• No results found

Cisco Identity Services Engine

N/A
N/A
Protected

Academic year: 2021

Share "Cisco Identity Services Engine"

Copied!
38
0
0

Loading.... (view fulltext now)

Full text

(1)

Stefan Dürnberger

CCIE Security | Sourcefire Certified Expert

Secure Access

(2)

Cisco 2014 Annual Security Report

Most organizations, large and small, have

already been compromised and don’t even

know it: 100 percent of business networks

(3)

The security problem

Changing Business Models

Dynamic Threat Landscape

Complexity and Fragmentation

60% data in breaches is

stolen in hours

54% of breaches

remain undiscovered

for month

Information of up to 750 million individuals on the

black market

over

last three years

(4)

“How would you do security

(5)
(6)
(7)

Cisco ISE is not just a single

product. It is a system, securing

your wired, wireless and RA VPN

infrastructur including guest

(8)

Secure Access on wired, wireless and VPN

Control with one policy across

wired, wireless and VPN

XYOD

Users get safely on the network –

fast and easy

Guest Access

It´s easy to provide

guests

limited time and resource access

TrustSec Network Policy

Rules written in

business terms

controls access

(9)

http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns744/landing_DesignZone_TrustSec.html

(10)
(11)

Based on the Cisco UCS C220 M3 Server

Virtual Appliance based on VMWare Hypervisor

(12)

SNS-34x5 Appliances- Specs

Platform

Secure Network Services Appliance

SNS-3415-K9

Secure Network Services Appliance

SNS-3495-K9

Processor

1 - QuadCore Intel Xeon

2.4 GHz

2 - QuadCore Intel Xeon

2.4 GHz

No. of Cores per CPU

4 (4 total cores)

4 (8 total cores)

Memory

16 GB DDR3-1066 (4 x 4GB)

32 GB DDR3-1066 (8 x 4GB)

Hard disk

1- 2.5 Inch

600 GB SAS 10K RPM

600 GB SAS 10K RPM

2- 2.5 Inch

RAID

No

Yes - RAID 1 (600 GB Total Storage)

Ethernet NICs

4 (2 on board; 2 on NIC)

4 (2 on board; 2 on NIC)

Power Supplies

1 x 650W

2 x 650W

Trusted Platform Module

Yes

Yes

SSL Acceleration Card

No

Yes

(13)
(14)

Cisco ISE Architecture

View/Configure

Policies

Attributes

Query

Access

(15)

Distributed Topology Deployment

Data Center A DC B Branch A Branch B AP AP AP WLC 802.1X AP ASA VPN Switch 802.1X Switch 802.1X Switch 802.1X WLC 802.1X Switch 802.1X Admin (P) Admin (S) Monitor (P) Monitor (S) Policy Services Cluster

HA Inline Posture Nodes Distributed Policy Services AD/LDAP (External ID/

(16)

ISE Software

(17)

-Secure Access: Classification Attributes

Personal

(18)

ISE- Identity Stores

Identity Store

OS / Version

ISE Internal Endpoints, Internal Users

RADIUS RFC 2865-compliant RADIUS servers

Active Directory

Microsoft Windows Active Directory 2003, 32-bit only Microsoft Windows Active Directory 2003 R2, 32-bit only Microsoft Windows Active Directory 2008, 32-bit and 64-bit Microsoft Windows Active Directory 2008 R2, 32-bit and 64-bit Microsoft Windows Active Directory 2012(ISE 1.2)

LDAP Servers SunONE LDAP Directory Server, Version 5.2Linux LDAP Directory Server, Version 4.1 NAC Profiler, Version 2.1.8 or later

Token Servers

RSA ACE/Server 6.x Series

(19)
(20)

PEAP/TLS is supported on all OS and compatible with compliance module

Compliance module is supported on Windows & MAC

(21)
(22)

Profiling Database is filled up with endpoint information

Using these information in policies will consume licenses

(23)
(24)

State of compliance with the company’s security policy

Is the system running the current Windows patches

Do you have anti-virus software installed? Is it up to date

Do you have anti-spyware software installed? Is it up to date

Services, Applications/processes & Registry Keys

(25)

Cisco ISE- Compliance

(26)

VLANs

DACLs

SGTs

(27)

Downlink Encryption

(28)

Sponsor & Guest

Local users or Active Directory Users/Groups are allowed to generate guest accounts

Different types of Guests (daily – weekly – monthly – user defined)

(29)

Different sponsor portals can be configured. Fully customizeable (HTML, CSS)

Concept of „sponsor all accounts“, „group accounts“ and „own accounts“

Sponsor & Guest cont.

Locallobby user can just see and manage their own created guest accounts

(30)

Guest Flow

Sponsor & Guest cont.

All unknown Endpoints (wired or wireless) are treated as guests. This make your network a closed infrastructure

(31)

More Options for Guest

Guest self-registration- SMS, Email

Guest self-registration with sponsord approval

Daily code for trainings

Hotspot

(32)

ISE brings identity & endpoint information to Cisco Prime

E.g. posture information. Use magnifier to drill into the event

(33)

ISE troubleshooting options

(34)

ISE troubleshooting options cont.

(35)
(36)
(37)

Cisco ISE is not just a single

product. It is a system, securing

your wired, wireless and RA VPN

infrastructur including guest

(38)

References

Related documents

Middleware 3.5.6 is supported on the following operating systems: Microsoft.. • Windows XP (32 bit) • Windows Vista (32-64 bit) • Windows 7 (32-64

This actor-based taxonomy distinguishes partnerships on the basis of the different nature of the actors involved (see also Selky & Parker, 2005). The societal triangle

Ingresso merci Goods entrance Via MAESTRI DEL MARMO Ingresso/ Entrance MARE Ingresso merci Goods entrance Via MAESTRI DEL MARMO 3 4 5 5 6 Parcheggi Visitatori Visitor’s parking

Superior frontal gyrus (posterior) P Pre-central gyrus (motor strip) Cingulate cortex posterior (Parietal) Q Post-central gyrus (opercular) Insular (posterior long gyrus) R

The current study demonstrates that supervisor support, but not colleague support, moderates the relationship between job demands and work engagement.. This can be explained:

However, the competitive climate of research and the perception of the level of competition was highly indicative of work to family conflict, indicating that faculty members have a

Change in walking outlet density was associated with change in alcohol-related harms: consumption of alcohol, emergency hospital admissions and violent crime against the person

Given the higher level of household leverage, as well as the complexity of the risks involved in mortgage loans (particularly for the latest generation of innovative housing