Pulse Policy Secure: BYOD & NAC Solutions
Pulse Policy Secure: BYOD & NAC Solutions
Identify
Context
Unified Policy
Visibility
Wireless LAN
Wired LAN
2. BYOD Ready
Onboarding
Guest Management
On-premise & Off-premise
Pulse Policy Secure
Firewall
VPN
3. Turnkey
RADIUS Server
Firewall Integration
MDM/IAM Integration BYOD-ready access policy follows user
Allow access to
authorized resources
Switches Firewall
Allow/Disallow? Protected
and WLAN (optional L4-L7)
Resources
Corporate
Network
Firewall Firewall
Pulse Policy Secure Pulse Connect Secure Pulse Policy Secure Pulse Connect Secure
(SSL VPN) (SSL VPN)
LAN Remote
AGENCY
REMOTE SITE
HQ
User: Adam User: Adam
Role: Finance Role: Finance
Monitor endpoint
Initial Access Modify / Deny
behavior Policy Applied Access
Unmanaged Endpoints
Detect unauthorized (Phones, Printers, etc.)
activity – modify
access Firewall
Allow/Disallow? Switches Protected
and WLAN (optional L4-L7)
Resources
Consolidated view of
appliance and endpoint
attributes
Dashboard with drill down
reporting on connected
endpoints
Historic trending for up to
1, 7, or 30 days
Compliance
Security alerts
Appliance health
1
3
2
Human behavior leads the new device
to the open (help) SSID
1
Device auto- joins on Day 2
Supports Native 802.1X client Advanced features supported Cross-platform (desktop &
built-in to Laptops, Tablets, and via Pulse Client for Windows mobile) clientless deployment
Smartphones and Mac OS X option with browser-based
Captive Portal
MobileIron
Single gateway runs multiple Pulse Secure offerings Runs on numerous hardware platforms and
4 models for companies of all sizes configurations
Enterprise licensing – perpetual or subscription Supports both VMware and KVM environments
PSA300 PSA3000
PSA5000 PSA7000
Unified VPN & NAC Policies Single BYOD and NAC solution
Access control effective on- Unified Policy End-to-end for the enterprise
premise & off-premise. Seamless mobility
0 MDM Integration
Automated onboarding. Offers best-in-class onboarding of BYOD devices. With seamless user-experience, Policy Secure
enables personal devices to be automatically configured for corporate access.
Role-based, application level enforcement of security policy. Industry leading access control solution that supports full
Layer 2 - Layer 7 enforcement.
Security automation. Automates security policy enforcement and incident response for Enterprises. Co-ordinated threat
control mechanisms continually protect from un-authorized access.
Context-aware security. Intelligent context-aware security policies analyzing user, role, device, location, time, network, and
application & compliance status information.
Guest access management. A complete guest access management solution and simplifies an organization's ability to
provide secure, differentiated guest user access to their networks.
Single Pulse client. Integrated, multi-service client software that enables anytime, anywhere connectivity, security and
acceleration with a simplified user experience.
Standards-based & interoperable that enables ease-of-deployment, leading to faster ROI, includes a standards-based
RADIUS Server, IF-MAP Server, support for native 8021.x supplicant, and TCG's TNC standards.
Proven secure. With FIPS 140-2 compliance & Common Criteria assurance level of EAL3+, Pulse Policy Secure (IC 6500
Series) provides proven security that adheres to the toughest government standards for security.
Leverages existing infrastructure investments in directories, PKI, and strong authentication with extensive support for
802.1X, RADIUS, LDAP, Microsoft Active Directory, RSA Authentication Manager, and others.
Full visibility of users, devices and applications, accessing information in the Enterprise with, dashboards, drill-down levels
and comprehensive reporting.
BYOD
Role based Access Control Monitoring/Containment
• Access based on end device, corporate
group membership etc.
Backbone
• L2 (802.1x) and L3 (firewall) based access
• Guest Access LANs
• Vendor agnostic
• Supports ANY vendor’s 802.1X-
compatible switches and access points
Wired Switch
Any 802.1X Switch/AP
• Supports standard EAP types
• Granular policy capabilities
• VLANs, ACLs, QoS,…
Persistent client (Pulse) or captive portal for agentless SRX User Role based “Application” firewall support – Can
users manage policies at app level
PPS pushes policies to Juniper SRX firewalls based on Dynamic VPN policy – PPS forces endpoint to establish
user and device identity/role. VPN to SRX based on the type of DC application that is
accessed
Finance
Broad coverage
Active Active
Flexible deployment options Directory Directory Manufacturing
Finance
Switch
Local User
Video
Juniper or PAN
Firewall Apps
Patch Remediation Corporate Data Center
• Policy Secure provisions switch VLAN, ACLs, and QoS for session User attempts to access
4 • Policy Secure enables role-based policy enforcement on firewall
5 “Finance” data, but is blocked
Endpoints
Attacker spoofs MAC Profiler detects behavior Policy Secure maps endpoint to
4 address, attempts to 5 mismatch, signals Policy 6 new role, applies restrictive
access network Secure via IF-MAP event access control policies
Federation Data
Server
Finance
Pulse Policy Secure
Juniper
Firewall
Apps
Patch Remediation
Corporate Data Center
4 • VPN session data federated to Policy Secure User attempts to access “Finance”
• Policy Secure enables role-based policy enforcement on firewall
5 data, but is blocked
Federation Server
Pulse Policy
Secure Profiler
Sensor signals behavior Policy Secure correlates the Policy Secure pushes appropriate
change to Policy Secure via anomalous behavior and policy to enforcement points, which
4 IF-MAP
5 network threat to the specific
6 take necessary actions against the
device device
Personality switching Easily change between SSL VPN & NAC personalities
(e.g., SSL VPN today, NAC tomorrow)
Modular design Mix & match service modules in chassis models to meet
changing enterprise access needs
Scalable architecture Max. support of up to 40K SSL VPN users and up to 60K NAC users in
fully-loaded high-end chassis
Access Policy
L7 Web VPN
AAA
ActiveSync