0% found this document useful (0 votes)
18 views65 pages

Pulse Policy Secure: BYOD & NAC Solutions

Uploaded by

hung.nguyen
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views65 pages

Pulse Policy Secure: BYOD & NAC Solutions

Uploaded by

hung.nguyen
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Pulse Policy Secure (PPS)

Network Access Control – Mobility and BYOD ready


Topics
 Introduction to Pulse Policy Secure (PPS)
 Market Trends
 Key Use Cases
 Solution Overview
 Summary
 Back up
• Deployment Options
• Usage Scenarios
• Components
• Common Features Pulse Connect Secure and Pulse Policy Secure

Proprietary & Confidential 2


Mobility Ready Network Access Control
Comprehensive visibility offers dynamic
control, reporting, and compliance

Context-aware NAC policies (role, location,


time and device) provide granular control of
BYOD smartphones, tablets, and laptops
Pulse Policy Secure

Automated BYOD onboarding, self-


service enrollment, and integration with
existing infrastructure to simplify BYOD
deployments

Proprietary & Confidential 3


Differentiators
Built on Proven, Flexible Context- End-to-end
Open Technology aware Security NAC/BYOD solution

Multi-vendor solution Allows context-aware One-stop NAC & BYOD


secures access via any policy enforcement for solution, mobility-ready
802.1X-enabled switch or wired & wireless and easy to deploy.
access point. connections, at admission
and in network, across
desktop & mobile
platforms.

Proprietary & Confidential 4


Market Trends

Proprietary & Confidential 5


Customer Challenges

Enable Mobile Balance Business Protect Sensitive Data


Workforce including Security with User by Enforcing
BYOD Productivity Compliance

Proprietary & Confidential 6


Key Customer Problems Today
How do I allow and secure
How do I allow and secure
How do I manage guest personal devices that
personal devices that
network access? guests and contractors
employees use for work?
use for work?

How do I secure my How do I meet How do I secure


IP phones, cameras, my compliance myself from APTs &
printers, and growing requirements? pervasive malware?
Internet of Things?

Proprietary & Confidential 7


Pulse Policy Secure Solutions

• Automated Onboarding • Strong Authentication


• Guest Access Management • Strong Authorization
BYOD Policy
• On/Off premise BYOD Enablement Server • Advanced RADIUS Server
• Single Pulse Client • Context-aware policies

• Single Sign-on Security • Visibility


Compliance
Automation
• Coordinated Threat Control • Endpoint Health Checks
• Seamless Integration w/ • MDM Integration
Top Networking Vendors • Reporting
• High scalability

Proprietary & Confidential 8


Key Use Cases

Proprietary & Confidential 9


Visibility – Improving Awareness
 Required to understand your
environment
 Foundation on which security
policies are built
 Simplifies responding to audits
 Enables detection and
investigation of exceptions /
incidents

Proprietary & Confidential 10


Secure BYOD – Increasing Productivity
 IT is productive by centralizing
policy control across wired,
wireless and remote devices
 Users can be productive from
corporate owned or employee
owned device
 Increase security by policy
following the user, no matter
where they travel and what
device they choose to use

Proprietary & Confidential 11


Regulatory Compliance
PPS for most stringent industry/government compliance regulations

 Prevent unauthorized network,


application, or data access
 Dynamically assess and remediate
device security posture pre- and post-
admission
 Protect network against infected devices
 Enforce consistent, context-aware,
cross-network access policies
 Apply strong, government-approved
encryption

Proprietary & Confidential 12


Comprehensive Access Control
 Enforce context-based policy
to access your network
 Users may access only
authorized resources
 Unified policy across wired
and wireless connections,
personal and corporate
devices, remote and local
access

Proprietary & Confidential 13


Solution Overview

Proprietary & Confidential 14


Pulse Policy Secure
1. Secure Access Control

 Identify
 Context
 Unified Policy
 Visibility
Wireless LAN
Wired LAN
2. BYOD Ready

 Onboarding
 Guest Management
 On-premise & Off-premise
Pulse Policy Secure
Firewall
VPN
3. Turnkey

 RADIUS Server
 Firewall Integration
 MDM/IAM Integration BYOD-ready access policy follows user

Proprietary & Confidential 15


Pulse Policy Secure
Secure Access to Corporate Network and Cloud Resources
Employee/Contractor/Guest? Identity
 Set access policy Correct?

