About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Evolve to Cloud-Enforced Security to Empower Your Anywhere Workforce Jeff Scheaffer on October 26, 2023 at 3:00 pm

Part 4 of the six-part series – The 2023 Global Networking Trends Report series

The next generation of enterprise architecture has arrived. Organizations are moving away from a complex patchwork of b… Read more on Cisco Blogs

Part 4 of the six-part series – The 2023 Global Networking Trends Report series

The next generation of enterprise architecture has arrived. Organizations are moving away from a complex patchwork of best-of-breed point solutions to a single-vendor strategy for a more consistent, secure networking platform that allows their distributed workforce to access hybrid cloud and multicloud applications more efficiently, reliably, and securely.

In recent years, the software-defined WAN (SD-WAN) has been favored for its ability to enhance network performance, optimize connectivity, and provide centralized policy control and management. Thanks to advanced traffic management and optimization techniques, SD-WAN enables IT teams to provide users with a more seamless and predictable experience anywhere they work.

As for securing those experiences, 59% of respondents to our 2023 Global Networking Trends Report said their top cloud-access networking priority over the next two years is to centralize security in the cloud to provide a consistent policy across users and devices located anywhere. That requires security service edge (SSE), an overlay of protective services for the web, cloud services, and private applications.

Gartner predicts that by 2026, 85% of organizations looking for a cloud access security broker (CASB), secure web gateway (SWG), or zero trust network access (ZTNA) will obtain these from a converged solution rather than from separate vendors. Here is a look at why cloud-enforced and converged security with an SSE platform is so effective, along with a look at the different types of SSE offerings companies can deploy today.

Complexity is the enemy of great experiences

Once, organizations had workforces in one office location or a headquarters with maybe a few satellite locations. Secure access to business-critical applications was easily monitored, managed, and enforced.

Two decades into the 21st century and one pandemic later, that ship has sailed. Exceptional experiences, anywhere, anytime, on any device, are expected. Providing security from application to endpoint, however, has proven to be extremely challenging as workers, applications, networks, clouds, and security solutions extend far beyond traditional office walls and data centers.

Security policies used for remote workers, for example, SD-WAN and a secure access service edge (SASE) model with SSE, are underway. You can see how organizations regard this transition in our 2023 Global Networking Trends Report, as shown in Figure 1 with a two-year trend showing an evolution in providing secure access.

Figure 1. How organizations are planning to support user access to cloud-based applications over the next two years

Finding your way to SSE and SASE

SASE is designed specifically to support the types of hybrid working models we are seeing today, where people, places, and things (such as Internet of Things and operational technology initiatives) are now highly distributed. SASE includes a set of services that describe network and security requirements for quality of experience—including access policies, performance and availability metrics associated with a network, and interaction with edge endpoints. SD-WAN plus SSE equals a SASE framework (see Figure 2).

Figure 2. A cloud-enforced SSE is one half of a comprehensive SASE architecture

Today, SASE architectures come in two major varieties: modular and unified. IT departments with separate NetOps and SecOps teams may want to go the modular route, which offers a converged cloud security SSE solution with a single dashboard (unified policies, single agent, and single SLAs), integrated with an SD-WAN solution with its own dashboard. In a modular approach, these SSE and SD-WAN solutions are single- or multi-vendor solutions. However, single-vendor solutions are advised to allow for simpler integration and management and less security risk.

Taking the single-vendor route a step further, another option is a unified SASE solution with fully converged SSE and SD-WAN managed through a unified dashboard for common policy services and controls.

According to a recent article in Forbes, Gartner predicts that by 2026, 65% of organizations will have consolidated individual components of SASE into a solution delivered by one or two vendors. In the same article, Gartner also predicts 50% of new SD-WAN purchases will be based on a single-vendor solution.

How organizations are approaching SSE and SASE today

Here are the top options I’m seeing customers pursuing:

Organizations are adding SSE to their SD-WANs—evolving from centralized, point security solutions to cloud-enforced security.

We are seeing this especially among our customers with branch offices, adding SSE to their SD-WANs to enhance their security postures. Some organizations may have some of the components of SSE already, like next-generation firewalls. But a full SSE―especially where all pieces are integrated into a single vendor offering―delivers benefits like the zero-trust model in ZTNA to protect against internal and external threats, gain end-to-end visibility, and improve user and IT experience.

Organizations are adding SSE to move from VPN logins to a ZTNA environment.

ZTNA within SSE provides a security model where users and devices are granted access to the specific applications and resources they need to avoid over-privilege and the risks from lateral movement. Cisco provides a modern approach to ZTNA that enables least-privileged access to all application types in a “no-friction” format that delivers a more seamless user experience and simplified IT management. Innovative support for both new and traditional protocols, as well as continuous posture checking and user experience insights, help to mitigate risk while improving end-user productivity.

Organizations are adding SSE to shrink the architectures and WAN backbones of their branches and single offices.

