The Cisco TrustSec classification and policy enforcement functions have been embedded within Cisco switching, routing, wireless LAN, and firewall products. By categorizing traffic based on the circumstantial identity of the endpoint versus its IP address, Cisco TrustSec allows more malleable access controls for vibrant networking environments and data centers.

At the point of network access, a Cisco TrustSec policy group called a Security Group Tag (SGT) is allocated to an endpoint, normally grounded on that endpoint’s user, device, and location features. The SGT signifies the endpoint’s access prerogatives, and all traffic from the endpoint will transport the SGT data. The SGT is utilized by switches, routers, and firewalls to make forwarding choices. Since SGT assignments can represent business parts and roles, Cisco TrustSec controls can be demarcated in terms of business requirements and not causal networking details.

With Cisco TrustSec, a system administrator is able to implement wide-ranging network subdivision and endpoint access controls without the modifying of the network topology (e.g., additional VLANs) and rule administration, which vastly streamlines IT engineering and operations. Cisco TrustSec policies are centrally managed by Cisco Identity Services Engine (ISE) with enforcement roles accessible in campus switches, data center switches, firewalls, and routers.

Business Issues Addressed

Reduce Operational Expenses

Virtual footprints enable flexible and elastic operations. Cisco TrustSec enables firewall and access control rules to be set by an asset or application’s role, and systematizes management of these rules, saving substantial operational efforts and time.

Allows Secure, “Any Device” Access to Resources

To assist companies, get visibility into, and effective control over, unmanaged mobile devices gaining access to their networks, Cisco TrustSec gives flexible and high-performance controls in network devices to regulate access to resources founded upon features like user role, location, device type, and posture.

Dynamic Campus Segmentation

Unlike old-style campus network subdivision methods, Cisco TrustSec is a scalable, nimble, and effective method to enforce security policy in today’s increasingly dynamic environments.

Caters for Changing Workforces and Business Relationships

Users are even more mobile and businesses are ever more cooperative. Enabling controlled access to resources for mobile users, contractors, partners, and guests has now become operationally exhaustive and technically perplexing for many companies.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.