First principle: Completing capacity, not replacement equipment
The first response to a new certification system should not be to replace anyone. The right idea is to determine which of the missing parts of the equipment are: missing identification, account management, log connections or missing hand-off strategies. The authentication system is supplemented by these pieces, behavioural analysis is managed and wireless control is controlled by AC. If relationships are reversed, the solution is replaced by an actual field wall.
How does Natshell get a division of labour between AUTEWAY and AC, Bras?
NATSHEL_AUTH_GATEWAY Retroactivity of authentication jumps, user identification, tactical release, flow attribution, and authentication platform connections. AC is responsible for wireless control and strategy distribution, BRAS is assigned dialling and secondary validation to the operator. Three are collaborations or not. For example, Portal certification, AC detects uncertified terminals, redirects requests to the authentication server through Portal protocols, authenticates the server page, verify identities, successfully sends a business account number down to AC, forwards it to the proxy gateway.
Connect to the unified identity system, with one account number less
Schools usually have a teaching service, a cartoon or LDAP domain. The authentication system supports third-party data source certification, using the school number, work number as a single Internet account for mandatory change in encryption for the first time without students re-registering. The interface is based on an open interface, field mapable, and it is a capability that requires field confirmation before any system can be linked. The field cannot be customized, cost and cycle assessed separately.
Multi-producer equipment docking is a basic function.
The campus network equipment brands are so diverse that it can be mixed with H3C, sharpness, Ruckus, Arba, Cisco. Certification systems need to match mainstream manufacturers ' accelerators ' ACs, Brass, gateways, routers, and switches, which is a mandatory requirement for the campus project.
No substitution for behavioural management and firewalls
Schools already have online behavior management and firewalls, and the certification system does not rob them of their functions. Behaviour management is a seven-storey application identification and behaviour control, firewall security at borders, and certification systems are designed to feed them with an identity log and firewall log on account numbers and human dimensions. This only works when traced: a behavioural record corresponds to who, what end and how long.
Programmatic expression of the collaboration
The following are the points of reference: AC-wire, BRAS-dialing, behavioural management applications, firewall boundaries, and a single identity for account. Any current network, whether to make major changes or who to put questions on the agenda, all three leaders have concerns in the context of the relationship: basic bypass roads, sub-regions, identification dimensions.
High combing and symmetry are a school-based requirement.
The campus network certification system is capable of carrying a scale: Portal and Radius have a high level of capacity per second, based on information, with the enterprise-level Portal single aircraft carrying maximum capacity to millions of users by data, multi-producer AC, Bras, gateways, routers, switches. But the depth of the connection depends on whether or not the end supports the standard protocol, External Portal, Radius, and it cannot be concluded that the message is necessarily connected.
Log docks to get the systems to bring their identity dimensions.
The authentication system connects the NATSHEL_LOG_AUDIT system, feeding authentication identities to behavioural management and firewalls so that their logs are accountable and human dimensions. In this way a track record matches who, what end and when, the NAT logs bridge the internal and external web addresses, and the three logs together form the complete evidence chain. The certification system does not rob behavior management and firewall functions, but gives them the dimensionality.
Greyscale intruding, not a single-time course
The greyscales detect early-discovering problems in the compatibility of equipment and field mapping, without risk being transferred to the whole school. The current network equipment is operated by divisions, certification systems are supplemented with identification and logs that affect the existing network ' s smallness and ease of retreat.
Multi-endpoint and wireless integration online and cable
The certification system supports cable and wireless terminals, multi-ends online. Under a unified identity, a school number is experienced on the cable side of the wireless and no re-entry is required. But multiple terminals also pose a risk of account sharing, with accommodation MAC tied to the living room and anti-agent devices matched. The authentication system is not allowed to share, but the identification dimensions and controls are accessible and manageable.