A small office in a strip mall has different needs than a manufacturing plant. Small offices do not need expensive Multiprotocol Label Switching (MPLS) WAN backbones. They can use internet fiber, 5G, or broadband—plus SSE for security, including ZTNA. Branch locations, on the other hand, are more likely to need an MPLS backbone to ensure the organization’s WAN has the bandwidth to support a wide range of data transport technologies.

Cloud-enforced security in action

One of the largest universities in Australia, Deakin University, has up to 100,000 devices and users connecting to its network each day. By moving to a cloud-enforced security environment, Deakin consolidated cloud, endpoint, email, and firewall security into an integrated platform with end-to-end visibility. The new security posture reduced investigation and response times from weeks to minutes.

Marine Credit Union, which serves 90,000 member employees of Mercury Marine, a Wisconsin-based manufacturer of outboard motors, shows the benefits that can be achieved with an enterprise-wide, cloud-based security solution. The small IT team deployed cloud-enforced, integrated security features to provide cloud security, endpoint security, firewall, malware analytics, and detection and response. Marine Credit Union said this approach has made management much easier and contributed to consistently great, secure experiences for member users.

Secure and seamless user experiences are possible—with anywhere access and tight security controls—thanks to a cloud-enforced SSE. How do you choose one? Start by considering the benefits of SSE with tightly integrated solutions from a single, leading vendor. Partnering with the right vendor enables you to create a more consistent and efficient secure networking platform over time, and to protect your people, places, and things, wherever they are.

Watch the Global Networking Trends on-demand webinar:

“Securely connect people, places, and things in an ever-changing world”

Download the 2023 Global Networking Trends Report

Share

  The next generation of enterprise networking architecture is here. Organizations are moving to cloud-enforced security with security service edge (SSE) to optimally connect and secure the distributed workforce.  Read More Cisco Blogs 

By |2023-10-26T20:53:25+00:00October 26, 2023|Cisco: Learning|0 Comments

SD WAN solutions for utility Distribution Automation Marcus Smith on October 25, 2023 at 3:30 pm

Networks are expanding outside traditional office buildings and into industrial fixed and mobile use cases. This results in more devices being connected to the Internet and data centers as well as… Read more on Cisco Blogs

Networks are expanding outside traditional office buildings and into industrial fixed and mobile use cases. This results in more devices being connected to the Internet and data centers as well as increased security exposure. IoT has moved traditional networking far beyond the carpeted spaces and into industries like Fleets, Oil & Gas, Energy & Water Utilities, Remote Condition Monitoring and Control — basically anything that can establish a wide area connection. Moreover, these industrial networks are increasingly being considered critical infrastructure. In response to this expansion, Cisco has on-going innovations advancing the ways networks operate – and at the forefront of these trends is the way that SD WAN solutions enable and support industrial use cases.

Cisco Catalyst SD-WAN today is already an industry-leading wide area network solution offering a software-defined WAN solution that enables enterprises and organizations to connect users to their applications securely. It provides a software overlay that runs over standard network transports, including MPLS, broadband, and Internet, to deliver applications and services. The overlay network supports on-premises solutions but also extends the organization’s network to Infrastructure as a Service (IaaS) and multi-cloud environments, thereby accelerating their shift to the cloud.

Most utilities are used to building large networks utilizing technologies such as Internet Protocol Security (IPsec) and Dynamic Multipoint Virtual Private Network (DMVPN) to encrypt critical communications, Multiprotocol Label Switching (MPLS) for the underlying transport network, and public or private cellular for remote sites with no other WAN connectivity. Catalyst SD-WAN brings these technologies together and enables automation to greatly simplify deployments.

Automation benefits:

Secure Zero Touch deployment of field gateways (i.e., no field staff required to configure a gateway)
Simple provisioning of end-to-end service VPNs to segment traffic (SCADA, CCTV, PMU, IP Telephony, etc.)
Templated configurations making it easy to change configurations at scale and push it to gateways in the field.
Application of unified security policies across a diverse range of remote sites and equipment
Managing multiple backhaul connectivity options at the gateway including private MPLS for critical SCADA traffic and cellular for backup and even internet-based connections for non-critical traffic, where appropriate
Lifecycle management of gateways (e.g., firmware updates, alarm monitoring and statistics)

Cisco SD-WAN Validated Design for Distribution Automation (DA)

SD-WAN has origins as an enterprise solution using fixed edge routers of various performance capabilities and predictable enterprise traffic patterns. Utility networks present new challenges with especially when applied to Distribution network use cases:

Connectivity to legacy serial devices not supporting Ethernet/IP
communications (g., Modbus RTU, DNP3 over serial, IEC101 or vendor proprietary)
Mobility needs for mobile assets to ensure resilient wide area connectivity
New WAN interfaces including dual 4G or 5G cellular, DSL, fiber or Ethernet
The use of NAT to allow fixed privately addressed equipment to communicate
Requirement to encrypt SCADA traffic across the wide area network
Applicable to both distribution substations and field area networks
Segregation of services via VPNs in flexible topologies (Hub & Spoke, or Meshed [Fully or Partial])
Intelligent traffic steering across multiple backhaul interfaces when needed (critical vs. non-critical traffic)

Key use Distribution Network use cases that the Cisco SD-WAN solution can address are:

Cisco IoT Solutions have introduced a new Cisco Validated Design to address an SD-WAN architecture for Distribution Automation use cases. Leveraging the Cisco Catalyst IR1100 Rugged Series Routers as an SD-WAN router with flexible modular backhaul capabilities (DSL, Fiber, Ethernet, 4/5G, 450MHz LTE) and operating as an SD-WAN controlled edge router.

