,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. 2

Similar documents
BIG‑IP Access Policy Manager | F5 Datasheet

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

ScreenOS 5.0 ScreenOS 5.0 Deep Inspection VLAN NetScreen-25/-50/-204/-208 HA NetScreen-25 HA Lite NetScreen-25 NetScreen-50) ALG(Application Layer Gat

One Core, One Windows Windows Xbox 360 Xbox One Windows 8 Windows 8.1 OS Windows Phone 8.1 Windows Phone 8 OS OS Devices + IoT Adaptive User Interface

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

Campus LAN Design Guide

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

アライドテレシス ディストリビューション・スイッチ AT-x600シリーズで実現するMicrosoft® NAP

AirMac ネットワーク for Windows

契約№2020-XXXX

Dec , IS p. 1/60

スライド 1

iPhone/iPad/Android(TM) とベリサイン アイデンティティプロテクション(VIP)エンタープライズゲートウェイとの組み合わせによるL2TP+IPsecのワンタイムパスワード設定例

AirMac ネットワーク構成の手引き

All Rights Reserved, Copyright FUJITSU LIMITED All Rights Reserved, Copyright FUJITSU LIMITED

1 Microsoft Windows Server 2012 Windows Server Windows Azure Hyper-V Windows Server 2012 Datacenter/Standard Hyper-V Windows Server Windo

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

Aventail EX-2500/1600/750 STv(Ver.8.9) Sep 2007 c 2007 SonicWALL,Inc. All rights reserved.

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

Microsoft Global Briefing Technical Briefing

Part 1 IT CPU IT IT 1998 Windows NT Server 4.0, Terminal Server Edition 1 Windows Based Terminal WBT Windows CE 1 100Mbps 1Gbps LAN OS 1 PC 1 OS 2

Windows PC/ BCP () PC (BYOD: Bring Your Own Device) Windows 8 2 Windows 8 Windows 8 Windows Windows 8 Windows 8 Windows 8 PC/ 2

VNSTProductDes3.0-1_jp.pdf

LAN

FileMaker Server 9 Getting Started Guide

"CAS を利用した Single Sign On 環境の構築"

Oracle Identity Managementの概要およびアーキテクチャ

Faronics Core User Guide

DS_BIG-IP LTM VE_jp.indd

FileMaker Server Getting Started Guide

ガイドブック

雲の中のWebアプリケーション監視術!~いまなら間に合うクラウド時代の性能監視入門~

ScreenOS 6.0 のご案内 平成 21 年 3 月 ノックス株式会社 ノックス株式会社ネットワーク事業部 Copyright (C) 2009 NOX Co., Ltd. All Rights Reserved.

CP_SBA_Catalog2012_ indd

FileMaker Server 8 Administrator’s Guide

untitled

P2P? ( )? ( SOX ) ( ) COPYRIGHT 2005 SSH COMMUNICATIONS SECURITY CORP. ALL RIGHTS RESERVED. 2

Testing XML Performance

"CAS を利用した Single Sign On 環境の構築"

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi

クララパンフレット2011冬1P-P40

Cisco Aironet 1130AG アクセス ポイント クイック スタート ガイド

モバイルプリペイド決済の実現モデルの調査研究

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.

VMware Horizon

<Documents Title Here>

HP ELITE x3 初めてガイド

IPSEC-VPN IPsec(Security Architecture for Internet Protocol) IP SA(Security Association, ) SA IKE IKE 1 1 ISAKMP SA( ) IKE 2 2 IPSec SA( 1 ) IPs

SRX300 Line of Services Gateways for the Branch

IP IP DHCP..

ISE 2.1 および AnyConnect 4.3 ポスチャ USB チェックの設定

HP MSM Controller シリーズ

内閣官房情報セキュリティセンター(NISC)

NIC Reference Guide

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Detroit, US Tokyo, JP Boulder, US TJ Watson, US Tokyo, JP Atlanta,

Configuration Manager (SCCM) + IT IT PC IT PC PC Windows XP OS 移行は簡単! P.7 SCCM / SCCM PC OS Configuration Manager PC PC 2

3 4 iphone BIG-IP 5 F5 BIG-IP Edge

Windows 10 Windows 10 IT Windows 10 MSDN Windows 10 Pro Windows 10 Enterprise Microsoft Store Windows 10 Pro MSDN Windows 10 Pro Windows 10 Enterprise

1 / 1 idrac8 CPU 1 Intel Xeon E v5 Intel Pentium Intel Core i3 Intel Celeron Intel C236 Microsoft Windows Server 2008 R2 SP1 Microsoft Windows S

