Skip to main content

Posts

Cisco Zero Trust Architecture

 As a follow up to the previous post around Zero Trust Architecture , Cisco has been delivering zero trust architectures for customers for many years. With the platform approach provided by Cisco Zero Trust organizations gain better visibility across users, devices, containers, networks, and applications, verifying their security states with every access request. Adopting this model provides a balance between security and usability. Security teams can make it harder for attackers to collect what they need (user credentials, network access, and the ability to move laterally), and users can get a consistent and more productive security experience, regardless of where they’re located, what endpoints they’re using, or whether their applications are on-premises or in the cloud. Cisco Zero Trust provides a comprehensive approach to securing all access across applications and environment, from any user, device and location. It protects the workforce , workloads and workplac...

Zero Trust Architecture Overview

 Its 2020 and there is still so much buzz around Zero Trust in the industry. This is in part due to the fact that organizations still fight every day to prevent incidents, minimize risk and accelerate their time to detect | respond. As hard as organizations fight, the bad guys find new innovative ways to overcome the existing controls.  At the same time, organizations rapidly are digitizing everything they can. Whether its work from home due to pandemic, adding smart IOT sensors to improve manufacturing, or moving application to public cloud, security teams fight with the ever expanding attack surface while trying to operationalize security to be agile enough to keep up.  As defined by NIST in Special Publication 800 -207 Zero Trust Architecture : Zero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. A zero trust architecture (ZTA) uses zero tr...

Meet the Authors Video - CCIE Security and Practical Applications in Today’s Network: Zero Trust

This event took place on Thursday 29th, October 2020 at 10hrs PDT  In this session, Cisco Press authors and security experts talks about the relevance of CCIE Security in today’s evolving networks, focusing on the importance of Zero Trust. They will discuss how the CCIE Security Guide and exam prepare candidates and security experts to implement and talk about Zero Trust. In addition, the session provides the opportunity to interact with the authors and ask them questions in a live Q&A session . Join the world-class experts, who combined have over 70 years of security experience, and learn more about Zero Trust and its importance to becoming a security pro and succeeding on the CCIE Security exam. In addition, they present key content featured in the book Integrated Security Technologies and Solutions - Volume I. This event provides an opportunity to interact with the authors in real-time and learn more about them, their story, the story behind their publications,...

Why are Virtual Private Networks and Software Defined Perimeters mutually exclusive?

Increased remote work, vulnerabilities popping up and the #killthevpn movement has the cyber security industry laser focused on the transition from VPN to SDP. Let’s start with an acceptable definition of SDP from Wikipedia: “Software-defined perimeter (SDP) framework was developed by the Cloud Security Alliance (CSA) to control access to resources based on identity. Connectivity in a Software Defined Perimeter is based on a need-to-know model, in which device posture and identity are verified before access to application infrastructure is granted.” I hope we all can agree that the “ground truth" of SDP is valid and any organizations will benefit by adopting SDP architecture and principals(including Zero Trust). How is a Remote Access VPN any different than the “Client-to-gateway” deployment model defined for SDP? “In the client-to-gateway implementation, one or more servers are protected behind an Accepting SDP Host such that the Accepting SDP Host acts as a gateway between ...

Cisco Releases Idenity Services Engine (AKA ISE)

Introduction After years of innovation around Network Access Control, Cisco has released its next generation NAC solution: Identity Services Engine. ISE is combines existing loosely coupled devices AAA, profiling, posture and guest management - in single, scalability appliance. As part of the Cisco TrustSec solution and Cisco’s SecureX architecture for Borderless Networks, the Cisco Identity Service Engine provides a centralized policy engine for business relevant policy definition and enforcement. This policy work horse enables centralized, coordinated policy creation and consistent policy enforcement across the entire corporate infrastructure, from head office to branch office. ISE Features & Benefits Visibility: Single Platform & Pane of Glass - Let IT see who and what is on the network for advanced discovery and troubleshooting Dynamically collects & consolidates endpoint information to make adaptive policy decisions based on ‘context’ Integrates functions previously d...

