Cisco TrustSec

The Cisco TrustSec classification and policy enforcement functions have been embedded within Cisco switching, routing, wireless LAN, and firewall products. By categorizing traffic based on the circumstantial identity of the endpoint versus its IP address, Cisco TrustSec allows more malleable access controls for vibrant networking environments and data centers.

At the point of network access, a Cisco TrustSec policy group called a Security Group Tag (SGT) is allocated to an endpoint, normally grounded on that endpoint’s user, device, and location features. The SGT signifies the endpoint’s access prerogatives, and all traffic from the endpoint will transport the SGT data. The SGT is utilized by switches, routers, and firewalls to make forwarding choices. Since SGT assignments can represent business parts and roles, Cisco TrustSec controls can be demarcated in terms of business requirements and not causal networking details.

With Cisco TrustSec, a system administrator is able to implement wide-ranging network subdivision and endpoint access controls without the modifying of the network topology (e.g., additional VLANs) and rule administration, which vastly streamlines IT engineering and operations. Cisco TrustSec policies are centrally managed by Cisco Identity Services Engine (ISE) with enforcement roles accessible in campus switches, data center switches, firewalls, and routers.

Business Issues Addressed

Reduce Operational Expenses

Virtual footprints enable flexible and elastic operations. Cisco TrustSec enables firewall and access control rules to be set by an asset or application’s role, and systematizes management of these rules, saving substantial operational efforts and time.

Allows Secure, “Any Device” Access to Resources

To assist companies, get visibility into, and effective control over, unmanaged mobile devices gaining access to their networks, Cisco TrustSec gives flexible and high-performance controls in network devices to regulate access to resources founded upon features like user role, location, device type, and posture.

Dynamic Campus Segmentation

Unlike old-style campus network subdivision methods, Cisco TrustSec is a scalable, nimble, and effective method to enforce security policy in today’s increasingly dynamic environments.

Caters for Changing Workforces and Business Relationships

Users are even more mobile and businesses are ever more cooperative. Enabling controlled access to resources for mobile users, contractors, partners, and guests has now become operationally exhaustive and technically perplexing for many companies.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Using Cisco TrustSec for Campus Network Segmentation

If some communication between user segments is required or shared services are transported to numerous user groups, meticulous interactions tend to be defined in static switch and router configurations, which can become complex. Furthermore, regulating communication within a VLAN or segment is hard to put in force.

Cisco TrustSec Solution

Utilizing a Cisco TrustSec role or SGT as the means to outline permissions on the network permits the cooperation of differentiated systems to be concluded by comparing SGT values. This avoids the necessity for additional VLAN provisioning, keeping the access network design simple and avoiding VLAN proliferation and alignment tasks required as the number of roles grows. Communication amongst user groups may be rejected, or controlled interaction on accurate ports and protocols can be allowed. This allows a much simpler and more flexible way to handling security policies.

Cisco TrustSec SG-ACLs can also stop unwelcome traffic among users of the same role, so that malicious scouting behavior and even remote misuse from malware can be efficiently prevented.

Access Controls

Typical Situation

IP-address-based ACLs are easy to install, given an understanding of the network design structure and the precise assets that require protection. They need ongoing management, but for simple role structures this is not difficult. However, as the number of access roles goes up, it can become problematic to not only manage these ACLs, but also make sure that downloaded ACLs will not surpass the memory and processing abilities of any given network access device applying them.

Cisco TrustSec Solution

Cisco TrustSec uses protected group ACLs (SG-ACL) for role-based access control. These lists comprise of source and destination roles and Layer 4 services (ports). You don’t have to maintain IP addresses in these ACLs, so they are easy to maintain, even as the environment expands.

SG-ACLs are automatically downloaded from Cisco ISE as needed by the network device, so modifications to SG-ACLs do not have to be provisioned on the network. On many Cisco platforms, the SG-ACL enforcement functions are operating at line rate, permitting ACLs to be implemented at 10G, 40G, and even 100G.

