœืŸ ื•ื•ื™ื–ืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ืขื ื“ืคึผื•ื™ื ื˜;

  • ืฉื™ืงืŸ ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’ืก ืคื•ืŸ ืœืึธื’ืึธืŸ / ืœืึธื’ืึธืคืฃ ืคื•ืŸ ื ื™ืฆืขืจืก, ื–ื™ื™ืขืจ ืึทืงืึทื•ื ืฅ (ืื™ื“ืขื ื˜ื™ื˜ืขื˜) ืฆื• NGFW ืฆื• ืคืึธืจืขื ืึท ื‘ืึทื ื™ืฆืขืจ-ื‘ืื–ื™ืจื˜ ืคึผืึธืœื™ื˜ื™ืง;

  • ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื“ ื’ืขื‘ื•ื™ืจืŸ ืžื™ื˜ Cisco StealthWatch ืื•ืŸ ืงืึทืจืึทื ื˜ื™ืŸ ืกืึทืกืคึผื™ืฉืึทืก ืžื—ื ื•ืช ื™ื ื•ื•ืึทืœื•ื•ื“ ืื™ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื™ื ืกืึทื“ืึทื ืฅ (ืžืขืจ);

  • ืื•ืŸ ืื ื“ืขืจืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื ืึธืจืžืึทืœ ืคึฟืึทืจ ืึทืึทืึท ืกืขืจื•ื•ืขืจืก.

ืงืึธืœืขื’ืขืก ืื™ืŸ ื“ื™ ืื™ื ื“ื•ืกื˜ืจื™ืข ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื’ืขืฉืจื™ื‘ืŸ ื•ื•ืขื’ืŸ Cisco ISE, ืึทื–ื•ื™ ืื™ืš ืจืขืงืึธืžืขื ื“ื™ืจืŸ ืื™ืจ ืฆื• ืœื™ื™ืขื ืขืŸ: Cisco ISE ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื™ืจ, ื•ื•ื™ ืฆื• ืฆื•ื’ืจื™ื™ื˜ืŸ ืคึฟืึทืจ Cisco ISE ื™ืžืคึผืœืขืžืขื ื˜ืึทื˜ื™ืึธืŸ.

2. ืึทืจื˜ืฉื™ื˜ืขืงื˜ื•ืจืข

ื“ื™ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ื‘ืึทื“ื™ื ื•ื ื’ืก ืขื ื’ื™ื ืข ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ ื”ืื˜ 4 ืขื ื˜ื™ื˜ื™ื– (ื ืึธื“ืขืก): ืึท ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ื ืึธื“ืข (ืคึผืึธืœื™ื˜ื™ืง ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ื™ืึธืŸ ื ืึธื“ืข), ืึท ืคึผืึธืœื™ื˜ื™ืง ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ื ืึธื“ืข (ืคึผืึธืœื™ื˜ื™ืง ืกืขืจื•ื•ื™ืก ื ืึธื“ืข), ืึท ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื ืึธื“ืข (ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื ืึธื“ืข) ืื•ืŸ ืึท ืคึผืงืกื’ืจื™ื“ ื ืึธื“ืข (ืคึผืงืกื’ืจื™ื“ ื ืึธื“ืข). Cisco ISE ืงืขื ืขืŸ ื–ื™ื™ืŸ ืื™ืŸ ืึท ืกื˜ืึทื ื“ืึทืœืึธื ืข ืึธื“ืขืจ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ืื™ืŸ ื“ื™ ืกื˜ืึทื ื“ืึทืœืึธื ืข ื•ื•ืขืจืกื™ืข, ืึทืœืข ืขื ื˜ื™ื˜ื™ื– ื–ืขื ืขืŸ ืœื™ื’ืŸ ืื•ื™ืฃ ืื™ื™ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ืึธื“ืขืจ ื’ืฉืžื™ื•ืช ืกืขืจื•ื•ืขืจ (ืกืขืงื•ืจืข ื ืขื˜ื•ื•ืึธืจืง ืกืขืจื•ื•ืขืจืก - SNS), ื‘ืฉืขืช ืื™ืŸ ื“ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ื˜ื™ื“ ื•ื•ืขืจืกื™ืข, ื“ื™ ื ืึธื•ื“ื– ื–ืขื ืขืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื™ืฃ ืคืึทืจืฉื™ื“ืขื ืข ื“ืขื•ื•ื™ืกืขืก.