Intrusion Prevention Best Practice - IPS Placement

Background In today's organizations, attacks come from everywhere. As cliche as it sounds, networks are borderless and because of this organizations face more sophisticated threats. As networks evolve, many organizations struggle to have intrusion prevention or other security architecture evolve at the same pace. Visibility is everything: you must be able to detect and respond to threats before they cause significant damage. The following entry is all about how to gain visibility at the different areas of the network. IPS Overview Wikipedia defines Intusion Prevention Systems as a "network security appliance that monitor network and/or system activities for malicious activity. The main functions of intrusion prevention systems are to identify malicious activity, log information about said activity, attempt to block/stop activity, and report activity." By deploying IPS, organizations are able to identify, classify, and stop malicious traffic, including worms, spyware ...

Cisco NAC vs. 802.1X

Background Access Control is on the rise. A recent Gartner survey indicates that 50% of enterprises plan to implement 802.1X in their wired networks by 2011. Gartner believes that momentum will increase strongly, and that actual enterprise adoption will reach 70% by 2011. With that said, we have a lot of organizations evaluating the differences between Cisco NAC and Cisco 802.1X. Before we dive into the details of either solution, I thought it would be appropriate to compare the two. Cisco NAC Overview Cisco NAC Appliance (formerly Cisco Clean Access) was designed to use your organization's network infrastructure to enforce security policy compliance on all devices that attempt to gain access. You can use the Cisco NAC Appliance to authenticate, authorize, evaluate, and remediate wired, wireless, and remote users before they can access the network. Features Recognize users, their devices, and their roles in the network Evaluate whether machines are compliant with security policie...

Cisco NAC Version Matrix

One popular request is a list of features that come along with the different versions out. Below is a comparison of all the major code revisions of Cisco NAC Appliance. 4.8 (LATEST) * Support for Cisco NME-NAC Platforms * Administrator Access Restriction * Out-of-Band Logoff * In-Band and Out-of-Band Filter Behavior Enhancements * Fast-OPSWAT * RADIUS Session Timeout * Passive Re-assessment * Reporting Enhancements * Agent Customization * Agent Authorizes CAS * Field-Replaceable FIPS Card for HP-Based Cisco NAC Appliances * Cisco NAC Windows Agent Version 4.8.0.32 * Mac OS X Agent Version 4.8.0.569 * Cisco NAC Web Agent Version 4.8.0.4 * Features Optimized/Removed in Release 4.8 * Supported AV/AS Product List Enhancements (Windows Version 83, Mac OS X Version 7) 4.7 * FIPS 140-2 Compliance * New Hardware Platform Support * Cisco NAC Appliance WAN Deployment Enhancements * AD SSO Requirements for Windows 7 * Windows 7 Support on Cisco NAC Agent 4.6 * Posture Assessment Support for 64-Bi...

Welcome

Today, organizations use IT to support their mission and business objectives. With the evolution of business through technology, organizations have proven that it can be an accelerator for growth, competitive differentiator, productivity enhancer and even strengthen employee satisfaction. The challenge organizations face is how to obtain these returns from the technology that they have invested in? This blog hopes to help unlock some of the secrets of deploying or using technology in a way to obtain return on your investment: get the most out of the features; optimize your environment to save cost; secure your IT infrastructure; Some of the core topics that you can count on from this Cisco Security Blog: Deployment Best Practices Upgrade Announcements & Procedures Gotchas & Workarounds Troubleshooting Tips Operationalizing Products Unlike the Cisco NAC blog, CAYSEC will expand to covering Cisco ASA, IPS, SIEM, 802.1X, IronPort S-Series and C-Series(Web and Email), and router/sw...