 Enforce policies Pulse Secure PSA


(running Pulse Policy Secure )
Authentication,
Authorization, and
before users get fully Corporate device
Accounting Server
(Radius or AD)
on the network
Policy Met? Authorized?
 Identify who gets
access Personal Device

 Allow access to
authorized resources
Switches Firewall
Allow/Disallow? Protected
and WLAN (optional L4-L7)
Resources

Proprietary & Confidential 16


Pulse Policy Secure
Dynamic Security Enforcement
San Jose, CA Barcelona, Spain

Corporate
Network

Firewall Firewall

Pulse Policy Secure Pulse Connect Secure Pulse Policy Secure Pulse Connect Secure
(SSL VPN) (SSL VPN)

LAN Remote

AGENCY
REMOTE SITE
HQ
User: Adam User: Adam
Role: Finance Role: Finance

Proprietary & Confidential 17


Security Automation
Dynamic Security Enforcement
Employee/Contractor/Guest? Unauthorized
 Classify endpoints Behavior!

 Enforce policies Pulse Secure PSA


(running Pulse Policy Secure )
Network Sensor
(Profiler, SIEM, IPS,
based on purpose User Endpoints
etc.)

 Monitor endpoint
Initial Access Modify / Deny
behavior Policy Applied Access
Unmanaged Endpoints
 Detect unauthorized (Phones, Printers, etc.)

activity – modify
access Firewall
Allow/Disallow? Switches Protected
and WLAN (optional L4-L7)
Resources

Proprietary & Confidential 18


Local Visibility
On-Device Dashboard and Reporting

 Consolidated view of
appliance and endpoint
attributes
 Dashboard with drill down
reporting on connected
endpoints
 Historic trending for up to
1, 7, or 30 days

Proprietary & Confidential 19


Global Visibility
Centralized enterprise-level visibility for monitoring

 Compliance
 Security alerts
 Appliance health

* Centralized management will be available in Q3 2015

Proprietary & Confidential 20


Mobility-Ready Turn-Key Solution
 Policies enforced on any device entering the
network (laptop, smartphone, tablet)
 Integration with MDM vendors extends NAC
policy enforcement based on information
obtained from MDM.
 Interoperable with existing network
infrastructure (switches, wireless controllers,
AD, Firewalls, IDS, SIEM) and manages
security and compliance
 Role, location, time, compliance, and security
information are dynamically analyzed to
enforce fine-grained access policies

Proprietary & Confidential 21


Self-Service Device Onboarding
[Link]
Automated provisioning of device VPN,
WiFi, Email, and Certificates

Self-service steps guide users through


onboarding without helpdesk support

Smartphones and tablets can be redirected


Available for Windows, Macs,
to MDM for specialized processing iOS, and Android

Proprietary & Confidential


Proprietary & Confidential 22 22
User Experience – Day 1
Open Secure

1
3
2
Human behavior leads the new device
to the open (help) SSID

The captive portal presents a link


for onboarding

SSID is configured and the device


is moved to the secure SSID

Proprietary & Confidential 23


User Experience – Day 2+
Open Secure

1
Device auto- joins on Day 2

Proprietary & Confidential 24


Mobile Deployment Choices

Supports Native 802.1X client Advanced features supported Cross-platform (desktop &
built-in to Laptops, Tablets, and via Pulse Client for Windows mobile) clientless deployment
Smartphones and Mac OS X option with browser-based
Captive Portal

Proprietary & Confidential 25


Integration with MDM Vendors
 Easy enablement of Device
intelligent mobile-aware Management
security policies
 Starting with MobileIron
and AirWatch
Attribute
 Consolidated policy Mobile Devices Sharing
management, alerting
and reporting Authentication
& Authorization

Pulse Policy Secure

Proprietary & Confidential 26


MDM Integration
MDM Partners

MobileIron

Device Classification Compliance Extended Reporting


Differentiated access Query MDM (at admission Link to MDM from Pulse
AirWatch based on device type. and periodically) for device Policy Secure for
John on iPad gets different posture. If non-compliant, advanced device level
level of access versus limit access and/or reporting.
John on laptop. remediate.