ืคึผืึธืœื™ื˜ื™ืง ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ื™ืึธืŸ ื ืึธื“ืข (PAN) ืื™ื– ืึท ืคืืจืœืื ื’ื˜ ื ืึธื“ืข ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึทืœืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ื™ื•ื•ืข ืึทืคึผืขืจื™ื™ืฉืึทื ื– ืื•ื™ืฃ Cisco ISE. ืขืก ื›ืึทื ื“ืึทืœื– ืึทืœืข ืกื™ืกื˜ืขื ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ืฉื™ื™ึทื›ื•ืช ืฆื• ืึทืึทืึท. ืื™ืŸ ืึท ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ (ื ืึธื“ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ื•ื•ื™ ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ), ืื™ืจ ืงืขื ืขืŸ ื”ืึธื‘ืŸ ืึท ืžืึทืงืกื™ืžื•ื ืคื•ืŸ ืฆื•ื•ื™ื™ ืคึผืึทื ืก ืคึฟืึทืจ ืฉื•ืœื“ ื˜ืึธืœืขืจืึทื ืฅ - ืึทืงื˜ื™ื•ื• / ืกื˜ืึทื ื“ื‘ื™ื™ ืžืึธื“ืข.

ืคึผืึธืœื™ื˜ื™ืง ืกืขืจื•ื•ื™ืก ื ืึธื“ืข (PSN) ืื™ื– ืึท ืžืึทื ื“ืึทื˜ืึธืจื™ ื ืึธื“ืข ื•ื•ืึธืก ื’ื™ื˜ ื ืขืฅ ืึทืงืกืขืก, ืฉื˜ืึทื˜, ื’ืึทืกื˜ ืึทืงืกืขืก, ืงืœื™ืขื ื˜ ืกืขืจื•ื•ื™ืก ืคึผืจืึทื•ื•ื™ื–ืฉืึทื ื– ืื•ืŸ ืคึผืจืึธืคื™ืœื™ื ื’. PSN ื™ื•ื•ืึทืœื™ื•ื™ื™ืฅ ื“ื™ ืคึผืึธืœื™ื˜ื™ืง ืื•ืŸ ืึทืคึผืœื™ื™ื– ืขืก. ื˜ื™ืคึผื™ืงืึทืœืœื™, ืงื™ื™ืคืœ PSNs ื–ืขื ืขืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืกืคึผืขืฆื™ืขืœ ืื™ืŸ ืึท ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืคึฟืึทืจ ืžืขืจ ื™ื‘ืขืจื™ืง ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืึธืคึผืขืจืึทืฆื™ืข. ืคื•ืŸ ืงื•ืจืก, ื–ื™ื™ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ื ืึธื•ื“ื– ืื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืกืขื’ืžืึทื ืฅ ืึทื–ื•ื™ ื ื™ืฉื˜ ืฆื• ืคืึทืจืœื™ืจืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืื•ืŸ ืึธื˜ืขืจื™ื™ื–ื“ ืึทืงืกืขืก ืคึฟืึทืจ ืึท ืจื’ืข.

ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื ืึธื“ืข (MnT) ืื™ื– ืึท ืžืึทื ื“ืึทื˜ืึธืจื™ ื ืึธื“ืข ื•ื•ืึธืก ืกื˜ืึธืจื– ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’ืก, ืœืึธื’ืก ืคื•ืŸ ืื ื“ืขืจืข ื ืึธื•ื“ื– ืื•ืŸ ืคึผืึทืœืึทืกื™ื– ืื•ื™ืฃ ื“ื™ ื ืขืฅ. ื“ื™ MnT ื ืึธื“ืข ื’ื™ื˜ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืื•ืŸ ื˜ืจืึธื•ื‘ืœืขืฉืึธืึธื˜ื™ื ื’, ืงืึทืœืขืงืฅ ืื•ืŸ ืงืึธืจืึทืœื™ื™ืฅ ืคืึทืจืฉื™ื“ืŸ ื“ืึทื˜ืŸ, ืื•ืŸ ืื•ื™ืš ื’ื™ื˜ ืžื™ื ื™ื ื’ืคืึทืœ ืจื™ืคึผืึธืจืฅ. Cisco ISE ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื”ืึธื‘ืŸ ืึท ืžืึทืงืกื™ืžื•ื ืคื•ืŸ ืฆื•ื•ื™ื™ MnT ื ืึธื•ื“ื–, ื“ืขืจืžื™ื˜ ืงืจื™ื™ื™ื˜ื™ื ื’ ืฉื•ืœื“ ื˜ืึธืœืขืจืึทื ืฅ - ืึทืงื˜ื™ื•ื• / ืกื˜ืึทื ื“ื‘ื™ื™ ืžืึธื“ืข. ืึธื‘ืขืจ, ืœืึธื’ืก ื–ืขื ืขืŸ ื’ืขื–ืืžืœื˜ ื“ื•ืจืš ื‘ื™ื™ื“ืข ื ืึธื•ื“ื–, ื‘ื™ื™ื“ืข ืึทืงื˜ื™ื•ื• ืื•ืŸ ืคึผืึทืกื™ื•ื•.

PxGrid Node (PXG) ืื™ื– ืึท ื ืึธื“ืข ื•ื•ืึธืก ื ื™ืฆื˜ ื“ื™ PxGrid ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ืึทืœืึทื•ื– ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ ืื ื“ืขืจืข ื“ืขื•ื•ื™ืกืขืก ื•ื•ืึธืก ืฉื˜ื™ืฆืŸ PxGrid.

