If some communication between user segments is required or shared services are transported to numerous user groups, meticulous interactions tend to be defined in static switch and router configurations, which can become complex. Furthermore, regulating communication within a VLAN or segment is hard to put in force.
Cisco TrustSec Solution
Utilizing a Cisco TrustSec role or SGT as the means to outline permissions on the network permits the cooperation of differentiated systems to be concluded by comparing SGT values. This avoids the necessity for additional VLAN provisioning, keeping the access network design simple and avoiding VLAN proliferation and alignment tasks required as the number of roles grows. Communication amongst user groups may be rejected, or controlled interaction on accurate ports and protocols can be allowed. This allows a much simpler and more flexible way to handling security policies.
Cisco TrustSec SG-ACLs can also stop unwelcome traffic among users of the same role, so that malicious scouting behavior and even remote misuse from malware can be efficiently prevented.
Access Controls
Typical Situation
IP-address-based ACLs are easy to install, given an understanding of the network design structure and the precise assets that require protection. They need ongoing management, but for simple role structures this is not difficult. However, as the number of access roles goes up, it can become problematic to not only manage these ACLs, but also make sure that downloaded ACLs will not surpass the memory and processing abilities of any given network access device applying them.
Cisco TrustSec Solution
Cisco TrustSec uses protected group ACLs (SG-ACL) for role-based access control. These lists comprise of source and destination roles and Layer 4 services (ports). You don’t have to maintain IP addresses in these ACLs, so they are easy to maintain, even as the environment expands.
SG-ACLs are automatically downloaded from Cisco ISE as needed by the network device, so modifications to SG-ACLs do not have to be provisioned on the network. On many Cisco platforms, the SG-ACL enforcement functions are operating at line rate, permitting ACLs to be implemented at 10G, 40G, and even 100G.
Secure BYOD or “Any Device” Access
Cisco TrustSec can utilize the wide-ranging ISE profiling, posture validation, and mobile device management integration functions as a part of the classification process. Cisco TrustSec can give wide-ranging controls applied across the network, or precisely in firewall functions if needed, that take account of the back ground classification from ISE.
Summary of Benefits
• Streamlined policy using business circumstance
– Based on expressive business language, not networking detail
– Based on groups that are not modified when resources are moved
– Returns policy administration to the security team
• Improved security and reduced intricacy
– Simplified design reduces traffic engineering and improves data center Performance
– Highly scalable line-rate marking and policy implementation on compatible devices
– Decreased network intricacy as compared to other segmentation methods, like VLANs.
To learn more visit www.cisco.com/go/ise
For more details contact our Cisco Licensing Specialists here.