NAC Version 4.6.1 - Now Available

NAC Appliance Version 4.6.1 was release yesterday. Some of the new features: Posture Assessment Support for 64-Bit Windows Operating Systems The new NAC Agent can be installed and launched on 64-bit versions of Windows XP and Windows Vista, and can perform posture assessment and remediation on client machines. Earlier releases of Cisco NAC Appliance provided only authentication support for 64-bit client operating systems. Agent Configuration XML File Upload Enhancement This XML configuration file method of setting up Agents on client machines replaces the previous Clean Access Agent configuration schema requiring Windows registry setting manipulation for custom parameters. No more registry changes, hooray! If you previously employed Windows registry settings to adjust Clean Access Agent behavior on client machines, you must specify the same settings in the XML Agent configuration file to preserve Agent behavior using the Cisco NAC Agent. This upgrade has a ton of new agent features, as...

Cisco NAC Guest Server 2.0

NAC Guest Server has changed significantly with the latest 2.0 release. From External Portal Support to AD SSO, this revision has added some key enterprise features. The features that have hit home the most for myself and my customers have been: Active Directory Single Sign On Cisco NAC Guest Server 2.0 can be joined to an Active Directory Domain and then automatically authenticate Internet Explorer browsers using Integrated Windows Authentication. This removes the need for sponsors to enter their username and password. For details on configuration of ADSSO, see the Configuration of Active Directory Single Sign-On for NAC Guest Server Configuration Example Credit Card Billing Support Cisco NAC Guest Server 2.0 provides the ability for guests to purchase accounts via credit card support. This means that you can now use NGS to provide ROI for guest internet access. Management Reports Management reports are enhanced to provide the following guest network usage information: •Total Guest A...

NAC NEWS UPDATES

The following is a list of new things out there in the Cisco NAC World. The NAC Market is continuing to grow in 2009 and with the growth the products will continue to evolve, get better and have more options. Security Options Abound: New NAC Release My friends over at TechWiseTV are a huge multi-media machine, producing video, audio and podcasts. Well this PodCast is on NAC 4.5, Alok Agrawal of the NAC Business Unit and Myself dive into some of the cool features of 4.5. All of the podcasts can be subscribed to through iTunes. To access the NAC podcast go to: http://www.cisco.com/en/US/solutions/ns340/ns339/ns638/ns719/html_TW/tw_episode_198.html And to get more information on all the great stuff coming from Techwise TV visit: http://www.mytechwisetv.com/ or http://cisco.com/go/interact NAC Layer 3 Out of Band Design Guide That Uses VRF-Lite for Traffic Isolation Cisco wrote a new configuration guide on using VRF-Lite for traffic isolation. This is a great configuration option for NAC, ...

NAC Support Logs in 4.5

Many people might be wondering what happen to the handy dandy support logs that used to be located in the "/perfigo/logs/" directory in previous NAC versions. Well in version 4.5 there were some enhancements to the logging and with those enhancements came new placement of the logs. These logs are most commonly used to troubleshoot NAC during deployments. Please do not turn on advanced logging without reading the documentation fully or with the assistance of Cisco TAC. The CAM log can be found at: /perfigo/control/tomcat/logs/nac_manager.log The CAS log can be found at: /perfigo/access/tomcat/logs/nac_server.log For those of you not familiar with what the logs contain, please feel free to reference the CAM and CAS Configuration Guides: CAM Admin Guide - Support Logs CAS Admin Guide - Support Logs

NAC Version Matrix

In June of 2006, NAC Version 4.0.0 was released. Since then, Cisco has released numerous updates and features to the NAC Appliance line! Recently a member of the NAC Mailing List posted the following request: Is there a feature matrix to compare the various versions/tracks of Cisco NAC? So that is exactly what this posts answers. It is long, but I know at least one person appreciates it! I will explore 3 major lines of code.. 4.0.X, 4.1.X and 4.5.X. Realistically all new deployments should be using 4.1.X or 4.5.X, but I wanted to give a good overview for everyone on older codes. 4.0.X 4.0.0 Support for Active Directory (Windows Domain) Single Sign-On (SSO) Corporate Asset Authentication and Posture Assessment by MAC Address Support for Layer 3 Out-of-Band (OOB) Deployment New Windows Update Requirement Type SMP Kernel Support for Super CAM Support for Assigning VLANs by VLAN Name in OOB Deployments Support for "IGNORE" Global Device Filter for IP Phones in OOB Deployments Abi...