Proprietary & Confidential 27


Integrated Guest Management

Self-service steps guide users through


onboarding without helpdesk support

Quick to deploy with built-in wizards and pre-


defined configurations while customizable with
corporate branding

Interoperates with Cisco and Aruba


wireless infrastructure

Proprietary & Confidential 28


Deployment Options
Pulse Policy Secure Pulse Policy Secure
Flexible Hardware Platform Virtual Appliance

 Single gateway runs multiple Pulse Secure offerings  Runs on numerous hardware platforms and
 4 models for companies of all sizes configurations

 Low power consumption  Enables elastic demand-based scaling

 Enterprise licensing – perpetual or subscription  Supports both VMware and KVM environments

PSA300 PSA3000

PSA5000 PSA7000

Proprietary & Confidential 29


Summary

Proprietary & Confidential 30


Pulse Policy Secure - Strengths

 Strong focus on security  Automated Onboarding


 Proven to secure mission-critical  Automated Incident Response
infrastructure Proven Secure Automation

 Unified VPN & NAC Policies  Single BYOD and NAC solution
 Access control effective on- Unified Policy End-to-end for the enterprise
premise & off-premise.  Seamless mobility
0  MDM Integration

Proprietary & Confidential 31


Mobility-ready NAC & BYOD Solution
Highly secure, end-to-end NAC & BYOD for mobility driven enterprises.

Automated onboarding. Offers best-in-class onboarding of BYOD devices. With seamless user-experience, Policy Secure
enables personal devices to be automatically configured for corporate access.

Role-based, application level enforcement of security policy. Industry leading access control solution that supports full
Layer 2 - Layer 7 enforcement.

Security automation. Automates security policy enforcement and incident response for Enterprises. Co-ordinated threat
control mechanisms continually protect from un-authorized access.

Context-aware security. Intelligent context-aware security policies analyzing user, role, device, location, time, network, and
application & compliance status information.

Guest access management. A complete guest access management solution and simplifies an organization's ability to
provide secure, differentiated guest user access to their networks.

Proprietary & Confidential 32


Simple, Secure & Easy Deployment
Eliminates the challenges of managing NAC, supporting BYOD and mobility through a simple and unified policy framework.

Single Pulse client. Integrated, multi-service client software that enables anytime, anywhere connectivity, security and
acceleration with a simplified user experience.

Standards-based & interoperable that enables ease-of-deployment, leading to faster ROI, includes a standards-based
RADIUS Server, IF-MAP Server, support for native 8021.x supplicant, and TCG's TNC standards.

Proven secure. With FIPS 140-2 compliance & Common Criteria assurance level of EAL3+, Pulse Policy Secure (IC 6500
Series) provides proven security that adheres to the toughest government standards for security.

Leverages existing infrastructure investments in directories, PKI, and strong authentication with extensive support for
802.1X, RADIUS, LDAP, Microsoft Active Directory, RSA Authentication Manager, and others.

Full visibility of users, devices and applications, accessing information in the Enterprise with, dashboards, drill-down levels
and comprehensive reporting.

Proprietary & Confidential 33


Thank You
[Link]
For More Information

(408) 372-9600 info@[Link] [Link]

Proprietary & Confidential 35


Back up

Proprietary & Confidential 36


Deployment Options

Proprietary & Confidential 37


Network Visibility + Context-based Access Control
Identity & Authorization (AAA) Endpoint Posture Assessment
• RADIUS Server
• Active Directory, LDAP integration
Patches?
• MAC Auth (for headless devices)
Antivirus?
• Cert Server, Site Minder
Firewall?
• Local DB Auth

BYOD
Role based Access Control Monitoring/Containment
• Access based on end device, corporate
group membership etc.

