NAC ȣ ߵ پ ¿ ǰ Ǿ ־ ǰ з پ ⺻ ٰ ִ. پ ǰ ۿ ϱ Ʊ NAC ǰ ִ Network Based NAC ַ ˾ƺ.
ȣ NAC(Network Access Control) , ʿ伺 ǰ з ˾ƺҴ. ٽ ѹ ϸ NAC ܸ , ȹ , Ʈũ , å ؼ(Compliance) ȯ Ʈũ ̴ַ.
Ʒ 1 䵵 Gartner NAC Ѵ ִ ڷ̴. ̹ ȣ NAC ϴµ ־ ˻, μ μ å ؾ ϴ ؼ ϰ ϸ 帧 Gartner ʸ ΰ ִ.
NAC ȣ 뿡 ҵ پ ¿ ǰ Ǿ ־ ǰ з پ ʿ ⺻ ٰ ְ پ ǰ ϱ Ƿ ̹ 翡 NAC ǰ ִ Network Based NAC ַ ڴ.
NAC
NAC Ϸ NAC Ȯ ϰ Ʈũ ȯ ľ ϴ ߿ϴ. Ʈũ üؾ ϴ ں ִ. Ϲ NAC ý 2 μ ϰ ȴ.
Ư NAC ý ϴµ ־ ߿ κ ȯ ̴. Ʈũ ߸ ľ߰ų Client ȯ濡 ȯ翡 Ȯ ľϰ Ǹ NAC Ǵ Ʈũ ߴ ʷ ִ ߱ ִ. ȯ ݵ 湮Ͽ NAC üũƮ ȯ ľؾ Ѵ.
NAC ˻
NAC ؼ ȯ ʼ̴. üũƮ Ͽ ʿ ̰ 湮 ؾ Ѵ.
-
ϴ NAC ǰ Ʈũ
-
ġ ý ý
-
Ʈũ ߴ ִ
-
NAC ϴ Ʈũ ߿ ġ ʿ
-
Multiple Network Vendor ǰ
-
VoIP
-
Client ȯ濡 ߰ ߿Ұ ִ
-
ܸ ϴ
-
̱ Ʈũ ȯ
-
־ü 湮
-
Ʈũ 3-Tier 2-Tier ʿ
NAC ġ ȯ濡 ں ϴ 찡 ϸ ġ ġ ؾ ɰ ̰ ϰ ǰ ֽ Ǵ ıȿ å ݵ ؾ Ѵ.
ȯ ܰ踦 NAC ý ϰ Ǹ NAC ýۿ ܸġ ؾ Ѵ. NAC ϴ ָ Ʈũ ܸġ Ʈũ ȣ̹Ƿ ȣ Ȯ зϿ λ, ܺ¾ü, 湮 Ʈũ ؾ Ѵ.
NAC ȿ ϵǸ NAC Ʈũ ȿ ȣ ġ ϰ ش Ͽ Һ зϰ ȴ.
ܸġ ĺ ϷǸ NAC ܸġ ڿ ۾ Ѵ. ⼭ ýۿ м ʿϴ. NAC ý ǰ ý۰ ȣȯ Ǵ ߰ ʿ ֱ ̴.
ؿܿ AD(Active Directory) Ϲ ǰ ϰ ʰ ġ ϰ ִ ִ. AD , LDAP Ǵ 802.1x ʿ 쿡 NAC ý۰ ⺻ Ǿ Ѵ. NAC ü ýۿ Plug-in ϱ ϰ ߰ ʿ Ƿ ǰ Ǵؾ ̴.
Ư 802.1x Port Based Authentication ǥȭ Protocol̰ Ʈũ ġ(End Point ӵǴ) AP(Access Point) ϴ ̴. ܸġ Supplicant(α) ݵ ġǾ ϰ Ŀ μ IP ִٴ ű Supplicant ( ü ȵ), ʴ ܸ , ϳ ƯƮ Ʈ ϴ Non 802.1x ġ ü ϰ Ǵ 鵵 Ƿ Ǵؾ κ̴.
