Ruckus Cloudpath Control de acceso inteligente Juan Grau

  • Slides: 23
Download presentation
Ruckus Cloudpath: Control de acceso inteligente Juan Grau – Iberia PAM Felix Martos –

Ruckus Cloudpath: Control de acceso inteligente Juan Grau – Iberia PAM Felix Martos – Iberia SE RUCKUS WIRELESS PROPRIETARY AND CONFIDENTIAL

Few Wi-Fi Devices Nice-To-Have IT Service Disconnects Tolerated More & More Devices Mission Critical

Few Wi-Fi Devices Nice-To-Have IT Service Disconnects Tolerated More & More Devices Mission Critical Make It Work, Always

Control Your Connections Challenges in Need of Control 3 RUCKUS PROPRIETARY AND CONFIDENTIAL stress-free

Control Your Connections Challenges in Need of Control 3 RUCKUS PROPRIETARY AND CONFIDENTIAL stress-free security complaint-free connectivity hassle-free administration Hoping your weak security is never exposed? Cloudpath will allow you to relax. Complement your performanceoptimized access with user-friendly accessibility. Overworked? Let your network for you with self-service features. Take a break already.

Onboarding Becoming More Critical, Complex More Devices Fundamental Shifts Chromebooks, Tablets, Phones, MAC BYOD

Onboarding Becoming More Critical, Complex More Devices Fundamental Shifts Chromebooks, Tablets, Phones, MAC BYOD and Owned Windows Domain, IT-owned More Users o Large Growth in Devices & Users o “Wi-Fi First” Approach of Connectivity Drivers Of Growth o BYOD (All Device Types) o Managed Devices o Higher User Adoption

Policy Management Policy. A Policy. B Policy. C Policy. D ✔ ✔ ✔ ✔

Policy Management Policy. A Policy. B Policy. C Policy. D ✔ ✔ ✔ ✔ ✔ Flexible Policy and Workflow decisions based on… policy. A policy. B policy. C policy. D 1. IT-Owned vs BYOD 2. Corporate vs Guest 3. Device OS Type 4. User authorization domain Student User BYOD Staff User IT-Owned Student User IT-Owned Staff User BYOD 5. Certificate status 6. Role Based Access 7. Much more… 5 © 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. INTERNAL USE ONLY

Device Enablement Device Posturing & Remediation Verify the device before getting it onto the

Device Enablement Device Posturing & Remediation Verify the device before getting it onto the network; enable Firewall, check for antivirus & windows updates install custom app and more. Google Console Integration Deploy The Cloudpath Extension Via The Google Console For Hands-Free Certificate Installation. User, IT, or Distributor Provisioned Flexibility To Allow Secure & Efficient Workflows For Various Provisioning Models. Onboard or Pre-board. Integration with MDM vendors Use the inbuilt light MDM or integrate with full blown MDM provider

Certificate Management 1 2 ✔ ✔ ✔ ✔ ✔ 3 Unique Manageable Secure Non-Stop

Certificate Management 1 2 ✔ ✔ ✔ ✔ ✔ 3 Unique Manageable Secure Non-Stop Unique certificates on each device allows policies, including VLANs, ACLs, and more, to be applied on -the-fly with certainty. Visibility into each device, control over policies, and the ability to remove devices allows Wi-Fi to be managed easily. Simply the goldstandard in security. Connectivity is not disrupted by password changes, allowing Wi-Fi to finally be set-it-and-forget-it simple.

One Size Fits All Easily buildable workflows Simple Sophisticated Complex

One Size Fits All Easily buildable workflows Simple Sophisticated Complex

Flexible Deployment Platform • Public Cloud • On-Premise Identity • Inbuilt • AD, LDAP

Flexible Deployment Platform • Public Cloud • On-Premise Identity • Inbuilt • AD, LDAP • Social Login Oauth 2. 0 Radius • Inbuilt • External Certificate Authority • Inbuilt • Microsoft Access Network • Wireless – Vendor Agnostic • Wired – Vendor Agnostic

Full-Service Platform Integration Ruckus Cloudpath RADIUS PKI Device Provisioning User Database Integration Device Management

Full-Service Platform Integration Ruckus Cloudpath RADIUS PKI Device Provisioning User Database Integration Device Management Guest Access Services Policy Engine Integrated Platforms 1. RADIUS – efficient and flexible 802. 1 X connectivity 2. PKI – certificate management has never been this easy 3. Client Provisioning – support for all client OS types 4. User DB Integration – integrate with existing user databases/CAs 5. Device Management – enforce device-specific settings for antivirus, firewall, passcodes, NAC, proxies 6. Guest Access – secure or traditional self-service guest 7. Policy Engine – enforce custom user and device privileges

APIs Allow 3 rd Party Integration Firewall Antivirus Switch MDM Io. T Wireless Network

APIs Allow 3 rd Party Integration Firewall Antivirus Switch MDM Io. T Wireless Network