Backbone
• L2 (802.1x) and L3 (firewall) based access
• Guest Access LANs

Proprietary & Confidential 38


Two Enforcement Modes
802.1X / RADIUS Non 802.1X –
L2 Admission Control Firewall Enforcer
L3 Network Segmentation

Proprietary & Confidential 39


Pioneer in 802.1X-Based NAC
• Standards based approach
• Highly Scalable Policy Secure

• Vendor agnostic
• Supports ANY vendor’s 802.1X-
compatible switches and access points
Wired Switch
Any 802.1X Switch/AP
• Supports standard EAP types
• Granular policy capabilities
• VLANs, ACLs, QoS,…

Proprietary & Confidential 40


Non-802.1X Deployments
Integrates with Juniper & Palo Alto Firewalls

Pulse Policy Secure


SBR/AD/LDAP/PKI/RSA/Radius

Endpoints Switches and WLAN Juniper or PAN Firewalls Protected Resources

Firewall acts as Policy Enforcement Point

 Persistent client (Pulse) or captive portal for agentless  SRX User Role based “Application” firewall support – Can
users manage policies at app level
 PPS pushes policies to Juniper SRX firewalls based on  Dynamic VPN policy – PPS forces endpoint to establish
user and device identity/role. VPN to SRX based on the type of DC application that is
accessed

Proprietary & Confidential 41


Enterprise-Wide Single Sign-On

AD/LDAP/PKI/RSA Pulse Policy Secure

Pulse Client Pulse Connect Secure Juniper Firewall Protected


Resources

Enterprise-wide Single Sign On (SSO)

 Seamless session migration from remote to local


 Cached credentials – no re-authentication is required
 Remote user policies are automatically provisioned on Juniper firewall with a SINGLE license

Proprietary & Confidential 42


Identity and Context Driven Security
SOLUTION
Pulse Secure Client, PCS, PPS and SRX using IF-MAP

 Secure connectivity, device and application protection, and


simplified management across multiple device types
PCS +
 Enable dynamic, policy-driven security enforcement PPS
between endpoint , MAG (PCS & PPS), and SRX firewall
 Deliver consistent, secure, and context driven access to
MAG SRX
corporate resources Series
 Endpoint profiling and behavior monitoring offer additional
security for unmanaged endpoints
HR

Finance
Broad coverage
Active Active
Flexible deployment options Directory Directory Manufacturing

Scalability and operational simplicity

Proprietary & Confidential 43


Usage Scenarios

Proprietary & Confidential 44


Basic Access Control Enforcement
Imagine an employee returning Policy Secure instructs switch
2 Remediation successful; full
1 from vacation – “Sales” user logs in to quarantine the user/device 3 network access granted
from un-patched device for automatic patch remediation

Pulse Policy Data


Secure

Finance
Switch
Local User

Video

Juniper or PAN
Firewall Apps
Patch Remediation Corporate Data Center

• Policy Secure provisions switch VLAN, ACLs, and QoS for session User attempts to access
4 • Policy Secure enables role-based policy enforcement on firewall
5 “Finance” data, but is blocked

Proprietary & Confidential 45


Unmanaged Device Access Control
Endpoint Profiler profiles Unmanaged device connects to Policy Secure looks up MAC
1 devices, creates MAC address 2 network, switch sends MAC- 3 address in Profiler, assigns
database RADIUS query role-based access

AAA – Identity Stores


User Auth
802.1X

MAC MAC Auth


Switch Pulse Policy Secure Profiler
Authentication

Endpoints

Attacker spoofs MAC Profiler detects behavior Policy Secure maps endpoint to
4 address, attempts to 5 mismatch, signals Policy 6 new role, applies restrictive
access network Secure via IF-MAP event access control policies

Proprietary & Confidential 46


Endpoint Profiling
Enterprise-wide Access Control
Imagine an employee on the
“Sales” user’s device is Remediation successful; full
road - “Sales” user logs into 2 3
1 Connect Secure from un-
quarantined for automatic network access granted via
patch remediation Pulse VPN tunnel
patched device

Federation Data
Server

Finance
Pulse Policy Secure

Mobile User Internet Pulse Connect Secure Video

Juniper
Firewall
Apps
Patch Remediation
Corporate Data Center

4 • VPN session data federated to Policy Secure User attempts to access “Finance”
• Policy Secure enables role-based policy enforcement on firewall
5 data, but is blocked

Proprietary & Confidential 47


Coordinated Threat Control
Imagine an infrastructure device Once connected, device attempts Network sensor (scanner,
1 accessing network resources: 2 unauthorized access to protected 3 IPS, SIEM) detects
printer, VoIP phone, etc. resources unauthorized behavior

