Cisco AnyConnect Reduces Threats from Non-Corporate Mobile Applications

Take the example of a sales executive who is required to check a client’s order from his company- authorized tablet in the client’s lobby. Another case could be a contractor with his private smartphone who needs to be able to access project emails from his place of residence.

What is the big issue here? The rush to give access to these off-site devices implies that we have abridged or even thrown away much needed security controls when it comes to remote connectivity for mobile devices. Providing access from any device, any location, anytime, can grant unauthorized access to possible security threats. The mobile endpoint is a threat trajectory with 68% of companies stating that their mobile devices were besieged by malware in the last year.

What if we protect these mobile devices using VPN tools in the same manner as laptops? “Turning On” VPN on any endpoint implies that all traffic and apps (personal and company) are all communicated over the same VPN channel to access company networks. This co-mingling of company and user applications increases the risk of compromised user apps contaminating the company network and enhances the possibility of threats to the network.

So now what? I don’t wish to enable VPN every single time I have to look for a document or use salesforce.com or try to access my company email. This would increase the complications for the user and provide them with a motive to either find a way around the procedure or invalidates the productivity which all businesses wish to encourage with their mobile workforce.

The solution lies with Cisco AnyConnect which offers companies the capability to provide per-application protected access for only permitted company apps in a manner which is seamless to the users. By simply clicking on the registered company app I wish to use, I can automatically initiate a protected connection for JUST that app every time. This implies that I don’t blend access to company assets between sanctioned apps and possibly infected user apps. It even minimizes bandwidth and IT resource usage as user apps will not get tunneled back to the company network and have to go through user networks (mobile or WiFi).

Companies want to enable their mobile users to work remotely, while IT staff wants a simplified method of controlling and securing enterprise access reliably across all connected devices whether these are on or off-site. Cisco AnyConnect continues to develop to deliver unified and elastic protection and access control for all remote and/or mobile endpoints.

To find out more about Cisco AnyConnect features, plans and pricing please reach out to our AnyConnect professionals here.

Cisco AnyConnect and Cisco Identity Services Engine

Advantages and Features of Cisco ISE

View and share rich user and device information – Users and devices are displayed in a simple, elastic user friendly interface. ISE shares information via the Cisco Platform Exchange Grid (pxGrid) with partner platforms to ensure they are aware of the user, device, and network.

Manage all user access via one platform – Streamline access over wired, wireless, and VPN connections. User Access Control Policies are implemented across all types of access points and applied by Cisco TrustSec software-defined subdivision.

Halt and contain network threats – Minimize the risks and contain network threats by automatically regulating network access by all users. Cisco ISE is able to evaluate network susceptibilities and implement network threat intelligence. Cisco ISE is has the ability to contain a doubtful device for immediate remediation. This feature is called Cisco Rapid Threat Containment.

Cisco ISE Deployment

Cisco ISE is a highly elastic and scalable license model which dynamically aligns with your desired results.

1) Choose a deployment model – You can choose from a plethora of deployment models including AAA, 802.1X, guest, BYOD, pxGrid, mobile device management.

2) Choose the number of endpoints – Cisco ISE has the ability to dynamically scale to cater up to 500,000 concurrent sessions and up to 1.5 million endpoints per deployment. This is the best in the industry!

3) Choose a machine – Cisco’s physical and virtual appliances are grounded on the Cisco UCS C220 server and are configured to be able to support Cisco ISE.

4) Get deployment services – Cisco ISE deployment will help you get up and running in no time without the risk of operational disruptions. The Cisco Security Plan and Build Services will be your best guide for all the advanced support you require in this transition.

To learn more about Cisco AnyConnect and Cisco ISE, please speak to a professional today.

Why your Network is Still Getting Infected by Malware

Malware threats to your corporate network are becoming more and more sophisticated but attackers usually reuse the same infrastructure to make numerous attacks on your network — leaving their cyber fingerprints behind. What if you had the ability to use those fingerprints to expose attacks prior to their launch?

Most of your branch locations will be connecting directly to the internet instead of sending their traffic to the corporate headquarters. You will be left with inadequate or zero visibility into possible network threats targeted to these users. What if you were able to defend your branch locations without needing to add additional hardware or installing endpoint security?

Your primary emphasis has always been to minimize the time invested in detecting and defending against malware. Has this priority made your network more secure? You are still being flooded with network infections despite your current security. It’s not sufficient to wait for any malware to reach the company network and endpoints before you attempt to find and halt them. What if you could find and stop malware threats earlier?

Cisco Umbrella can be your Network Savior

Being the IT industry’s pioneering Secure Internet Gateway in the cloud, Cisco Umbrella gives your network the first line of protection against malware threats on the internet. As Cisco Umbrella is delivered from the cloud, it is the simplest method of protecting all of your users in within minutes.

To find out more about Cisco AnyConnect and Cisco Umbrella, please speak to a specialist today.

Advanced Threat Protection with Cisco AnyConnect

As per a survey conducted recently by the Ponemon Institute, 75 percent of respondents (a big jump from 68% in last year’s survey) consider their mobile endpoints have been the target of malware for at least the past year.

