Sie sind auf Seite 1von 4

Alcatel-Lucent Operating System for OmniSwitch LAN Switches

with Integrated CyberGatekeeper Solution

Alcatel-Lucent offers a seamless, secure and scalable enterprise network access control solution through its
embedded network security framework. This framework includes a comprehensive security solution for
verifying endpoint integrity through host integrity checking (HIC). The solution is the result of integration
between InfoExpress CyberGatekeeper and the Alcatel-Lucent OmniSwitch™ 6400 Stackable Gigabit LAN
Switch (SGS), the Alcatel-Lucent OmniSwitch 6850 Stackable LAN Switch (SLS) and any edge switches using
the Alcatel-Lucent Operating System™ (AOS), Release 6.3.4 or later.

Key features Key benefits The Alcatel-Lucent OmniSwitch families


of Stackable LAN Switches and
• Automatically manages the security • Ensures 100 percent of network InfoExpress CyberGatekeeper solution
fitness of endpoints endpoints are compliant (patch provide enterprise customers with a
• Operates independently of authen- levels, configurations and application comprehensive network access control
tication mechanism and network settings) or they are quarantined and HIC security layer. Enterprise LAN
access controls until remediated segments with the OmniSwitch 6400
• Integrates endpoint compliance • Separates authentication mechanism SGS and the OmniSwitch 6850 SLS
directly with the edge switch from security running AOS, Release 6.3.4 or later
¬ 802.1x not a requirement for HIC benefit from enhanced authentication
• InfoExpress CyberGatekeeper
and user-profile-enabled network access
integration with the Alcatel-Lucent ¬ Endpoints can be plugged into
control. Enterprise LAN segments with
OmniSwitch™ ensures endpoint device phones and still be secured
third-party switches are protected by
security policy compliance with quaran- • Will not interfere with existing VoIP InfoExpress CyberGatekeeper Dynamic
tine and remediation as required deployments Access Control (DNAC) technology.
• Enhanced security at the network • Keeps rogue devices off the network Wireless and VPN users are protected
edge with InfoExpress • Reduces vulnerabilities – Security by InfoExpress in-line appliances.
CyberGatekeeper HIC policy server solutions, OS and patches are assured
• Compatible with Microsoft®, to be running and up-to-date Please refer to the InfoExpress
Windows®, Mac®, Linux, mobile, • Lowers help desk costs – Automatic CyberGatekeeper data sheet for
PDA remediation of non-compliant PCs complete details on the InfoExpress
• Captive portal for web-based user • Improves security CyberGatekeeper product line.
authentication with configurable compliance/auditing scorecard
web page Through the integrated solution,
• Reduces risks associated with
• Agents are permanently installed enterprises ensure endpoint devices are
improperly configured computers
or provided on-demand verified to be compliant and healthy
• Integrates with existing patch when initially connecting to the net-
• Dynamic enforcement via access management solutions to preserve
control lists (ACLs), not VLAN or work. Only those endpoint devices that
software investments are compliant with enterprise security
IP address changes
• Reduces support costs by maintaining policies are allowed access to the
• Central policy management delivers standard configurations across production network. Those endpoint
consistent user experience desktops devices that fail the HIC are redirected
• Continuous surveillance of endpoint at the switch level by the Alcatel-Lucent
configuration
Access Guardian AOS feature, and tifies the corresponding user network endpoint device by both the permanent
allowed access only to the remediation profile (UNP), which is a security profile. agent and the web-based on-demand
servers. The HIC agent (permanently agent are defined on the InfoExpress
installed or provided on-demand) on UNPs allow the creation of easily CyberGatekeeper Policy Server using
the endpoint, in conjunction with the defined profiles that are mapped to the InfoExpress CyberGatekeeper Policy
InfoExpress CyberGatekeeper policy security policies. A profile may contain Manager. The policy server determines
server, attempts to update the endpoint. network, application, priority, band- whether the endpoint device has passed
Once compliant with security policies, width and compliancy rules based on or failed the HIC test and directly
the endpoint is allowed network access. a user’s role in the organization. The notifies the edge OmniSwitch 6400 SGS
As long as the endpoint is connected UNP is provided during authentication or OmniSwitch 6850 SLS to which the
to the network infrastructure, the HIC and rules are enforced immediately by device is connected. Traffic restrictions
agent provides continuous surveillance. the network switch. During this time, and redirections are processed by the
If the agent detects a violation of the the switch allows the endpoint limited Alcatel-Lucent Access Guardian AOS
security policies or is disabled or access to the network. Authentication feature, which integrates authentication,
terminated, the policy server will notify using 802.1X, MAC or web-based device compliance and network access
the switch, which in turn quarantines methods is not required, but can be control functions directly into the net-
the endpoint and allows access only added to provide more granular work infrastructure at the switch level.
to the remediation servers. control of the profiles.
If the OmniSwitch 6400 SGS or the
The OmniSwitch 6400 SGS/OmniSwitch Operation OmniSwitch 6850 SLS receives a HIC
6850 SLS/InfoExpress CyberGatekeeper pass status for the specified endpoint
solution is easy to deploy and maintain, When a user/device connects to an device, the switch dynamically applies a
requiring no network changes. enterprise network with HIC, the new set of ACLs that allow the endpoint
Installations can be done in hours endpoint device is required to undergo device access to the production network.
compared to those for most network a verification process. The switch
access control solutions that can take dynamically restricts network access If the OmniSwitch 6400 SGS or the
weeks or months. using ACLs, which only allow the OmniSwitch 6850 SLS receives a HIC
endpoint access to the InfoExpress fail status for the specified endpoint
User network profile CyberGatekeeper Policy Server and device, the switch dynamically applies
the remediation server(s). a restrictive set of ACLs that allow the
When a device initially connects endpoint to access the remediation
to the enterprise network edge, If the endpoint device has a permanent servers only.
the OmniSwitch 6400 SGS or the InfoExpress CyberGatekeeper Agent
OmniSwitch 6850 SLS authenticates installed, the agent communicates with If the endpoint device does not have
the user/device as defined by its Access the InfoExpress CyberGatekeeper Policy a permanent agent installed on it, the
Guardian policy. The OmniSwitch 6400 Server to assess the endpoint’s integrity. user is required to launch a browser
or OmniSwitch 6850 subsequently iden- The tests to be performed on the that is redirected to a customer-defined