Secure BYOD or “Any Device” Access

Cisco TrustSec can utilize the wide-ranging ISE profiling, posture validation, and mobile device management integration functions as a part of the classification process. Cisco TrustSec can give wide-ranging controls applied across the network, or precisely in firewall functions if needed, that take account of the back ground classification from ISE.

Summary of Benefits

• Streamlined policy using business circumstance

–          Based on expressive business language, not networking detail

–          Based on groups that are not modified when resources are moved

–          Returns policy administration to the security team

• Improved security and reduced intricacy

–          Simplified design reduces traffic engineering and improves data center Performance

–          Highly scalable line-rate marking and policy implementation on compatible devices

–          Decreased network intricacy as compared to other segmentation methods, like VLANs.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Cisco ISE Integration with Network and Application Performance Management Platforms

At one time it was adequate to scrutinize network and application performance using general identifiers such as an IP address. Nonetheless, enterprises now require more comprehensive user information to find performance events and rapidly execute root-cause analysis and remediation. Cisco brings these features together by assimilating the Cisco® Identity Services Engine with the partner network and application performance management platforms. Together, the systems deliver in-depth performance visibility along with relevant identity and device context. The incorporation of these solutions assists the IT manager in correlating circumstantial information with a performance episode and to prioritize investigation happenings. Network and application management platforms use the circumstantial data supplied by the Identity Services Engine for quicker root-cause analysis and remediation of performance problems.

How the Integration Works

Integration makes new visibility and actions possible. Here is how this is accomplished:

• The Identity Services Engine provides circumstantial user identity and device data to network and application performance management platforms. It employs Cisco Platform Exchange Grid (pxGrid) expertise to share circumstantial information such as user name, device type, operating system, and network location.

• The management application can use this circumstantial data for quicker root-cause examination and incident resolution. For example, use this circumstantial data to comprehend specific types of endpoint devices and OS version having performance problems with particular WLAN segments in particular buildings. Applications use the Identity Services Engine as a channel for taking extenuation actions inside the Cisco network. The Identity Services Engine can isolate or block users and devices as per the policies it defines.

The Identity Services Engine gathers and provides the following circumstantial data:

• User: User name, IP address, authentication status, location

• User class: Authorization group, guest, quarantine status

• Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location

• Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) or MDM ecosystem partners

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco ISE Integration with Vulnerability Assessment Platforms

It was once considered adequate to analyze network vulnerabilities by the use of broad identifiers like an IP address. However, the upsurge in mobile traffic and devices, bring-your-own-device (BYOD) enterprises, software as a service (SaaS), and virtualization have all contributed to the requirement for profounder network security visibility and more fine-grained scrutiny. Susceptibility assessment tools allow the audit of operating systems, servers, network devices, databases, and web applications for recognized or possible susceptibility threats.

Cisco Identity Services Engine (ISE) gives precise circumstantial data, like user identity, user privilege levels, endpoint device type, and endpoint security posture via the engine’s Cisco Platform Exchange Grid (pxGrid) technology, with susceptibility assessment platforms.

Together, they give in-depth network susceptibility visibility along with pertinent identity and device circumstance. The incorporation of these cutting-edge security solutions provides security analysts the capability to assess the importance of a susceptibility event by associating the context of the incident within a susceptibility management platform console. This outlines a thorough picture of the hazards each vulnerability signifies and the aptitude to take instant action on the most egregious ones.

How the Cisco ISE Platform Works

• Cisco ISE supplies user identity and device/circumstantial data to susceptibility assessment platforms.

• Cisco ISE circumstantial information is used to produce a comprehensive view of susceptibility incident, identity, and device information. The data is used to rate the severity of susceptibilities, which then allows susceptibility incidents and responses to be prioritized.

• Users of susceptibility valuation partner products can then utilize the Identity Services Engine to take extenuation steps within the Cisco network structure. The engine can perform a quarantine or block admission to specific users and devices based on rules definite by the engine for such actions.

• All of these functions are able to be recorded and reported upon within the susceptibility valuation platform, giving unified, network wide security logging.