This issue becomes aggravated as more and more users use mobile devices for private use as well as for gaining access to commercial applications. This same survey shows that one of the major apprehensions emphasized was “…staff use of corporate cloud applications in the Place of work…” One area where many IT companies are wanting to supply reliable and safe right of entry is employing VPN expertise on a broader variety of endpoints being used to connect to business assets.

While remote VPNs on endpoints are important for defending and obscuring data in transit, it doesn’t do much in defending against malware. On the other hand, traffic in a VPN tunnel has the ability to even hide malware from inspection engines up until the tunnel is terminated. This is mostly done at the end or from within the network. As a result, there is an incorrect feeling of security, while users do not understand that their endpoint can still become infected and forward compromised traffic back to the company network. Hence VPNs have the ability to act as an express pathway into the inner sanctum of the company network for malware in case an endpoint has been infected.

Just as in traditional systems, clients need access to reliable malware defense irrespective of how users gain access to the corporate applications and data. IT companies have to apply forward-thinking malware scrutiny inside the VPN tunnel before it can go too far into the network to have damaging consequences. The mixture of VPN tunneling technology to defend data being sent externally from the network and malware scrutiny gives the standard of security required which is in line with defense inside the company network itself.

Cisco is now shipping the new AnyConnect Mobile Client 4.1 which has the Cisco Advanced Malware Protection (AMP) Enabler for setting up and running Cisco AMP for Endpoints when requested. AMP for Endpoints can quickly find out if a VPN tunnel is hiding malware-infected traffic and then provide instant resolution and defense.

AMP for Endpoints gives innovative threat defense for endpoints, whether these end points are connected to a protected network or if they are roaming on the Internet, with nonstop and incorporated detection, reaction, and remediation abilities. AMP employs big data analytics and incessant scrutiny to unceasingly examine files after they are first perceived to track shifting threat levels. In case a file with an unidentified or previously believed “good” temperament begins acting badly, AMP will find it and immediately inform security teams with a warning of compromise, or spontaneously remediate the malware as per the policy controls.

To find out more about CISCO AnyConnect features, benefits and pricing, please reach out to one of our AnyConnect Specialists.

Cisco AnyConnect Network Visibility Module

How the CISCO AnyConnect Module Benefits You

The Cisco AnyConnect® Network Visibility Module allows you to view user and endpoint activities both on and off site. It gathers standard data flows from endpoints (laptops, for example) as well as data like user, application, device, location, and destination data. IT Admins can then accumulate and examine this rich aggregated statistic. They can then better protect the company from possible security issues along with assist them in addressing a variety of network operational challenges.

The Network Visibility Module employs standards-based flow expertise. IT Security staff can use their current collector platform to screen and examine performance. For example, an IT security team could view an off-site user transmitting abnormal amounts of data to an external storage medium, indicative of possible data exfiltration. Or they can get insight into shadow IT activities when users try to gain access to unsanctioned solicitations.

Networking and application staff can use the material to enhance global network processes, sustain application capacity design, and troubleshoot problems. The network operations staff can set up VPN split tunneling to preserve Internet bandwidth costs. This will help them find out which traffic has to be sent to the enterprise and which can go directly to the Internet.

With the release of version 4.3 for AnyConnect, the Network Visibility Module comes bundled with improved functionality, which gives you additional features like cached data throttling, broadcast and multicast suppression, and a more elastic collection strategy with innovative property fields. The Network Visibility Module is also being released for 3rd-party development via APIs offered by Cisco DevNet.

To find out more about CISCO AnyConnect and pricing for your enterprise, please speak to an AnyConnect professional today.

Cisco AnyConnect Secure Mobility Client

CISCO AnyConnect Features and benefits

Access from anywhere – Give any user highly secure access to the enterprise network, from any device, at any time, in any location.

Enhanced visibility – AnyConnect gives you more understanding into user and endpoint happenings with complete visibility across the whole network. Using AnyConnect’s Network Visibility Module (NVM), you will be able to protect more efficiently and enhance network processes.

Complete security – Guard your network against threats, no matter where these occur. With Cisco Identity Services Engine (ISE), you can preclude nonconforming hardware from accessing your network. And vis Cisco Umbrella Roaming, you can enhance protection when users are off 0the VPN.

Streamlined management and usability – CISCO AnyConnect gives you access to a reliable user experience across various platforms and devices, both on and off site, without creating a nuisance for your IT teams. Streamline management with a single agent.

How to deploy CISCO AnyConnect

1) Select your use case – Basic VPN, posture, roaming protection, network visibility? With Apex and Plus licensing, you can get the features you need.

2) Select a subscription period – Both term (1, 3, or 5 years) and perpetual licenses are obtainable.

3) Select your required number of total users – 25, 1000, 100,000… AnyConnect has the ability to scale to meet your user requirements.

4) Get deployment facilities – Get up and running quickly without any troubles. The CISCO Security Plan and Build Services give you access to advanced professional deployment support.

To find out more about CISCO Any Connect licensing and pricing, please contact one of our Cisco licensing professionals here.