Federation Server

Pulse Policy
Secure Profiler

802.1X Switches/APs Firewalls

PPS Enforcement Points


Application
Servers

Sensor signals behavior Policy Secure correlates the Policy Secure pushes appropriate
change to Policy Secure via anomalous behavior and policy to enforcement points, which
4 IF-MAP
5 network threat to the specific
6 take necessary actions against the
device device

Proprietary & Confidential 48


Components

Proprietary & Confidential 49


MAG Series Pulse Gateways
Modular, Purpose-built Gateways Supporting Pulse Connect Secure
(SSL VPN) and Pulse Policy Secure (NAC)

 Single, purpose-built gateway designed MAG6611 Gateway


to run Pulse Secure Solutions
• Pulse Connect Secure (SSL VPN)
• Pulse Policy Secure (NAC)
 4 models to meet needs of companies
of all sizes
 Small form factor for low-end devices SSL VPN Module NAC Module
 Lower power consumption
 Investment protection

Proprietary & Confidential 50


MAG Series Models
LICENSE OPTIONS: Policy Secure/Connect Secure ICE (In Case of Emergency) Advanced feature licenses

MAG2600 MAG4610 MAG6610 MAG6611


 Single application engine,  Single application engine,  1U high chassis modular  2U high chassis modular
fixed HW config. fixed HW config. configuration supports up configuration
 1U high, 30W power  1U high ½-width (may be to two service modules supports up to four service
consumption deployed side-by-side  Optional management modules
 Supports up to 100 SSL in 1U rack space) module  Optional management
VPN users or 250  Supports 1000 concurrent  Supports up to 20K module
concurrent PPS users SSL VPN or 5000 concurrent SSL VPN users  Supports up to 40K
concurrent PPS users or 30K concurrent PPS concurrent SSL VPN users
users or 60K concurrent PPS
users

Proprietary & Confidential 51


Unique MAG series Features
Feature Description
Single client, - One converged gateway for SSL VPN & NAC
single gateway - Single client for SSL VPN & NAC

Personality switching Easily change between SSL VPN & NAC personalities
(e.g., SSL VPN today, NAC tomorrow)

Modular design Mix & match service modules in chassis models to meet
changing enterprise access needs

Scalable architecture Max. support of up to 40K SSL VPN users and up to 60K NAC users in
fully-loaded high-end chassis

Proprietary & Confidential 52


The Pulse Secure Appliance Series

Multi-service appliance supporting Pulse


Connect Secure and Pulse Policy Secure

High performance throughput with


trusted access security for
enterprise services

Easy to configure, install, and deploy


out of the box with centralized
management for operational scale

Proprietary & Confidential


Proprietary & Confidential 53 53
Categories PSA300 PSA3000 PSA5000 PSA7000c/PSA7000f

MAG 2600 IC/SA2500 MAG 4610, MAG 6611+SM360,


MAG 6610+SM160, IC/SA6500
IC/SA4500
Replacement for:

Form factor Mini-ITX (6.7" x 6.7”) 1U chassis 1U chassis 2U chassis

CPU Subsystem Celeron Celeron Pentium Intel Haswell

Concurrent Sessions 200 200 2500 25,000 to 35,000

DRAM 8GB 8GB 8GB 32GB

Redundant Hot-swap 1TB


HDD 120GB 500GB 500GB
RAID 1

Encryption Data Acceleration


No No No Yes
(AES-NI)
Two 1G/10G copper or Two 10G fiber (INT/EXT)
Two 1G RJ-45 ports (INT/EXT) Two 1G RJ-45 ports (INT/EXT)
Two 1G links (INT/EXT) (Redundant links)
Ports 1G RJ-45 port (MGMT) 1G RJ-45 port (MGMT)
RJ-45 Console port 1G RJ-45 port (MGMT)
RJ45 Console port RJ45 Console port
RJ45 Console port

Power Supply 60W 200W 200W 700W Redundant

Proprietary & Confidential 54 54


PPS Virtual Appliance
PPS-VA-SPE
 Supported on VMware ESX 5.1/5.0/4.1
and KVM
 Subscription-based or perpetual licensing
with license server
 Can support up to 5000 concurrent sessions
 Advanced feature licenses are not
supported
 Supports full PPS functionality including
RADIUS server

Proprietary & Confidential 55


Pulse Client for Windows & Mac
Integrated multi-service network client delivering anytime/anywhere connectivity,
authentication/authorization, and security with a simplified user experience

 Dynamically provisioned software Pulse Client


supports both SSL VPN, L2 NAC, and L3 NAC
 Machine and user authentication
 Single sign-on with Windows Credential
Provider
 Location awareness and session migration
deliver anytime/anywhere access
automatically, without user intervention
 Standards-based, future-proofing network Builds on Pulse Secure’s market leading SSL
investments VPN and NAC technology!

