Cisco ISE for BYOD and Secure Unified Access (Paperback)
暫譯: Cisco ISE 在 BYOD 和安全統一訪問中的應用 (平裝本)

Jamey Heary, Aaron Woland

相關主題

商品描述

Plan and deploy identity-based secure access for BYOD and borderless networks

 

Using Cisco Secure Unified Access Architecture and Cisco Identity Services Engine, you can secure and regain control of borderless networks in a Bring Your Own Device (BYOD) world. This book covers the complete lifecycle of protecting a modern borderless network using these advanced solutions, from planning an architecture through deployment, management, and troubleshooting.

 

Cisco ISE for BYOD and Secure Unified Access begins by reviewing the business case for an identity solution. Next, you’ll walk through identifying users, devices, and security posture; gain a deep understanding of Cisco’s Secure Unified Access solution; and master powerful techniques for securing borderless networks, from device isolation to protocol-independent network segmentation.

 

You’ll find in-depth coverage of all relevant technologies and techniques, including 802.1X, profiling, device onboarding, guest lifecycle management, network admission control, RADIUS, and Security Group Access.

Drawing on their cutting-edge experience supporting Cisco enterprise customers, the authors present detailed sample configurations to help you plan your own integrated identity solution. Whether you’re a technical professional or an IT manager, this guide will help you provide reliable secure access for BYOD, CYOD (Choose Your Own Device), or any IT model you choose.

 

  • Review the new security challenges associated with borderless networks, ubiquitous mobility, and consumerized IT
  • Understand the building blocks of an Identity Services Engine (ISE) solution
  • Design an ISE-Enabled network, plan/distribute ISE functions, and prepare for rollout
  • Build context-aware security policies
  • Configure device profiling, endpoint posture assessments, and guest services
  • Implement secure guest lifecycle management, from WebAuth to sponsored guest access
  • Configure ISE, network access devices, and supplicants, step-by-step
  • Walk through a phased deployment that ensures zero downtime
  • Apply best practices to avoid the pitfalls of BYOD secure access
  • Simplify administration with self-service onboarding and registration
  • Deploy Security Group Access, Cisco’s tagging enforcement solution
  • Add Layer 2 encryption to secure traffic flows
  • Use Network Edge Access Topology to extend secure access beyond the wiring closet
  • Monitor, maintain, and troubleshoot ISE and your entire Secure Unified Access system

 

商品描述(中文翻譯)

計劃和部署基於身份的安全訪問,以應對自帶設備(BYOD)和無邊界網絡

使用 Cisco Secure Unified Access Architecture 和 Cisco Identity Services Engine,您可以在自帶設備(BYOD)的世界中保護和重新掌控無邊界網絡。本書涵蓋了使用這些先進解決方案保護現代無邊界網絡的完整生命周期,從架構規劃到部署、管理和故障排除。

《Cisco ISE for BYOD and Secure Unified Access》首先回顧了身份解決方案的商業案例。接下來,您將學習如何識別用戶、設備和安全狀態;深入了解 Cisco 的 Secure Unified Access 解決方案;並掌握保護無邊界網絡的強大技術,從設備隔離到協議獨立的網絡分段。

您將發現所有相關技術和技術的深入介紹,包括 802.1X、設備剖析、設備入網、訪客生命周期管理、網絡接入控制、RADIUS 和安全組訪問。

作者基於支持 Cisco 企業客戶的前沿經驗,提供詳細的示範配置,幫助您規劃自己的集成身份解決方案。無論您是技術專業人員還是 IT 經理,本指南將幫助您為 BYOD、CYOD(選擇自己的設備)或您選擇的任何 IT 模型提供可靠的安全訪問。

- 回顧與無邊界網絡、無處不在的移動性和消費化 IT 相關的新安全挑戰
- 了解身份服務引擎(ISE)解決方案的基本組件
- 設計 ISE 啟用的網絡,規劃/分配 ISE 功能,並為推出做好準備
- 建立上下文感知的安全政策
- 配置設備剖析、端點狀態評估和訪客服務
- 實施安全的訪客生命周期管理,從 WebAuth 到贊助訪客訪問
- 逐步配置 ISE、網絡接入設備和客戶端
- 進行分階段的部署,以確保零停機時間
- 應用最佳實踐以避免 BYOD 安全訪問的陷阱
- 通過自助入網和註冊簡化管理
- 部署安全組訪問,Cisco 的標籤強制解決方案
- 添加第二層加密以保護流量
- 使用網絡邊緣接入拓撲將安全訪問擴展到配線櫃之外
- 監控、維護和故障排除 ISE 及整個 Secure Unified Access 系統