Figure 1. OmniSwitch AOS - Embedded network security framework

Identity Integrity
Authentication Host integrity check
• Employee: 802.1x • Integrated HIC (CyberGateKeeper)
• Guest: captive portal static or on-demand agents
• IP phone: 802.1x or Mac-based
• Printer: port-based

Access guardian OmniSwitch embedded User network profiles


• Monitoring/audit trail network security • Role-based access including
framework VLAN, QoS, ACL

Visibility Privilege

AQM Traffic anomaly detection


• Quarantine and • Zero day attack
remediation

Isolation Threats control

2 Alcatel-Lucent Operating System for OmniSwitch LAN Switches with Integrated CyberGatekeeper Solution | Data Sheet
web server. From here the InfoExpress Figure 2. User network profile (UNP)
CyberGatekeeper web agent is automat- What?
ically downloaded onto the end-user’s RADIUS • This feature is to provide the capability to
have roles/profiles assigned to users during
device. This web agent communicates authentication
with the InfoExpress CyberGatekeeper • More than just a VLAN
Policy Server and performs an integrity UNP name • Eases implementation of central RADIUS
configuration
assessment. When complete, the agent • Scalable deployment with 8 distinct ACL/QoS
reports the endpoint’s status to the policy lists
policy server. If the endpoint complies UNP name attibuted:
• VLAN ID How?
with security policies, it is allowed • HIC flag • UNP name is stored in RADIUS and returned
access to the network. Otherwise it • QoS policy list to the switch
• The switch maps the UNP name to the actual
is directed to the remediation server profile attibutes
so it can be patched to meet security • Profiles determine
¬ VLAN ID (mandatory)
requirements. ¬ HIC flag (optional)
Guest user
¬ QoS/ACL Policy LIst Name (optional)
The endpoint HIC test is not a one-time
Employee Benefits
test; it is a periodic and continuous Simplify network access control management
process that provides constant surveil-
lance while the endpoint is connected the addition of the InfoExpress Simplifies network management
to the network. If at any time the CyberGatekeeper Policy Server, the
endpoint device fails the HIC test, its InfoExpress CyberGatekeeper Agent, The Alcatel-Lucent Access Guardian
access is automatically restricted to the and the creation of network security and InfoExpress CyberGatekeeper
remediation network. The InfoExpress policies. No modifications to the net- simplify network management of
CyberGatekeeper agent may be pre- work are needed, meaning deployment endpoints. The edge switch integrates
installed on Microsoft® Windows®, takes hours instead of days. authentication, device compliance and
Mac OS® X, or Linux® operating access control functions directly into
systems, or the user’s web browser can the hardware. Switch-based security
Saves time and money
be redirected to a download page to functions allow an administrator to
load a web-based on-demand version Once in place, the automated configure, manage and maintain the
of the agent. compliancy checking and updating entire security infrastructure more
means fewer support calls to apply efficiently and without additional
software upgrades and system patches. equipment. HIC provided by the
Easy to deploy
In addition, because each endpoint is InfoExpress CyberGatekeeper simplifies
The Alcatel-Lucent/InfoExpress solution more secure (endpoint access is restrict- network maintenance by automatically
is easily deployed. The authentication ed at the switch level until compliance managing the security fitness of
and HIC redirection are built into the is met), there is less chance of a endpoints.
Alcatel-Lucent Access Guardian, which security breach from malware being
is a function of the AOS, Release 6.3.4. introduced to the network.
Once turned on, all that is needed is
+
Figure 3 OmniSwitch + CyberGatekeeper integration