PxGrid  - ืึท ืคึผืจืึธื˜ืึธืงืึธืœ ื•ื•ืึธืก ื™ื ืฉื•ืจื– ื“ื™ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืคื•ืŸ IT ืื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ ืคึผืจืึธื“ื•ืงื˜ืŸ ืคื•ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขื ื“ืึธืจืก: ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ, ื™ื ื˜ืจื•ื–ืฉืึทืŸ ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืŸ ืคืึทืจื”ื™ื˜ื•ื ื’ ืกื™ืกื˜ืขืžืขืŸ, ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึธืœื™ื˜ื™ืง ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืคึผืœืึทื˜ืคืึธืจืžืก ืื•ืŸ ืคื™ืœืข ืื ื“ืขืจืข ืกืึทืœื•ืฉืึทื ื–. Cisco PxGrid ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื˜ื™ื™ืœืŸ ืงืึธื ื˜ืขืงืกื˜ ืื™ืŸ ืึท ื•ื ื™ื“ื™ืจืขืงื˜ื™ืึธื ืึทืœ ืึธื“ืขืจ ื‘ื™ื™ื“ื™ืจืขืงื˜ื™ืึธื ืึทืœ ืฉื˜ื™ื™ื’ืขืจ ืžื™ื˜ ืคื™ืœืข ืคึผืœืึทื˜ืคืึธืจืžืก ืึธืŸ ื“ื™ ื ื•ื™ื˜ ืคึฟืึทืจ ืึทืคึผื™ืก, ืื•ืŸ ื“ืขืจืžื™ื˜ ืขื ื™ื™ื‘ืึทืœื™ื ื’ ื“ื™ ื˜ืขื›ื ืึธืœืึธื’ื™ืข TrustSec (SGT ื˜ืึทื’ืก), ื˜ื•ื™ืฉืŸ ืื•ืŸ ืฆื•ืœื™ื™ื’ืŸ ANC (ืึทื“ืึทืคึผื˜ื™ื•ื•ืข ื ืขื˜ื•ื•ืึธืจืง ืงืึธื ื˜ืจืึธืœ) ืคึผืึธืœื™ื˜ื™ืง, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื•ืจื›ืคื™ืจืŸ ืคึผืจืึธืคื™ืœื™ื ื’ - ื“ื™ื˜ืขืจืžืึทื ื™ื ื’ ื“ื™ ืžื™ื˜ืœ ืžืึธื“ืขืœ, ืึทืก, ืึธืจื˜ ืื•ืŸ ืžืขืจ.

ืื™ืŸ ืึท ื”ื•ื™ืš ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, PxGrid ื ืึธื•ื“ื– ืจืขืคึผืœืึทืงื™ื™ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ ื ืึธื•ื“ื– ืื™ื‘ืขืจ ืึท PAN. ืื•ื™ื‘ ื“ื™ PAN ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜, ื“ื™ PxGrid ื ืึธื“ืข ืกื˜ืึทืคึผืก ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื ื’, ืึธื˜ืขืจื™ื™ื–ื™ื ื’ ืื•ืŸ ืึทืงืึทื•ื ื˜ื™ื ื’ ืคึฟืึทืจ ื™ื•ื–ืขืจื–. 

ื•ื ื˜ืขืจ ืื™ื– ืึท ืกื›ืขืžืึทื˜ื™ืฉ ืคืึทืจื˜ืจืขื˜ื•ื ื’ ืคื•ืŸ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืคืึทืจืฉื™ื“ืขื ืข Cisco ISE ืขื ื˜ื™ื˜ื™ื– ืื™ืŸ ืึท ืคึฟื™ืจืžืข ื ืขืฅ.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 1. ืกื™ืกืงืึธ ื™ืกืข ืึทืจื˜ืฉื™ื˜ืขืงื˜ื•ืจืข

3. ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ

Cisco ISE ืงืขื ืขืŸ ื–ื™ื™ืŸ ื™ืžืคึผืœืึทืžืขื ืึทื“, ื•ื•ื™ ืจื•ื‘ึฟ ืžืึธื“ืขืจืŸ ืกืึทืœื•ืฉืึทื ื–, ื›ืžืขื˜ ืึธื“ืขืจ ืคื™ื–ื™ืงืœื™ ื•ื•ื™ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืกืขืจื•ื•ืขืจ. 

ื’ืฉืžื™ื•ืช ื“ืขื•ื•ื™ืกืขืก ืžื™ื˜ Cisco ISE ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื–ืขื ืขืŸ ื’ืขืจื•ืคึฟืŸ SNS (Secure Network Server). ื–ื™ื™ ืงื•ืžืขืŸ ืื™ืŸ ื“ืจื™ื™ ืžืึธื“ืขืœืก: SNS-3615, SNS-3655 ืื•ืŸ SNS-3695 ืคึฟืึทืจ ืงืœื™ื™ืŸ, ืžื™ื˜ืœ ืื•ืŸ ื’ืจื•ื™ืก ื’ืขืฉืขืคื˜ืŸ. ื˜ื™ืฉ 1 ื•ื•ื™ื™ื–ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ ื“ืึทื˜ืึทืฉื™ื˜ SNS.

