Designing Access Controls

Finalize Security Policies

Table 3-84and Table 3-85show the resources that PCU’s network administrators define. Even though the NAC 800 falls within another defined resource, it is defined as a resource alone so that quarantined users can have access to the NAC 800 only.

Table 3-84. PCU Resources by VLAN

Resources

VLAN

Subnet

 

ID

Address

 

 

 

Directory servers, DHCP servers, RADIUS servers, NAC 800s, and

3

10.3.0.0/16

other servers used by the entire network

 

 

 

 

 

Administration building file servers, printers, and fax machines

4

10.4.0.0/16

 

 

 

Financial databases

5

10.5.0.0/16

 

 

 

Student records

6

10.6.0.0/16

 

 

 

Web servers, white pages

7

10.7.0.0/16

 

 

 

Library card catalog and printers

8

10.8.0.0/16

 

 

 

Supercomputer

9

10.9.0.0/16

 

 

 

Faculty file servers and classroom printers

10

10.10.0.0/16

 

 

 

Student file servers and dormitory printers

11

10.11.0.0/16

 

 

 

IP telephone exchange

12

10.12.0.0/16

 

 

 

Table 3-85. PCU Resources

Resource

IP Address

Protocol

Port or Ports

NAC 800

10.3.10.10

Any

Any

 

 

 

 

Internet

All except for

Any

Any

 

private

 

 

 

 

 

 

You can assign multiple resources to an access profile. In Table 3-86,fill in the resources that you will assign to each profile in your network.

3-111