Proprietary & Confidential 56


Clientless User Access
Captive portal authentication enables
clientless login – anonymous, guest,
customer, contractor, employee, etc.

Access protected resources behind an


identity-enabled firewall enforcement point

Full Host Checker integration for


Windows, Mac, and Linux

Proprietary & Confidential 57


Host Checker
Compliance is enforced before and during network session

 Hard drive encryption  Hard drive encryption


 Pre-defined Antivirus, Personal Firewall and  Antivirus, Personal Firewall, Antispyware,
Antispyware Antimalware, Windows patch checks, machine
certificate checks
 Processes
 Custom policy definition for maximum flexibility
 Files
 Processes, files, ports
 TCP or UDP Ports

Proprietary & Confidential


Proprietary & Confidential 58 58
Common Features with Pulse Connect Secure

Proprietary & Confidential 59


Pulse Secure Connect Secure
Managem ent

Per -App VPN

Connect ion Policy


Host Checker

Access Policy
L7 Web VPN

AAA
ActiveSync

L3 IPsec/ TLS VPN

Proprietary & Confidential


Proprietary & Confidential 60 60
Authentication and Authorization
Full Integration into customer Password Management Single Sign-On
AAA infrastructure Integration Capabilities

 AD  User self service for password  Automatic transition from


 LDAP management machine auth to user auth for
 Reduced support costs, enterprise backups, patching,
 RADIUS etc.
increased productivity
 RSA  Windows Credential Provider
 All standard LDAP, MSFT AD
 Certificate integration for SSO to network
and desktop
 OTP
 SSL VPN to NAC user
 Two-factor
federation for seamless access
 Etc. to internal resources by remote
users

Proprietary & Confidential


Proprietary & Confidential 61 61
Host Checker
Embedded update mechanism - appliances
• Checks devices before and during network session
automatically learn latest signature versions
• Ensures device compliance with policy
from AV vendors

Pulse Policy Secure


For Windows, checks:
• Antivirus, Personal Firewall, Antispyware,
Unmanaged Managed
Home Computer Laptop Antimalware, Windows patch checks, machine
certificate checks
• Custom policy definition for maximum flexibility
Mobile User • Process, files, open TCP & UDP ports

1. No antivirus (AV) 1. AV real-time protection running


2. Personal firewall enabled 2. Personal firewall enabled For MAC, checks:
3. User remediated  install AV 3. Virus definitions up to date • Pre-defined Antivirus, Personal Firewall and
4. Once AV installed, user granted access 4. User granted full access Antispyware
• Processes, files, open TCP & UDP ports

Proprietary & Confidential 62


Third-party MDM Integration
 Provides a single compliance enforcement
point for laptops, smartphones, and tablets
 Uses existing MDM’s SOAP/REST APIs
 Dozens of attributes, used for role-
mapping, available from the MDM vendors
 Pulse Policy Secure can push out
messaging to the MDM vendor which is
relayed to the MDM app

Proprietary & Confidential


Proprietary & Confidential 63 63
Self-Service Device Onboarding
[Link]
Automated provisioning of device VPN,
WiFi, Email, and Certificates

Self-service steps guide users through


onboarding without helpdesk support

Smartphones and tablets can be redirected


Available for Windows, Macs,
to MDM for specialized processing iOS, and Android

Proprietary & Confidential


Proprietary & Confidential 64 64
Pulse One Management
 Centralized management of appliances, endpoints, and policy for end-to-end control
 Dashboard, monitoring, and reporting for proactive administration
 SaaS offering (Amazon AWS) with role-based access for simplified and flexible
deployment

Proprietary & Confidential


Proprietary & Confidential 65 65

You might also like