ื˜ื™ืฉ 1. ืคืึทืจื’ืœื™ื™ึทืš ื˜ื™ืฉ ืคื•ืŸ ืกื ืก ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืึธื’

ืคึผืึทืจืึทืžืขื˜ืขืจ

SNS 3615 (ืงืœื™ื™ืŸ)

SNS 3655 (ืžื™ื˜ืœ)

SNS 3695 (ื’ืจื•ื™ืก)

ื ื•ืžืขืจ ืคื•ืŸ ื’ืขืฉื˜ื™ืฆื˜ ืขื ื“ืคึผืึธื™ื ืฅ ืื™ืŸ ืึท ืกื˜ืึทื ื“ืึทืœืึธื ืข ื™ื ืกื˜ืึทืœื™ืจื•ื ื’

10000

25000

50000

ื ื•ืžืขืจ ืคื•ืŸ ื’ืขืฉื˜ื™ืฆื˜ ืขื ื“ืคึผืึธื™ื ืฅ ืคึผืขืจ PSN

10000

25000

100000

ืงืคึผื• (ื™ื ื˜ืขืœ ืงืกืขืึธืŸ 2.10 ื’ื”ื–)

8 ืงืึธืจืขืก

12 ืงืึธืจืขืก

12 ืงืึธืจืขืก

ื‘ืึทืจืึทืŸ 

32 ื’ื™ื’ืื‘ื™ื™ื˜ (2 ืจืขื ื˜ื’ืขื  16 ื’ื™ื’ืื‘ื™ื™ื˜)

96 ื’ื™ื’ืื‘ื™ื™ื˜ (6 ืจืขื ื˜ื’ืขื  16 ื’ื™ื’ืื‘ื™ื™ื˜)

256 ื’ื™ื’ืื‘ื™ื™ื˜ (16 ืจืขื ื˜ื’ืขื  16 ื’ื™ื’ืื‘ื™ื™ื˜)

ื”ื“ื“

1 ืจืขื ื˜ื’ืขื  600 ื’ื™ื’ืื‘ื™ื™ื˜

4 ืจืขื ื˜ื’ืขื  600 ื’ื™ื’ืื‘ื™ื™ื˜

8 ืจืขื ื˜ื’ืขื  600 ื’ื™ื’ืื‘ื™ื™ื˜

ื™ื™ึทื–ื ื•ื•ืึทืจื’ RAID

ืงื™ื™ืŸ

RAID 10, ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ RAID ืงืึธื ื˜ืจืึธืœืœืขืจ

RAID 10, ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ RAID ืงืึธื ื˜ืจืึธืœืœืขืจ

ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–

2 x 10Gbase-T

4 x 1Gbase-T 

2 x 10Gbase-T

4 x 1Gbase-T 

2 x 10Gbase-T

4 x 1Gbase-T

ื•ื•ืขื’ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ื™ืžืคึผืœืึทืžืึทื ืฅ, ื“ื™ ื’ืขืฉื˜ื™ืฆื˜ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจื– ื–ืขื ืขืŸ VMware ESXi (ืžื™ื ื™ืžื•ื VMware ื•ื•ืขืจืกื™ืข 11 ืคึฟืึทืจ ESXi 6.0 ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“), Microsoft Hyper-V ืื•ืŸ Linux KVM (RHEL 7.0). ืจืขืกืึธื•ืจืกืขืก ื–ืึธืœ ื–ื™ื™ืŸ ื‘ืขืขืจืขืš ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ ืื™ืŸ ื“ื™ ื˜ื™ืฉ ืื•ื™ื‘ืŸ, ืึธื“ืขืจ ืžืขืจ. ืึธื‘ืขืจ, ื“ื™ ืžื™ื ื™ืžื•ื ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืคึฟืึทืจ ืึท ืงืœื™ื™ืŸ ื’ืขืฉืขืคื˜ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ื–ืขื ืขืŸ: ืงืกื ื•ืžืงืก ืงืคึผื• ืžื™ื˜ ืึท ืึธืคื˜ืงื™ื™ึทื˜ ืคื•ืŸ 2.0 GHz ืื•ืŸ ื”ืขื›ืขืจ, 16 ื’ื™ื’ืื‘ื™ื™ื˜ ื‘ืึทืจืึทืŸ ะธ 200 GB ื”ื“ื“. 

ืคึฟืึทืจ ืื ื“ืขืจืข Cisco ISE ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ื“ืขื˜ืึทื™ืœืก, ื‘ื™ื˜ืข ืงืึธื ื˜ืึทืงื˜ ืฆื• ืื•ื ื“ื– ืึธื“ืขืจ ืฆื• ืžื™ื˜ืœ #1, ืžื™ื˜ืœ #2.

4. ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’

ื•ื•ื™ ืจื•ื‘ึฟ ืื ื“ืขืจืข Cisco ืคึผืจืึธื“ื•ืงื˜ืŸ, ISE ืงืขื ืขืŸ ื–ื™ื™ืŸ ื˜ืขืกื˜ืขื“ ืื™ืŸ ืขื˜ืœืขื›ืข ื•ื•ืขื’ืŸ:

  • ื“cloud - ื•ื•ืึธืœืงืŸ ื“ื™ื ืกื˜ ืคื•ืŸ ืคืึทืจ-ืื™ื ืกื˜ืึทืœื™ืจืŸ ืœืึทื‘ืึธืจืึทื˜ืึธืจื™ืข ืœื™ื™ืึทื•ืฅ (ืกื™ืกืงืึธ ื—ืฉื‘ื•ืŸ ืคืืจืœืื ื’ื˜);

  • GVE ื‘ืขื˜ืŸ โ€“ ื‘ืขื˜ืŸ ืคื•ืŸ ืคึผืœืึทืฅ ืกื™ืกืงืึธ ืคื•ืŸ ื–ื™ื›ืขืจ ื•ื•ื™ื™ื›ื•ื•ืืจื’ (ืžืขื˜ืึธื“ ืคึฟืึทืจ ืคึผืึทืจื˜ื ืขืจืก). ืื™ืจ ืžืึทื›ืŸ ืึท ืคืึทืœ ืžื™ื˜ ื“ื™ ืคืืœื’ืขื ื“ืข ื˜ื™ืคึผื™ืฉ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’: ืคึผืจืึธื“ื•ืงื˜ ื˜ื™ืคึผ [ISE], ISE ื•ื•ื™ื™ื›ื•ื•ืืจื’ [ise-2.7.0.356.SPA.x8664], ื™ืกืข ืคึผืึทื˜ืฉ [ise-patchbundle-2.7.0.356-Patch2-20071516.SPA.x8664];

  • ืคึผื™ืœืึธื˜ ืคึผืจื•ื™ืขืงื˜ - ืงืึธื ื˜ืึทืงื˜ ืงื™ื™ืŸ ืึธื˜ืขืจื™ื™ื–ื“ ืฉื•ื˜ืขืฃ ืฆื• ืึธื ืคื™ืจืŸ ืึท ืคืจื™ื™ ืคึผื™ืœืึธื˜ ืคึผืจื•ื™ืขืงื˜.

1) ื ืึธืš ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ, ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ื’ืขื‘ืขื˜ืŸ ืึทืŸ ISO ื˜ืขืงืข ืื•ืŸ ื ื™ืฉื˜ ืึทืŸ ืึธื•ื•ืึท ืžื•ืกื˜ืขืจ, ืึท ืคึฟืขื ืฆื˜ืขืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื•ื•ืึธืก ISE ืจื™ืงื•ื•ื™ื™ืขืจื– ืื™ืจ ืฆื• ืกืขืœืขืงื˜ื™ืจืŸ ืึทืŸ ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’. ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ื™ืŸ ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืึทืจืึธืœ, ืื™ืจ ื–ืึธืœ ืฉืจื™ื™ึทื‘ืŸ "ืกืขื˜ืึทืคึผโ€œ!

ื‘ืึทืžืขืจืงื•ื ื’: ืื•ื™ื‘ ืื™ืจ ื“ื™ืคึผืœื•ื™ื“ ISE ืคึฟื•ืŸ OVA ืžื•ืกื˜ืขืจ, ื“ื™ ืœืึธื’ื™ืŸ ื“ืขื˜ืึทื™ืœืก admin/MyIseYPass2 (ื“ืึธืก ืื•ืŸ ืคื™ืœ ืžืขืจ ืื™ื– ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ืขืจ ื‘ืึทืึทืžื˜ืขืจ ืคื™ืจืŸ).

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 2. ื™ื ืกื˜ืึธืœื™ื ื’ Cisco ISE

2) ื“ืขืจื ืึธืš ืื™ืจ ื–ืึธืœ ืคึผืœืึธืžื‘ื™ืจืŸ ื“ื™ ืคืืจืœืื ื’ื˜ ืคืขืœื“ืขืจ ืึทื–ืึท ื•ื•ื™ IP ืึทื“ืจืขืก, ื“ื ืก, ื ื˜ืคึผ ืื•ืŸ ืื ื“ืขืจืข.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 3. ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื ื’ ืกื™ืกืงืึธ ื™ืกืข

3) ื ืึธืš ื“ืขื, ื“ื™ ืžื™ื˜ืœ ื•ื•ืขื˜ ืจืขื‘ืึธืึธื˜, ืื•ืŸ ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ื“ื•ืจืš ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืžื™ื˜ ื“ื™ ืคืจื™ืขืจ ืกืคึผืขืกื™ืคื™ืขื“ IP ืึทื“ืจืขืก.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 4. Cisco ISE ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“

4) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข > ืกื™ืกื˜ืขื > ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื•ื•ืึธืก ื ืึธื•ื“ื– (ืขื ื˜ื™ื˜ื™ื–) ื–ืขื ืขืŸ ืขื ื™ื™ื‘ืึทืœื“ ืื•ื™ืฃ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืžื™ื˜ืœ. ื“ื™ PxGrid ื ืึธื“ืข ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ื“ืึธ.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 5. ืกื™ืกืงืึธ ื™ืกืข ืขื ื˜ื™ื˜ื™ ืžืึทื ืึทื’ืขืžืขื ื˜

5) ื“ืขืจื ืึธืš ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข> ืกื™ืกื˜ืขื> ืึทื“ืžื™ืŸ ืึทืงืกืขืก> ืึทื•ื˜ื”ืขื ื˜ื™ืงืึทื˜ื™ืึธืŸ ืื™ืš ืจืขืงืึธืžืขื ื“ื™ืจืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึท ืฉืคึผืจื™ื›ื•ื•ืึธืจื˜ ืคึผืึธืœื™ื˜ื™ืง, ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ (ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืึธื“ืขืจ ืคึผืึทืจืึธืœ), ืขืงืกืคึผืขืจื™ื™ืฉืึทืŸ ื˜ืึธื’ ืคื•ืŸ ื—ืฉื‘ื•ืŸ ืื•ืŸ ืื ื“ืขืจืข ืกืขื˜ื˜ื™ื ื’ืก.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 6. ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื˜ื™ืคึผ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸCisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 7. ืคึผืึทืจืึธืœ ืคึผืึธืœื™ื˜ื™ืง ืกืขื˜ื˜ื™ื ื’ืกCisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 8. ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึทืจื•ื™ืฃ ื—ืฉื‘ื•ืŸ ืฉืึทื˜ื“ืึทื•ืŸ ื ืึธืš ืฆื™ื™ึทื˜ ื™ืงืกืคึผื™ื™ืขืจื–Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 9. ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึทืจื•ื™ืฃ ื—ืฉื‘ื•ืŸ ืœืึทืงื™ื ื’

6) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข > ืกื™ืกื˜ืขื > ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืึทืงืกืขืก > ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก > ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื™ื•ื–ืขืจื– > ืœื™ื™ื’ ืื™ืจ ืงืขื ื˜ ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 10. ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืœืืงืืœืข ืกื™ืกืงืึธ ื™ืกืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ

7) ื“ืขืจ ื ื™ื™ึทืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ืึท ื ื™ื™ึทืข ื’ืจื•ืคึผืข ืึธื“ืขืจ ืฉื•ื™ืŸ ืคึผืจืขื“ืขืคื™ื ืขื“ ื’ืจื•ืคึผืขืก. ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืขืก ื–ืขื ืขืŸ ื’ืขืจืื˜ืŸ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื˜ืึทืคืœื™ืข ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ืŸ ื’ืจื•ืคึผืขืก. ื˜ื™ืฉ 2 ืกืึทืžืขืจื™ื™ื–ื™ื– ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ISE ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก, ื–ื™ื™ืขืจ ืจืขื›ื˜ ืื•ืŸ ืจืึธืœืขืก.

ื˜ื™ืฉ 2. ืกื™ืกืงืึธ ื™ืกืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืขืก, ืึทืงืกืขืก ืœืขื•ื•ืขืœืก, ืคึผืขืจืžื™ืฉืึทื ื– ืื•ืŸ ืจื™ืกื˜ืจื™ืงืฉืึทื ื–

ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืข ื ืึธืžืขืŸ

ืคึผืขืจืžื™ืฉืึทื ื–

ืจื™ืกื˜ืจื™ืงืฉืึทื ื–

ืงื•ืกื˜ืึธืžื™ื–ืึทื˜ื™ืึธืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื’ืึทืกื˜ ืื•ืŸ ืกืคึผืึธื ืกืึธืจืฉื™ืคึผ ืคึผืึธืจื˜ืึทืœืก, ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข ืื•ืŸ ืงื•ืกื˜ืึธืžื™ื–ืึทื˜ื™ืึธืŸ

ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ื˜ื•ื™ืฉืŸ ืคึผืึทืœืึทืกื™ื– ืึธื“ืขืจ ื–ืขืŸ ืจื™ืคึผืึธืจืฅ

ื”ืขืœืคึผื“ืขืกืง ืึทื“ืžื™ืŸ

ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื–ืขืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ื“ืึทืฉื‘ืึธืจื“, ืึทืœืข ืจื™ืคึผืึธืจืฅ, ืœืึทืจืžืก ืื•ืŸ ื˜ืจืึธื•ื‘ืœืขืฉืึธืึธื˜ื™ื ื’ ืกื˜ืจื™ืžื–

ืื™ืจ ืงืขื ื˜ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ, ืฉืึทืคึฟืŸ ืึธื“ืขืจ ื•ื™ืกืžืขืงืŸ ืจื™ืคึผืึธืจืฅ, ืึทืœืึทืจืžืก ืื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืœืึธื’ืก

ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืึทื“ืžื™ืŸ

ืึธื ืคื™ืจื•ื ื’ ื ื™ืฆืขืจืก, ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ืŸ ืจืึธืœืขืก, ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื–ืขืŸ ืœืึธื’ืก, ืจื™ืคึผืึธืจืฅ ืื•ืŸ ืึทืœืึทืจืžืก

ืื™ืจ ืงืขื ืขืŸ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ ืคึผืึทืœืึทืกื™ื– ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื˜ืึทืกืงืก ืื•ื™ืฃ ื“ื™ ืึทืก ืžื“ืจื’ื”

MnT ืึทื“ืžื™ืŸ

ื’ืึทื ืฅ ืžืึธื ื™ื˜ืึธืจื™ื ื’, ืจื™ืคึผืึธืจืฅ, ืึทืœืึทืจืžืก, ืœืึธื’ืก ืื•ืŸ ื–ื™ื™ืขืจ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’

ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ื˜ื•ื™ืฉืŸ ืงื™ื™ืŸ ืคึผืึทืœืึทืกื™ื–

ื ืขืฅ ื“ื™ื•ื•ื™ื™ืก ืึทื“ืžื™ืŸ

ืจืขื›ื˜ ืฆื• ืฉืึทืคึฟืŸ ืื•ืŸ ื˜ื•ื™ืฉืŸ ISE ืึทื‘ื“ื–ืฉืขืงืฅ, ืงื•ืง ืœืึธื’ืก, ืจื™ืคึผืึธืจืฅ, ื”ื•ื™ืคึผื˜ ื“ืึทืฉื‘ืึธืจื“

ืื™ืจ ืงืขื ืขืŸ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ ืคึผืึทืœืึทืกื™ื– ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื˜ืึทืกืงืก ืื•ื™ืฃ ื“ื™ ืึทืก ืžื“ืจื’ื”

ืคึผืึธืœื™ื˜ื™ืง ืึทื“ืžื™ืŸ

ื’ืึทื ืฅ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืคื•ืŸ ืึทืœืข ืคึผืึทืœืึทืกื™ื–, โ€‹โ€‹ื˜ืฉืึทื ื’ื™ื ื’ ืคึผืจืึธื•ืคื™ื™ืœื–, ืกืขื˜ื˜ื™ื ื’ืก, ื•ื•ื™ื•ื™ื ื’ ืจื™ืคึผืึธืจืฅ

ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืกืขื˜ื˜ื™ื ื’ืก ืžื™ื˜ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ISE ืึทื‘ื“ื–ืฉืขืงืฅ

RBAC ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ

ื›ืœ ืกืขื˜ื˜ื™ื ื’ืก ืื™ืŸ ื“ื™ ืึธืคึผืขืจืึทื˜ื™ืึธื ืก ืงื•ื•ื™ื˜ืœ, ANC ืคึผืึธืœื™ื˜ื™ืง ืกืขื˜ื˜ื™ื ื’ืก, ืจื™ืคึผืึธืจื˜ื™ื ื’ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’

ืื™ืจ ืงืขื ื˜ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ ืคึผืึทืœืึทืกื™ื– ืื ื“ืขืจืข ื•ื•ื™ ANC ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื˜ืึทืกืงืก ืื•ื™ืฃ ื“ื™ ืึทืก ืžื“ืจื’ื”

ื™ื‘ืขืจ ืึทื“ืžื™ืŸ

ืจืขื›ื˜ ืฆื• ืึทืœืข ืกืขื˜ื˜ื™ื ื’ืก, ืจื™ืคึผืึธืจื˜ื™ื ื’ ืื•ืŸ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’, ืงืขื ืขืŸ ื•ื™ืกืžืขืงืŸ ืื•ืŸ ื˜ื•ื™ืฉืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–

ืงืขื ืขืŸ ื ื™ื˜ ื˜ื•ื™ืฉืŸ, ื•ื™ืกืžืขืงืŸ ืืŸ ืื ื“ืขืจ ืคึผืจืึธืคื™ืœ ืคื•ืŸ ื“ื™ ืกื•ืคึผืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืข

ืกื™ืกื˜ืขื ืึทื“ืžื™ืŸ

ื›ืœ ืกืขื˜ื˜ื™ื ื’ืก ืื™ืŸ ื“ื™ ืึธืคึผืขืจืึทื˜ื™ืึธื ืก ืงื•ื•ื™ื˜ืœ, ืึธื ืคื™ืจื•ื ื’ ืกื™ืกื˜ืขื ืกืขื˜ื˜ื™ื ื’ืก, ANC ืคึผืึธืœื™ื˜ื™ืง, ื•ื•ื™ื•ื™ื ื’ ืจื™ืคึผืึธืจืฅ

ืื™ืจ ืงืขื ื˜ ื ื™ืฉื˜ ื˜ื•ื™ืฉืŸ ืคึผืึทืœืึทืกื™ื– ืื ื“ืขืจืข ื•ื•ื™ ANC ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื˜ืึทืกืงืก ืื•ื™ืฃ ื“ื™ ืึทืก ืžื“ืจื’ื”

ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืจืขืกื˜ืคื•ืœ ื‘ืึทื“ื™ื ื•ื ื’ืก (ืขืจืก) ืึทื“ืžื™ืŸ

ื’ืึทื ืฅ ืึทืงืกืขืก ืฆื• ื“ื™ Cisco ISE REST API

ื‘ืœื•ื™ื– ืคึฟืึทืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ, ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืคื•ืŸ ื”ื™ื’ืข ื ื™ืฆืขืจืก, ืžื—ื ื•ืช ืื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืจื•ืคึผืขืก (SG)

ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืจืขืกื˜ืคื•ืœ ื‘ืึทื“ื™ื ื•ื ื’ืก (ืขืจืก) ืึธืคึผืขืจืึทื˜ืึธืจ

Cisco ISE REST API ืœื™ื™ืขื ืขืŸ ืคึผืขืจืžื™ืฉืึทื ื–

ื‘ืœื•ื™ื– ืคึฟืึทืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ, ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืคื•ืŸ ื”ื™ื’ืข ื ื™ืฆืขืจืก, ืžื—ื ื•ืช ืื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืจื•ืคึผืขืก (SG)

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 11. ืคึผืจืขื“ืขืคื™ื ืขื“ ืกื™ืกืงืึธ ื™ืกืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื’ืจื•ืคึผืขืก

8) ืึธืคึผื˜ื™ืึธื ืึทืœ ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ> ืคึผืขืจืžื™ืฉืึทื ื–> RBAC ืคึผืึธืœื™ื˜ื™ืง ืื™ืจ ืงืขื ืขืŸ ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ืจืขื›ื˜ ืคื•ืŸ ืคึผืจืขื“ืขืคื™ื ืขื“ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก.

Cisco ISE: ื”ืงื“ืžื”, ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ, ื™ื ืกื˜ืึทืœื™ืจื•ื ื’. ื˜ื™ื™ืœ 1ืคื™ื’ื•ืจืข 12. ืกื™ืกืงืึธ ื™ืกืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืคึผืจื™ืกืขื˜ ืคึผืจืึธืคื™ืœ ืจืขื›ื˜ ืžืึทื ืึทื’ืขืžืขื ื˜

9) ืื™ืŸ ืงื•ื•ื™ื˜ืœ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข > ืกื™ืกื˜ืขื > ืกืขื˜ื˜ื™ื ื’ืก ื›ืœ ืกื™ืกื˜ืขื ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ื‘ืืจืขื›ื˜ื™ื’ื˜ (ื“ื ืก, ื ื˜ืคึผ, ืกืžื˜ืคึผ ืื•ืŸ ืื ื“ืขืจืข). ืื™ืจ ืงืขื ืขืŸ ืคึผืœืึธืžื‘ื™ืจืŸ ื–ื™ื™ ื“ืึธ ืื•ื™ื‘ ืื™ืจ ืžื™ืกื˜ ื–ื™ื™ ื‘ืขืฉืึทืก ื“ื™ ืขืจืฉื˜ ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืžื™ื˜ืœ.

5. ืžืกืงื ื

ื“ืืก ืคืืจืขื ื“ื™ืงื˜ ื“ืขืจ ืขืจืฉื˜ืขืจ ืึทืจื˜ื™ืงืœ. ืžื™ืจ ื“ื™ืกืงืึทืกื˜ ื“ื™ ื™ืคืขืงื˜ื™ื•ื•ื ืึทืก ืคื•ืŸ ื“ื™ Cisco ISE NAC ืœื™ื™ื–ื•ื ื’, ื–ื™ื™ึทืŸ ืึทืจืงืึทื˜ืขืงื˜ืฉืขืจ, ืžื™ื ื™ืžื•ื ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืื•ืŸ ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืึธืคึผืฆื™ืขืก ืื•ืŸ ืขืจืฉื˜ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’.

ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืจื˜ื™ืงืœ, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึทืงืึทื•ื ืฅ, ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ Microsoft Active Directory ืื•ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ื’ืึทืกื˜ ืึทืงืกืขืก.

ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืคึฟืจืื’ืŸ ื•ื•ืขื’ืŸ ื“ืขื ื˜ืขืžืข ืึธื“ืขืจ ืื™ืจ ื“ืึทืจืคึฟืŸ ื”ื™ืœืฃ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ืขื ืคึผืจืึธื“ื•ืงื˜, ื‘ื™ื˜ืข ืงืึธื ื˜ืึทืงื˜ ืจื•ื ื’.

ื‘ืœื™ื™ื‘ืŸ ื˜ื•ื ื“ ืคึฟืึทืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื™ืŸ ืื•ื ื“ื–ืขืจ ื˜ืฉืึทื ืึทืœื– (ื˜ืขืœืขื’ืจืึทืfacebookVKTS ืœื™ื™ื–ื•ื ื’ ื‘ืœืึธื’Yandex Zen).

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’