Some of the main Identity Services Engine attributes accessible for use by susceptibility valuation platforms for user- and device-related circumstance are:

• User: User name, IP address, authentication status, location

• User class: Authorization group, guest, quarantined

• Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location

• Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine Portal Builder

You can give visitors hotspot access to your branded site, complete with commercials, while providing corporate company staff with a self-service bring-your-own-device (BYOD) portal. It doesn’t matter what type of portal you require, Cisco ISE makes it really easy to include your branding reliably across the enterprise.

Tailor Your Portals with Expert Tools

Simple-to-use features make easy the design and administration of your portals. Edit the typescript — with font size, type, and color — and make modifications to an image file’s location and size to help ensure a faultless fit. The color selector allows you to select from a palette and even make customized colors. Implement your designs, images, and color choices to all the portals inside a project. You also have the flexibility to modify each page. Once you are done, you are able to save, copy, share, or delete   your portals.

See Your Designs Come to Life

The Cisco ISE Portal Builder “what you see is what you get” (WYSIWYG) visual editor eliminates conjecture from the design procedure. Just drag and drop objects on the screen and view how the designs will be viewed on smartphones and laptops. Notwithstanding all the progressive functionality, the portal builder keeps the workflow extraordinarily easy so that nearly anybody can become skillful at designing and creating.

Keep Your Images in One Location for Simple Access

Simply import and save pictures, logos, banners, photographs, and commercials in the image manager. All pertinent pictures can be simply accessed and utilized every time you need to make a modification to your portals.

Rapidly Make Changed as Often as Needed

Since virtually any IT generalist can become skillful at making or changing portals, anybody on your team can update the guest and BYOD portals on a recurrent basis to make declarations, transfer offers, or just modify the look and feel of your portals.

Share Design Projects, Pool resources as a Team

You will be able to share your designs with other team members so that they can appraise, comment, and even make edits. In addition, you can also share your designs with the larger public and get stimulated by their ideas in return.

Eradicate Configuration Difficulties, Systematize Portal Uploads to Cisco ISE

How can you ensure that your constituted portal remains true to your design and workflow process? Aligning and exporting custom portals can be complex, but this tool removes the conjecture. It comprises an easy to use browser plug-in to simplify the alignment and exporting of your portals in Cisco ISE. It is done right the first time, every time.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine Security Technical Alliance

However, numerous solutions from multiple vendors also generate disconnected sources of data. All these dissimilar systems produce incongruent information that needs to be manually pieced together to precisely locate a network threat and define which remediating step should be taken.

Cisco ISE can help in streamlining this process. ISE gathers valuable circumstantial information from across the network. This information can then be combined and shared across manifold systems and vendors by the Cisco Platform Exchange Grid (pxGrid). You can get answers quicker. And you can utilize the Cisco ISE Rapid Threat Containment feature to halt security threats by using the network as an enforcer.

In addition, ISE allows Security Technical Alliance partner technologies to utilize Structured Threat Information Expression (STIX) threat scores and the Common Vulnerability Scoring System (CVSS) to modify or diminish the access status founded on a threat score. You can assign access to devices that have a lower risk score while rejecting access to devices with a high risk score.

Cisco pxGrid

Cisco pxGrid is an open, scalable, and IETF standards-powered information-sharing and data-control platform. It enables numerous security products to work in tandem. Security operations can systematize to get answers quickly and control threats faster.

How pxGrid Increases Your Protection

Easier integration: You can use one API for open, automated data sharing and control among more than 50 security products. Cisco pxGrid helps in enabling a complete ecology of different IETF standards-compliant technologies to work in tandem. You need to manage and sustain only a singular interface as a substitute of a group of unrelated APIs.

Immediate visibility: Seeing all circumstantial and pertinent data on a single screen improves time and staff efficiencies. Tailor the methods in which you share and view security information. See your security position more visibly and succinctly, including challenging events on your network. Improve your staff efficiency.

Faster investigations: Perform a complete analysis on one system for faster answers. Security intelligence is able to be shared automatically between almost any pxGrid-integrated technologies. You don’t need to perform long investigations. Your security operations can come up with solutions.