Solution Partners Firewall Cloudpath sends user identity to Palo Alto, enabling granular traffic policing

Solution Partners Firewall Cloudpath sends user identity to Palo Alto, enabling granular traffic policing Roaming Network Cloudpath secures devices using 802. 1 X, making them eduroam-ready Chromebook MDM Content Filter Streamline Chromebook authentication Filter IT-owned vs BYOD with appropriate policies; Single CA for all devices Enable the CF to filter encrypted/https content

Broad Client support 10. 7 & higher 4. 3 & higher XP & higher

Broad Client support 10. 7 & higher 4. 3 & higher XP & higher 6 & higher 12. 04 & higher 18 & higher

Self-Service Onboarding Day 1 BYOD Devices • • • Employees Students/Faculty Contractors Partners/Vendors Guests

Self-Service Onboarding Day 1 BYOD Devices • • • Employees Students/Faculty Contractors Partners/Vendors Guests Day 2+ Self-Service Onboarding Portal For All Users, All Devices Wi-Fi “Just Works” • Automatically Connects • No Splash Page IT Devices • Managed Chromebooks • IT-Owned Mac. Books • IT-Owned Mobile Devices • Scanners • Printers 14 • Fully Authenticated • Policies Via VLANs, ACLs, etc • Fully Encrypted Session

End-User Experience Day 1 Experience 15

End-User Experience Day 1 Experience 15

Day 2 Experience Wi-Fi “Just Works” o Automatically Connects o No Splash Page o

Day 2 Experience Wi-Fi “Just Works” o Automatically Connects o No Splash Page o Fully Authenticated via Certificate o Policies Applied Dynamically using WPA 2 -Enterprise o Fully Encrypted Session 16

Self-Service Onboarding 17

Self-Service Onboarding 17

Integration with Wired Features and Capabilities: Internet 3 User/Device based Dynamic VLAN, ACL 2

Integration with Wired Features and Capabilities: Internet 3 User/Device based Dynamic VLAN, ACL 2 • 802. 1 X authentication • MAC authentication • External Web authentication • Flexible Authentication 4 Flexible Authentication 802. 1 X & MACauth 4 sequence (802. 1 X, MACauth) Guest VLAN • Remediation for non compliant devices Intranet 1 • Co. A (ACL, disconnect, flip port, disable port, re-auth) © 2016 BROCADE COMMUNICATIONS SYSTEMS, INC. All Rights reserved.

Administrator UI 19

Administrator UI 19

Graphic banner can be added here Bar colour T&C text customised Any background can

Graphic banner can be added here Bar colour T&C text customised Any background can be added. This example has a full screen image RUCKUS WIRELESS PROPRIETARY AND CONFIDENTIAL Button text and colours

Cloudpath At A Glance Securely Simple Automated Onboarding Zero-To-Gold Standard Security In Minutes For

Cloudpath At A Glance Securely Simple Automated Onboarding Zero-To-Gold Standard Security In Minutes For Administrators And Users. Self-Service Portal Automatically Provisions Devices For Network. Certificate Infrastructure Rich Policy Control Policy-Enabled Certificates Tie User, Device, and Policy Together Without Passwords. VLANs, ACLs, & Policies Based On User, Groups, Device & More Give Per-Device Control. RADIUS Applies Policies To Certificate & MAC Authentications Without Traditional RADIUS Complexities. Device Visibility Tracks Who, What, & Why Of Every Device On Your Network. 21 RUCKUS PROPRIETARY AND CONFIDENTIAL Cloudpath Plug & Play Solution For Delivering Certificate-Based Wi-Fi To BYOD, Guest, And IT Devices. Broad Device Support i. OS, Android, Chrome. OS, Mac OS X, Windows, Linux & More. Wi-Fi Reliability Eliminates Password-Related Disconnects, Support Costs, and Security Problems.

Comparing with Others Cloudpath Others 1. No cloud offering 1. Cloud everything 2. No

Comparing with Others Cloudpath Others 1. No cloud offering 1. Cloud everything 2. No native Google Console support 2. Easiest Chromebook onboarding in the business 3. No multi-tenancy: not for MSPs 4. Separate charge-for modules 5. Partially WLAN-vendor agnostic 6. Moderately to highly complex UI 7. Device-based licensing 8. Requires bespoke PS engagement 3. MSP-ready multi-tenancy 4. One all-inclusive price 5. WLAN-vendor agnostic 6. Simple workflows 7. User-based licensing 8. Out-of-the-box or “white glove” © 2016 BROCADE, INC. BROCADE CONFIDENTIAL INFORMATION

GRACIAS Thank you! www. ruckuswireless. com 23 RUCKUS PROPRIETARY AND CONFIDENTIAL facebook. com/ruckuswireless @ruckuswireless

GRACIAS Thank you! www. ruckuswireless. com 23 RUCKUS PROPRIETARY AND CONFIDENTIAL facebook. com/ruckuswireless @ruckuswireless