NAC å
NAC Ǵ å Ʈũ , Ʈũ , ܸġ Ἲ, ö̾ ũ з ִ. ɵ иǾ ۵Ǵ ƴ϶ ϵ Ǿ ִ. NAC å ڿ پ · Ͽ ִ (Flexibility) ؾ Ѵ.
Ϻ NAC ǰ Binary · å ֵ Ǿ ִµ ̴ Ͽ 꼺 ڿ ȥ ų ִ ִ. ؾ ⺻ å ؼ ϸ .
Network Access Control(Ʈũ )
-
OS&Non-OS ġ и ĺ
-
湮ڰ Ʈũ ϴ ش ġ Ž ̷?? Ǽڵ忡 ʾҴ
-
ȭ , ݸ ġ VLAN ġ, ġ Ʈ 湮ڿ ڿ
-
å ؼ õϰ 湮 뱸 ġ
-
IP Ͽ Ͼ ʵ ġ
-
湮ڰ ʿ ѿ Ʈũ Ȱ ֵ μ (IP, MAC, Hostname, Active Directory, Radius )
-
湮 Һ ġ , å ġ
-
ġ Ͽ å ؼ
-
¾ü ̶ ϴ μ ſ Ȯ
-
Virtual F/W(ȭ) å Һ ο ־ ѿ Ʈũ
Network Threat Control(Ʈũ )
-
ARP Ǫο Ž å
-
IPS ZeroDay Ž Ʈ
-
ġκ ϱ ġ ġ Ʈ Disable, Ʈ ϴ ƯƮ , ġ ݸ VLAN ̵ ġ, Ʈũ ߴ ǻ ó
-
м ŽϿ ݸ VLAN ̵, ش ġ ȭ鿡 뺸, ȭ IP ƴ ڸ , ġ Ʈ Disable Ʈũ
-
P2P/Messenger , 丮 , Dual Network
ܸġ Ἲ
-
پ Client(Windows, Linux, Macintosh, Mobile OS, Workstation ) ġ ν, ĺ ڻ å
-
OS/α ġ ġ ݸ 뺸
-
پ ý ġ ݸ 뺸
-
ӽ å
-
ġ α , ,
-
ũ ̹ ȣ
-
ܺ ġ ü (USB, Bluetooth, DVD/CD-ROM, PDA, PCMCIA )
ö̾
-
系 ȣ ü ȿ ؼ
-
ȣ ̵ ȿ ؼ
-
PCI-DSS, SOX, ISO 27001 ȿ ؼ ü ؼ
å ϴµ ־ Client/Clientless å ٸ ְ ִ. Client ܸġ κ å Ǵ ̰ Clientless NAC ö̾ å ϴ ִ. Client ֱ ġ, ֹ HelpDesk Ƿ ؾ ̴.
å NAC å Ⱓ Listen Only(ùķ̼) 带 Normal ϰ ȴ. ߸ å ٷ Ͽ Ʈũ ݿ ģ ʷϰ ǹǷ IT μ ȿ ʿ κ̴. NAC å Ϸ Ŀ NAC ϴ End-Point ʿ伺 ȿ ٽ ѹ ϰ ̴.
NAC
NAC ñ ַ ǰ ̴. NAC ǰ Ư ʷ ִ.
ڿԴ Ʈũ ܸ⸦ ִ ַ ڿԴ å Ʈũ ϴ ܸġ ø ް ִٴ ظ ִ κ ִ. ڿԴ ִ ģϰ ٰ ִ( å ݵǾ ǽð ִ Action ) å ʿϰ ܰ ܰ躰 å ʿϴ.
鿡 ֱ α ˰ å ֽ ŷ ݵ鿡 ֵ ɰ Ǹ ← Ѵ. ַǰ NAC ϸ ƴ϶ ɰ ִ ȿ ֱ ̴.
NAC ˻ ϸ鼭 NAC ڵ鿡 DZ⸦ ٶ. ȣ NAC ֱ ˾ƺڴ.
< : ڿö Ʈ Director(pyc@foresight.co.kr)>
[ ȣ21c 112ȣ(info@boannews.com)]
<۱: ȴ(www.boannews.com) ->