Layered Safety for RADIUS With Cisco

Dream world for the CISO

Organizations have all kinds of assets to guard. And a few assets are simpler to guard than others. Nonetheless, it’s not the simple stuff that retains a CISO up at night time. Earlier than we dive into the more difficult examples, let’s take into account a situation that enables a CISO to sleep peacefully.

On this situation, when a employee “goes to work” (both within the workplace or remotely), they open their company laptop computer and login to a SaaS software. This employee sorts the URL into their browser, logs in with their SSO supplier and authenticates utilizing their fingerprint (biometric) on the system. Behind the scenes, this consumer is connecting to the applying via a Zero Belief Community Entry (ZTNA) answer and authenticating with SAML protocol (or OIDC or OAuth2.0), the fashionable authentication methodology for cloud purposes.

This situation is the dream situation (and simpler) to guard:

  • Trendy, cloud software
  • Coverage-driven software entry
  • Phishing-resistant authentication
  • Trusted, managed system

The truth examine

Nonetheless, the dream situation can also be the least more likely to be the reason for a breach. As a substitute, attackers are exploiting legacy expertise or networks the place it’s tough to deploy additional safety and implement coverage, like phishing-resisting multi-factor authentication (MFA) or ZTNA. Whereas organizations are on their infrastructure modernization journey, we have to have a practical plan to guard the lengthy tails of legacy belongings which are nonetheless in place and could also be tough to safe.

What might be finished?

Layered safety with RADIUS

One among these under-rated, however frequent, authentication protocols is RADIUS (Distant Authentication Dial-In Consumer Service). RADIUS is a standard network-based authentication protocol for customers and units that want to connect with the community.

In case your group is ready the place routers, switches, wi-fi entry factors and VPNs all use RADIUS, Cisco might help. First, Cisco Identification Providers Engine (ISE) gives a layer of Community Entry Management by providing AAA safety (Authentication, Authorization, and Entry). This safety exists for customers connecting to the community within the workplace and employees connecting to the community via the VPN.

The challenges and safety implications round legacy VPN entry are effectively documented, which is why organizations are transferring towards fashionable structure with ZTNA. The issue is that many legacy purposes aren’t suitable with ZTNA and organizations should hold on to their VPN infrastructure. It isn’t a shock that whereas 86% of organizations have began to undertake zero belief, 98% haven’t reached maturity. Basically, they’re caught on this journey.

That’s the place Cisco Safe Entry is available in. Safe Entry has built-in each VPNaaS and ZTNA capabilities. This enables organizations to modernize VPN infrastructure and join utilizing Cisco’s cloud answer, falling again to VPNaaS if ZTNA shouldn’t be potential. In follow, all customers have the identical expertise when connecting to purposes (legacy or fashionable, VPN-required or ZTNA-compatible) and the expertise takes care of the work behind the scenes.

In the case of VPNaaS use circumstances, organizations with ISE deployment can leverage the distinctive integration between Safe Entry and Cisco ISE to offer an additional layer of safety. Which means that when customers connect with VPNaaS, they’re protected by ISE’s authentication, posture evaluation, and community segmentation, all via a single agent — Safe Consumer.

We begin with VPNaaS and Cisco ISE working collectively and subsequent we add an additional layer of protection with one other type of authentication (that’s the place the “multi” in MFA is available in). Cisco Duo can provide RADIUS help for legacy VPNs via the Duo Authentication proxy by including servers to a company’s surroundings. However while you use Duo with ISE and VPNaaS, there’s a distinctive API integration that allows RADIUS authentication with out the necessity for the extra server in your surroundings. And all the top consumer sees is the standard Duo push that they’re used to when accessing cloud purposes.

Now, even when authenticating with RADIUS, customers have a seamless expertise, and organizations have layered safety to shut potential gaps within the assault floor.

Safe organizations with Consumer Safety Suite

Within the preferrred world, a company might shield all its assets utilizing essentially the most superior and fashionable expertise and protocols. Nonetheless, organizations have a variety of belongings that each one want safety, no matter how straightforward or laborious it’s to guard. When combining the community safety via Cisco ISE with Consumer Safety Suite instruments, Cisco can present the options you want at the moment whilst you proceed to modernize for the longer term. And permit CISOs to get a superb night time’s relaxation.

To be taught extra about how Cisco’s Consumer Safety Suite can shield your workforce, join with an professional at the moment.

Share:

Leave a Reply

Your email address will not be published. Required fields are marked *