Mac OS X Server Windows NTからの移行

SSO Sales/Tech combined webinar template


Si-R180 ご利用にあたって

Microsoft Word - PSB導入ガイド_ docx

実施していただく前に

Windows7移行ガイド

WS_EOS_user_Web

8 PC CoIT (Consumerization of IT) BCP () PC BYOD (Bring Your Own Device) BYOD IT IT IT IT PC/ 2

Oracle Application Server 10g(9

Microsoft PowerPoint - NetScreen-RA 500.ppt

FW Migration Guide(ipsec1)

Cisco WebEx ホワイトペーパー: リアルタイムコラボレーションのパワーを解き放つ: Cisco WebEx ソリューションのセキュリティ概要

meraki-datasheet-mx

Cisco Identity Services Engine Supported Mac OS X AV/AS Products Version

帯域を測ってみよう (適応型QoS/QoS連携/帯域検出機能)

Zurich, CH Brussels, BE Wrocław, PO Toronto, CA Ottawa, CA Herzliya, IL Almaden, US Boulder, US Detroit, US TJ Watson, US Tokyo, JP Tokyo, JP Atlanta,

Security Guide

<834E C F D E657073>

untitled

FW Migration Guide(ipsec2)

ISMSクラウドセキュリティ認証の概要

Microsoft Enterprise Mobility License

SSG5 and SSG20 Secure Services Gateways

82801pdf.pqxp

Junos Space

fusion.PDF

FortiNAC データシート

PowerPoint プレゼンテーション

ウイルスバスター2012 クラウド ガイドブック

KASPERSKY ENDPOINT SECURITY FOR BUSINESS IT IT IT IT IT Kaspersky Endpoint Security for Business IT IT IT IT 2013 NAC Advanced 2013 Select Select Work

PowerPoint Presentation

PRIMEPOWER / PRIMERGY Interstage 1

<Documents Title Here>

iR C3580/C3580F、iR C3080/C3080F 製品カタログ

11U Dell CPU RAID 1U 1 Intel Xeon E v5 Intel Pentium Intel Core i3 Intel Celeron Intel C236 Microsoft Windows Server 2008 R2/2008 R2 SP1 Standar

FUJITSU Network SR-M コマンド設定事例集

<Documents Title Here>

Oracle Application Server 10g( )インストール手順書

mvd_nas_2.0.5_release_notes_v1_ja.doc

Transcription:

NAC Advanced Technologies Business Development Manager Toru Konno toruk@juniper.net v1.81 Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 1

,,, J-SOX ISMS PCIDSS,, IM/VoIP/VoD Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 2

Network Access Control NAC Network Access Control) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 3

NAC Overview 802.1x 802.1x In Line In VPN Line VPN SSL, SSL, IPSec IPSec DHCP DHCP Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 4

Juniper s UAC Overview - Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 5

Juniper UAC UAC UAC x Pre-Admission Post-Admission Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 6

UAC Policy Manager ( ) (PC Agent ( ) Firewall &.1X Devices ( ) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 7

UAC Infranet Enforcer ( ): Infranet Agent ( ): (A.K.A Odyssey Access Client) Personal Firewall VPN IEEE802.1X IC 25 Infranet Controller ( ): IA IE IA Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 8

Infranet Enforcer (IE) Juniper Network Enforcer (Application Base): NetScreen SSG/ISG IC Juniper Enforcer IEEE802.1X Enforcer (VLAN Base): IEEE802.1X IEEE802.1x VLAN Host Enforcer (Application Base): Agent FW Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 9

Infranet Agent (IA) OS Windows2000/XP/Vista/MAC OS/Linux/Solaris) Agent Agent-Less HostChecker PC AntiVirus/windows update HostEnforcer FW) IPSec IEEE802.1X Windows /GINA TNC (IMC-IF ) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 10

Infranet Agent IA Host Checker Juniper OS Windows TCP/UDP / MD5 NetBIOS PC MAC Address PC MAC Address TNC Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 11

Infranet Agent (IA) IPsec Tunnel IPsec IPsec IE NAT Traversal NAT IPsec Firewall (IE) Agent (IA) IA IE IPsec * IPSec Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 12

Infranet Agent (IA) Windows Shavlik Microsoft Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 13

Infranet Agent (IA) Auto-Remediation Windows 2000/XP/Vista Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 14

Infranet Agent (IA) Agent-less IE IC IC IC IA Active-X/Java IA Agent (IA) Firewall (IE) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 15

