Using Cisco TrustSec for Campus Network Segmentation

If some communication between user segments is required or shared services are transported to numerous user groups, meticulous interactions tend to be defined in static switch and router configurations, which can become complex. Furthermore, regulating communication within a VLAN or segment is hard to put in force.

Cisco TrustSec Solution

Utilizing a Cisco TrustSec role or SGT as the means to outline permissions on the network permits the cooperation of differentiated systems to be concluded by comparing SGT values. This avoids the necessity for additional VLAN provisioning, keeping the access network design simple and avoiding VLAN proliferation and alignment tasks required as the number of roles grows. Communication amongst user groups may be rejected, or controlled interaction on accurate ports and protocols can be allowed. This allows a much simpler and more flexible way to handling security policies.

Cisco TrustSec SG-ACLs can also stop unwelcome traffic among users of the same role, so that malicious scouting behavior and even remote misuse from malware can be efficiently prevented.

Access Controls

Typical Situation

IP-address-based ACLs are easy to install, given an understanding of the network design structure and the precise assets that require protection. They need ongoing management, but for simple role structures this is not difficult. However, as the number of access roles goes up, it can become problematic to not only manage these ACLs, but also make sure that downloaded ACLs will not surpass the memory and processing abilities of any given network access device applying them.

Cisco TrustSec Solution

Cisco TrustSec uses protected group ACLs (SG-ACL) for role-based access control. These lists comprise of source and destination roles and Layer 4 services (ports). You don’t have to maintain IP addresses in these ACLs, so they are easy to maintain, even as the environment expands.

SG-ACLs are automatically downloaded from Cisco ISE as needed by the network device, so modifications to SG-ACLs do not have to be provisioned on the network. On many Cisco platforms, the SG-ACL enforcement functions are operating at line rate, permitting ACLs to be implemented at 10G, 40G, and even 100G.

Secure BYOD or “Any Device” Access

Cisco TrustSec can utilize the wide-ranging ISE profiling, posture validation, and mobile device management integration functions as a part of the classification process. Cisco TrustSec can give wide-ranging controls applied across the network, or precisely in firewall functions if needed, that take account of the back ground classification from ISE.

Summary of Benefits

• Streamlined policy using business circumstance

–          Based on expressive business language, not networking detail

–          Based on groups that are not modified when resources are moved

–          Returns policy administration to the security team

• Improved security and reduced intricacy

–          Simplified design reduces traffic engineering and improves data center Performance

–          Highly scalable line-rate marking and policy implementation on compatible devices

–          Decreased network intricacy as compared to other segmentation methods, like VLANs.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Cisco TrustSec

The Cisco TrustSec classification and policy enforcement functions have been embedded within Cisco switching, routing, wireless LAN, and firewall products. By categorizing traffic based on the circumstantial identity of the endpoint versus its IP address, Cisco TrustSec allows more malleable access controls for vibrant networking environments and data centers.

At the point of network access, a Cisco TrustSec policy group called a Security Group Tag (SGT) is allocated to an endpoint, normally grounded on that endpoint’s user, device, and location features. The SGT signifies the endpoint’s access prerogatives, and all traffic from the endpoint will transport the SGT data. The SGT is utilized by switches, routers, and firewalls to make forwarding choices. Since SGT assignments can represent business parts and roles, Cisco TrustSec controls can be demarcated in terms of business requirements and not causal networking details.

With Cisco TrustSec, a system administrator is able to implement wide-ranging network subdivision and endpoint access controls without the modifying of the network topology (e.g., additional VLANs) and rule administration, which vastly streamlines IT engineering and operations. Cisco TrustSec policies are centrally managed by Cisco Identity Services Engine (ISE) with enforcement roles accessible in campus switches, data center switches, firewalls, and routers.

Business Issues Addressed

Reduce Operational Expenses

Virtual footprints enable flexible and elastic operations. Cisco TrustSec enables firewall and access control rules to be set by an asset or application’s role, and systematizes management of these rules, saving substantial operational efforts and time.

Allows Secure, “Any Device” Access to Resources

To assist companies, get visibility into, and effective control over, unmanaged mobile devices gaining access to their networks, Cisco TrustSec gives flexible and high-performance controls in network devices to regulate access to resources founded upon features like user role, location, device type, and posture.

Dynamic Campus Segmentation

Unlike old-style campus network subdivision methods, Cisco TrustSec is a scalable, nimble, and effective method to enforce security policy in today’s increasingly dynamic environments.

Caters for Changing Workforces and Business Relationships

Users are even more mobile and businesses are ever more cooperative. Enabling controlled access to resources for mobile users, contractors, partners, and guests has now become operationally exhaustive and technically perplexing for many companies.

To learn more visit www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.