Even faster responses: Stop threats immediately using the network as an enforcer. Cisco pxGrid enables any unified and proficient technology on a pxGrid instance to educate ISE to contain a threat by using the network as an enforcer so that any attack anywhere in the network can be instantly halted.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine and Check Point Integration

Cisco ISE gives a wealth of user identity, endpoint device, and network context data that is beneficial to multiple IT platforms for customers around the globe. To bring more insight to hazardous user activities on the network, Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share identity, device, and network information. The IT infrastructure can aid more use cases and function more effectively by becoming identity, device, and network conscious. Cisco pxGrid is a cohesive framework that provisions multivendor, cross-platform network system cooperation among IT infrastructures such as security monitoring and detection structures, network policy platforms, identity and access management platforms, and almost any other IT operations platform.

This integration delivers Check Point gateways with improved visibility of user actions while improving management of corporate resources. ISE assists the Check Point console to show circumstantial data associated with an incident, such as the user’s characteristics and level of access. This ability enables your security team to make access policy judgments by using identity information which provides far more policy information than traditional firewalls, which are restricted to data like IP addresses or port numbers. This improved level of detail from ISE can decrease threats and data loss by limiting access to resources by users and devices. The resolution is composed of Cisco ISE running pxGrid context-exchange abilities, an ISE Plus or Advanced Feature license, and the Check Point Identity Awareness Software Blade.

How Cisco ISE & Check Point Integration Work

• Cisco ISE supplies its user identity and device data to Check Point Identity Awareness

• Identity Awareness utilizes the precise, real-time user identity context given by ISE in its firewall rule base

• ISE circumstantial information is also added to related events in Check Point to give the supplementary context of the user, device, and access level, assisting analysts to better comprehend the consequence of a security incident

• All of these utilities can be recorded and reported on within the Check Point console, which gives unified user activities for security threat reporting

Some of the chief ISE attributes obtainable for use by Check Point for user-related context include:

• User: user name, IP address, authentication status, location

• User class: authorization group

• Cisco TrustSec: security group tag (SGT)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Secure and Manage Your Evolving Network with the Cisco ISE

Flexibility, digitization, and the Internet of Things (IoT) are rapidly changing the way and manner in which we live and work. Enterprises are tested with supporting a wide array of network-enabled devices even as innumerable security threats and highly broadcasted data breaches exhibit the significance of defending access to the ever changing enterprise network.

As the modern network continues to expand, so does the difficulty of arranging resources, handling incongruent security solutions, and regulating risk. Then you need to take in to account the pervasive connectivity of non-corporate devices with already constrained IT resources. The likelihood of being unable to find and fix security threats becomes huge indeed. A different approach is needed to both manage and protect the ever changing enterprise network. It’s called the Cisco Identity Services Engine (ISE).

Important ISE 2.2 updates and enhancements allow you to:

• View and share rich user and device details: Get additional user and endpoint visibility all the way from all the guest users in the network right down to the endpoint application level.

• Manage access all over the network using next-level control for endpoints. Coupled with even richer endpoint and application visibility, Cisco ISE is able to enforce extremely granular user behavior and device compliance.

• Use the simple wireless setup tool. Enterprise-grade network access security can now be attained with industry-leading swiftness and simplicity of use with the new built-in ISE setup tool. The zero-day wireless installation with Cisco Wireless LAN Controllers can be attained in under 10 minutes for protected access, guest services, and BYOD.

• Halt and contain network threats: Develop a next-level segmentation tactic with ISE DEFCON. You can set multiple policy scenarios predefined within numerous Cisco TrustSec matrixes. You can dynamically install software-defined segmentation instantaneously based on your company’s threat climate.

Furthermore, ISE uses Cisco Platform Exchange Grid (pxGrid) technology to share rich circumstantial data with incorporated technology partner solutions. pxGrid is an Internet Engineering Task Force (IETF) standards-based method to quicken your ability to find, alleviate, and fix security threats all across your extended network. Overall, the access control is consolidated and mad easy to deliver important business services much more securely, augment infrastructure protection, impose compliance, and make more efficient IT operations.

