aruba 360 secure fabric€¦ · clearpass family: from visibility to control onboard self-service...

25

Upload: others

Post on 18-Aug-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+
Page 2: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+
Page 3: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Aruba 360 Secure Fabric

SECURING THE EXPERIENCE EDGE

Also Security Day 17.10.2019

Mirja Aimo, HPE Aruba

Simo Mäkinen, Also

Page 4: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

IOTFIXED MOBILE

CLOUDENABLED

Evolution of the

NETWORK

Page 5: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Key campus network

CHALLENGESPolicy

administration complexity

Security concerns with the growth of

IoT

Enhancing user (and device) experience

Page 6: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

New Attack Environment: No Walls, New Threats

ATTACKERSARE QUICKLY INNOVATING &

ADAPTING

BATTLEFIELDWITH IOT AND CLOUD, SECURITY

IS BORDERLESS

Page 7: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

…another example…

3. www.engage.arubanetworks.com/LP_REG_510245507_510245507_ARUBA_WW_EN-US

https://www.washingtonpost.com/news/innovations/wp/2017/07/21/how-a-fish-tank-helped-hack-a-casino/

Page 8: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

UNIQUELY POSITIONED TO DELIVER ADVANCED

PROTECTION

ANALYTICS

CONTROL

CONNECTIVITY

VISIBILITY

Page 9: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Visibility, Detection and Control

Aruba 360 Secure Fabric

Experience Edge ArchitectureAruba Secure Infrastructure

Encryption| Application FW | Dynamic Segmentation

ClearPass | IntroSpectDiscovery, Authorization, and Integrated Attack Detection and ResponseAruba

360 SecurityExchange

OtherInfrastructure

Security Analytics

Page 10: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

• Real-time Quarantine • Re-authentication• Bandwidth Control• Blacklist

User/Device Context

ActionableAlerts

ClearPassSecure Access Control Entity360 Profile

with Risk Scoring

1. Discover and Authorize

2. Monitor and Alert

3. Decide and Act

IntroSpect UEBA

CLEARPASS + INTROSPECT = INTEGRATED PROTECTION

ClearPass Adaptive Response

Page 11: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

IntroSpectContinuousMonitoring

ClearPass Policy Manager

Attack Response

ClearPass Policy Manager

DynamicSegmentation

ClearPass Device InsightDiscovery and

Profiling

AUTOMATED, CLOSED-LOOP SECURE CONNECTIVITY

Page 12: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

ClearPass Family: From Visibility to Control

Onboard

Self-service BYOD

Guest/

Captive Portal

Policy Engine

Reporting3rd Party

IntegrationsTACACS+

OnGuard

Device health checks

Device Insight

Total Visibility

Page 13: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

What does ClearPass do to help?

Defines WHO and WHAT DEVICES can connect to:

DEVICES DATA INFRASTRUCTURE APPLICATIONS

Identify – Enforce – Protect

Page 14: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

CONTROL: AUTHENTICATION AND AUTHORIZATION

WhichDEVICES

WhichDATA

WhichINFRASTRUCTURE

WhichAPPLICATIONS

Enterprises define who can access files and applications

Full range of RADIUS and non-RADIUS authentication

Defines WHO and WHAT DEVICES can connect to:

POLICY MANAGER

Page 15: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

SECURITY STARTS WITH VISBILITY

CLEARPASS DEVICE INSIGHT

Delivers automated, AI-powered device identification combined with policy-based

access control

Page 16: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

CLASSIFIES UNKNOWN DEVICES

Device Attributes

IP/MAC Address

Application Access

Communication Protocols

Communication Frequency

Deep Packet Inspection (DPI)

MACHINE LEARNING

Page 17: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

DEVICE INSIGHT

IT/Security teams lack visibility into devices on the network

Current device profiling techniques fail to address visibility and IoT use cases

Volume and variety of devices means manual approaches cannot keep pace

Without comprehensive visibility, effective security and compliance is not possible

Reduces Risk by Eliminating Blind Spots

through DPI-based discovery and profiling of devices

Automatically Classifies Unknown Devices

using advanced machine learning and crowdsourcing intelligence

Automates Secure Accessvia seamless integration with ClearPass Policy Manager

CHALLENGES VALUE PROPOSITIONS

Page 18: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Multi-Vendor Switching

Multi-Vendor WLANs

ClearPass Policy ManagerAUTOMATED SEGMENTATION AND

ENFORCEMENT

Internet of Things (IoT)

BYOD and Corporate Owned

ClearPass Device InsightENHANCED DISCOVERY / PROFILING

Bi-Directional Data Exchange

DEVICE INSIGHT + POLICY MANAGER

AUTOMATES SECURE ACCESS

40%Of the Global 500

130+ Ecosystem Partners

Page 19: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

AUTHORIZE: CONTEXT-BASED ACCESS

Enterprise LaptopInternet and Intranet

Authentication EAP-TLS

SSID CORP-SECURE

BYOD PhoneInternet Only

Authentication EAP-TLS

SSID CORP-SECURE

Page 20: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

GUEST

DATA

VOICE

CORP

BYOD

Segmentation brings

COMPLEXITY

Page 21: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Trust Enforced by Dynamic Segmentation

Campus Controller

Cluster

Corp

BYOD

IOT

Guest

Office

365

Academic

Records

n0tma1ware

.biz

AirGroupAccess Point

Access Switch

Users and Devices

Applications and Destinations

ClearPass Role-based

Policies

Page 22: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

IntroSpect Advanced Analytics and Forensics

SUPERVISED

UNSUPERVISED

MACHINE LEARNINGPackets

Flows

Logs

Alerts

Page 23: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

HOW WE’RE DIFFERENT

CONTINUAL INNOVATION IN IOT CONNECTIVITY, SECURITY, AND AI

COMPLETE VISIBILITY ACROSS THE ENTIRE INFRASTRUCTRE

AUTOMATED, MACHINE LEARNING-BASED, DISCOVERY AND PROFILING

CLOUD-ENABLED, CROWDSOURCED

AUTOMATED, POLICY-BASED SECURE ACCESS

Page 24: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

Case Study?

• https://www.arubanetworks.com/assets/cs/CS_Goliska_UK.pdf

Page 25: Aruba 360 Secure Fabric€¦ · ClearPass Family: From Visibility to Control Onboard Self-service BYOD Guest/ Captive Portal Policy Engine Reporting 3rd Party Integrations TACACS+

THANK YOU