Infranet Agent vs Agent-Less Full Agent Mode OS Windows2k, XP Persistent Agent Mode MAC Linux Agent-less Mode UAC OS Full Agent Mode Linux Solaris, MAC OS 2008 Q4).1X Supplicant IPsec Tunnel Patch Management Host Checker Host Enforcer Auto remediation Full Agent Mode (Windows2K, XP) Yes Yes Yes Yes Yes Yes Persistent Agent Mode (MAC, Linux) No No No Yes No No Agent-less Mode (All) No No *Yes Yes No **Yes *Agent-Less Windows ** Agent-Less Auto Remediation Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 16

Infranet Controller (IC) UAC IA IE IA Pre (RADIUS, Active Directory, LDAP, RSA, PKI, OTP NIS SSO) TNC (IMV-IF ) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 17

Infranet Controller (IC) UAC SSG UTM *SBR RADIUS EX 802.1x TCG/TNC IMV-IF TCG/TNC NAP *Steal Belted Radius: Juniper Networks Radius Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 18

Infranet Controller (IC) Role VLAN Policy Role Role VLAN Role Resource Policy Resource Policy Resource VLAN ACL QOS Agent (IA) User ID: ToruK PASS: a5gtrm9 (IC) Resource Resource Resource (IE) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 19

Infranet Controller (IC) 30,000 1 15,000 (IA) L2(IE) 1024 L3(IE) 128 IA IC6500 High Availability/Scalability 8 Active-Active, Active-Standby HDD 5,000 1 5000 (IA) L2(IE) 512 L3(IE) 64 IA IC4500 High Availability/Scalability ( 2 Active-Standby http://www.juniper.co.jp/products_and_services/unified_access_control/ Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 20

Security Solutions Around UAC- Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 21

IdM Juniper Unified Access Control 802.1x SIEM In Line VPN SSL, IPSec Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 22

UAC UAC SA L2 EX.1X IA NSM + STRM L3 NS/SSG/ISG L3 IDP Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 23

UAC Identity Management NAP Patch Management and Remediation PKI Directory Managed PKI LDAP/RADIUS/SDI.1X Support Devices OTP SSO IEEE 802.1x Host Checker Syslog Syslog Binary integlity Integrated Compliance Endpoint Security TPM Solution Security Information & Event Management (SIEM) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 24

Deployment Scenario - Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 25

UAC A Policy Manager (IC) Agent (IA) (PC Firewall (IE) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 26

UAC B Policy Manager (IC) Firewall Agent Java/Active-X Firewall (PC (IE) Agent-less (IA) Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 27

UAC Policy Manager (IC) (PC + 802.1X Devices IE Agent (IA) 802.1X VLAN.1X EAP Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 28

UAC D Policy Manager (IC) (PC + 802.1X Devices IE) Agent (IA) 802.1X VLAN Agent (IA).1X EAP Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 29

UAC E Policy Manager (IC) (PC + Agent (IA) Host Enforcer Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 30

UAC F TCG-TNC API Radius, LDAP, AD, OTP, PKI, SAML Policy Manager (IC) (PC Firewall (IE) PKI Agent (IA) 802.1X Devices IE) TCG-TNC API Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 31

Deployment Scenario - Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 32

企業ネットワーク環境でのUAC使用例 HQ Administration Room Enterprize HQ DC Data Center SOHO/Small Branch/ Mobile Users Branch Office Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 33

HQ Dynamic VLAN Multi-Supplicant Unmanaged device DNS/DHCP, etc Network Printer UAC Agent (Supplicant) Host Checker Personal Firewall UAC Agent (Supplicant) Host Checker Personal Firewall Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 34

HQ L3/4 enforcement UTM dynamic control URL Redirect Local Servers UAC Agent (Agent-Less mode) Host Checker UAC Agent (Agent-Less mode) Host Checker Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 35

HQ Working with ext IdM Looking up attributes HQ DC L3/4 enforcement IDP Module User information stored Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 36

HQ Branch L3/4 enforcement UTM Local Servers UAC Agent Host Checker Host Enforcer UAC Agent (Agent-Less mode) Host Checker Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 37

Employee remote access SSL VPN HR Sales Home Workers Mobile Workers Extranet access SSL VPN Business Partners Finance Customers Department Servers SSL-VPN (Core, Sum, NC) SVW, etc Host Checker L2-7 enforcement Authentication Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 38

Secure Access (SA) 30,000 1 10,000 SSL IC6500 High Availability/Scalability 4 Active-Active, Active-Standby HDD 100/1,000 1 1,000 / SSL IC2500/4500 High Availability/Scalability 2 Active-Active, Active-Standby http://www.juniper.co.jp/products_and_services/ssl_vpn_secure_access/ Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 39

Juniper UAC UAC 2005 Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 40

Copyright 2008 Juniper Networks, Inc. www.juniper.co.jp 41