Via its integrations with principal networking and threat defense solutions, its profound network visibility, and its protected access control abilities, ISE plays an essential role in the Rapid Threat Containment, network-as-a-sensor, and network-as-an-enforcer solutions which empower the Cisco Digital Ready Network.

To learn more about the Cisco ISE, visit http://www.cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Enterprise Guest Access for Less with Cisco Identity Services Engine (ISE) Express

Introducing Cisco ISE Express

Easy, Affordable Guest Services Entry-Level Bundle for the Market-Leading Cisco ISE

• ISE Express:

One (1) ISE VM with ISE Base Licenses for 150 Endpoints for Single Site Deployment (non-distributed, no high-availability)

• The Features:

Guest, RADIUS/AAA, Unlimited Custom Portals with ISE Portal Builder, Easy Installation Guide

It is a common occurrence that such services present an expensive proposition to a multitude of smaller organizations and more cost-cognizant companies. In response to this apprehension, the Cisco Identity Services Engine team developed ISE Express, an all-inclusive licensing package that offers enterprise-level guest services, comprising hotspot, sponsored, and self-registration portals. It gives RADIUS and authentication, permission, and accounting (AAA) for access control for up to 150 endpoints at an aggressive entry-level cost structure.

Features Included with Cisco ISE Express

The licensing bundle itself comprises a Cisco Identity Services Engine Base license for up to 150 endpoints, an ISE virtual machine, unconstrained access to the ISE Portal Builder, and a setup guide that makes installing the solution comparatively simpler. Cisco ISE comprises native design abilities. You can rapidly develop a portal by adding pictures (logos and banners, for example) and choosing a color scheme to match a corporate brand. The Cisco ISE Portal Builder is a web-based development tool which empowers users with the ability to develop highly tailored portals in 17 languages via a set of 10 designer templates which are easily customizable and simple to export to the solution.

Cisco ISE Express is constrained to a single occurrence and cannot be run as a distributed solution or in a high-availability installation configuration. Nonetheless, this bundle gives an attractive preliminary point for a Cisco ISE installation. You also gain the accessibility of expanding the configuration at a later date to support supplementary guests or more progressive use cases.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco AnyConnect and Cisco Identity Services Engine

Advantages and Features of Cisco ISE

View and share rich user and device information – Users and devices are displayed in a simple, elastic user friendly interface. ISE shares information via the Cisco Platform Exchange Grid (pxGrid) with partner platforms to ensure they are aware of the user, device, and network.

Manage all user access via one platform – Streamline access over wired, wireless, and VPN connections. User Access Control Policies are implemented across all types of access points and applied by Cisco TrustSec software-defined subdivision.

Halt and contain network threats – Minimize the risks and contain network threats by automatically regulating network access by all users. Cisco ISE is able to evaluate network susceptibilities and implement network threat intelligence. Cisco ISE is has the ability to contain a doubtful device for immediate remediation. This feature is called Cisco Rapid Threat Containment.

Cisco ISE Deployment

Cisco ISE is a highly elastic and scalable license model which dynamically aligns with your desired results.

1) Choose a deployment model – You can choose from a plethora of deployment models including AAA, 802.1X, guest, BYOD, pxGrid, mobile device management.

2) Choose the number of endpoints – Cisco ISE has the ability to dynamically scale to cater up to 500,000 concurrent sessions and up to 1.5 million endpoints per deployment. This is the best in the industry!

3) Choose a machine – Cisco’s physical and virtual appliances are grounded on the Cisco UCS C220 server and are configured to be able to support Cisco ISE.

4) Get deployment services – Cisco ISE deployment will help you get up and running in no time without the risk of operational disruptions. The Cisco Security Plan and Build Services will be your best guide for all the advanced support you require in this transition.

To learn more about Cisco AnyConnect and Cisco ISE, please speak to a professional today.