3 4
OmniSwitch 6400 or 6850 redirects traffic InfoExpress CyberGatekeeper policy server receives
to the InfoExpress CyberGatekeeper policy HIC report from CyberGatekeeper Agent and informs
server and the remediation servers the OmniSwitch 6400 or 6850 if the device has passed
or failed
2
OmniSwitch 6400 or 6850 provides
authentication and identifies user
profile. It ensures if HIC check
802.1x user is needed for this user InfoExpress
(802.1x, MAC, Captive Portal) CyberGatekeeper Remediation
1 Policy Server server(s)
Employee,
contractor or Regular
gular LAN u
user
guest connects 5
to the network OmniSwitch 6400 If HIC passed, OmniSwitch 6400 or 6850 selectively
or OmniSwitch 6850 Production allows device traffic to production network
Guest network following policy in user profile. If HIC failed,
OmniSwitch 6400 or 6850 restricts traffic to
remediation network only
Resident or on-demand agent
continuous surveillance

Alcatel-Lucent Operating System for OmniSwitch LAN Switches with Integrated CyberGatekeeper Solution | Data Sheet 3
Technical specifications
OmniSwitch products
supporting HIC integration
Alcatel-Lucent OmniSwitch 6400 SGS and OmniSwitch
6850 SLS families with AOS, Release 6.3.4 or later

CGS-1000 CyberGatekeeper Server Appliance


• Hardware revision: 1000-sm1a
• Software revision: 6.02 OS6400-24, OS6400-P24, and OS6400-P24H
• Compliance: RoHS, UL, FCC
• Power requirements: 5 A Max (100 V to 240 V
50/60 Hz, single power supply)
• Network interfaces: Dual 1000BT full duplex
RJ-45 (copper)
• Audit connections: Rated up to 10,000 for OS6400-48, OS6400-P48, and OS6400-P48H
policies with 500 audited conditions
• Enforcement modules:
¬ CGSI (HIC): Max 100 client switches
¬ EAP (RADIUS Proxy): Max 100 client switches
¬ Dynamic NAC: Max 200 managed subnets
¬ Bridge (in-line): Max 800 Mb/s (CGR-1000 OS6400-24U and OS6400-24UD
dedicated bridge enforcement)

CGM CyberGatekeeper Manager Software Suite


• Includes Policy Manager and Reporting Server
• Requires Microsoft Windows 2003 Server® and
Microsoft SQL Server® 2005/2008 database software
• Hardware specifications to support an implemen-
tation vary depending on total number of endpoints,
policy complexity, and data retention period. The
following sample configuration is provided only as
a guide for supporting a 3000-endpoint
implementation:

Web server (dedicated)


Windows 2003 Server SP1, IIS
• Processor and memory: Intel® Core™2 Quad 2.4 GHz, Non-PoE Models
3.0 GB of RAM OS6850-24
• Disk subsystem: RAID 5, 7200RPM disks, minimum OS6850-24X
80 GB for OS and application OS6850-48
OS6850-48X
PoE Models
Database SQL server (dedicated)
OS6850-P24
Windows 2003 (64-bit) Server SP1, SQL Server 2005/2008 OS6850-P24X
• Processor and memory: Intel Core 2 Quad 2.4 GHz, OS6850-P48
8 GB of RAM OS6850-P48X
• Disk subsystem: RAID 5, 7200 RPM disks, minimum Fiber Model
100 GB for DB OS6850-U24X
• Expected average database size: 45 GB

www.alcatel-lucent.com Alcatel, Lucent, Alcatel-Lucent and the Alcatel-Lucent logo


are trademarks of Alcatel-Lucent. All other trademarks are the property of their respective owners.
The information presented is subject to change without notice. Alcatel-Lucent assumes no responsibility
for inaccuracies contained herein. Copyright © 2009 Alcatel-Lucent. All rights reserved.
EPG3310090711 (07)

Das könnte Ihnen auch gefallen