Along the distribution network feeders, the IR1101 should be positioned as a Distribution Automation gateway. It can be easily mounted within a DA device cabinet (e.g. Recloser, Cap bank controller etc) and can be powered by the same DC supply (flexible 9-36VDC input). It also has extended environmental capabilities to cope with the variations in temperature, humidity, and vibration.

The new SD-WAN for Utility Distributed Automation Design Guide builds on other existing documents that describe in detail Cisco’s SD-WAN architecture and industrial IoT hardware offerings and shows how they can be combined to provide a scalable, secure network. The new Design Guide is focused on areas that are unique or at least emphasized by DA use cases in general. This document also has detailed configuration examples for many of the DA features.

Readers should already have some familiarity with Cisco SD-WAN and Industrial IoT. Prior to reading this document, it is recommended to be familiar with the following resources:

Cisco SD-WAN Small Branch Design Case Study – This document provides a great overview of general SD-WAN concepts in the context of a “small branch” which has many commonalities with a typical industrial IoT deployment.
Cisco Catalyst IR1101 Rugged Series Router Data Sheet – Datasheet for the IR1101 router which is designed for distribution network applications and certified for substation use (IEC61850-3 and IEEE 1613).

Share

  Leveraging a validated SD WAN architecture for Utility Distribution network use cases  Read More Cisco Blogs 

By |2023-10-26T07:57:57+00:00October 26, 2023|Cisco: Learning|0 Comments

CCIE Security Certification Exam Tips for Success Zia Hussain on October 25, 2023 at 10:25 pm

Security is an ever-evolving technology that is necessary in every organization. That’s why Cisco Certified Internetwork Expert (CCIE) Security-certified individuals are in high demand.<span data-ccp-props=' LinkedIn '> 

This year, we… Read more on Cisco Blogs

Security is an ever-evolving technology that is necessary in every organization. That’s why Cisco Certified Internetwork Expert (CCIE) Security-certified individuals are in high demand. 

This year, we celebrate the CCIE program’s 30th anniversary. As the second-most sought-after CCIE certification, I’m here to offer tips to achieve the CCIE Security certificate by sharing my own certification journey as well as preparation for success. 

My CCIE Security journey 

I started my professional career at the Cisco Technical Assistance Center (TAC) as a support engineer. In this role, it was essential to be at the top of my game to resolve critical and time-sensitive network incidents promptly. 

One of the ways to achieve that was to earn the CCIE Security certification, which demonstrated hands-on experience in a lab environment. 

Though I initially sought this certification to be proficient in my job role, it also paved the way for me to grow in my organization. 

After achieving my CCIE Security certification, I became the team tech lead of access-control technologies at the Cisco TAC, instructor of security bootcamp for the onboarding of engineers at Cisco, and network consulting engineer for the Cisco Advanced Services Organization for AT&T and BT-Infonet customer accounts. I also administered and delivered CCIE labs across the globe, authored technical documents on Cisco Connection Online (CCO), contributed as a subject matter expert (SME) for the CCIE Routing and Switching (RS) and Security tracks, and am currently the program manager of the CCIE Security exam. 

I strongly believe being CCIE certified hugely contributed towards my professional achievements and is key to anyone’s professional growth and success in this industry. 

Prep for success  

The CCIE Security exam has numerous security appliances and solutions with additional dependencies that require the highest level of expertise. The exam tests your design, deployment, optimization, and troubleshooting skills. For the past 30 years, we have ensured that the exam blueprint is relevant to both industry security solutions and aligned with the Cisco Security portfolio. The tasks in the blueprint are based on security technology and solutions that serve as the knowledge base you need to be successful in the lab exam. 

When I had my first CCIE exam 22 years ago, there was no concept of Network Function Virtualization (NFV) of Cisco devices, so I had to work with physical devices in a shared setup to practice for the lab exam, which was not an ideal scenario.  

I used the blueprint as my guide to build scenarios for each task, stitched multiple scenarios for a viable security solution, and then practiced deployment, optimization, and troubleshooting of those security solutions.

The exam blueprint should be the starting point of your journey. Identify the tasks from the blueprint that you are not an expert at. Then, build the lab modules for those tasks to test deployment, optimization, and troubleshooting skills. 

When practicing your lab modules, time it. This will develop time management skills for your lab attempt. Most of the candidates who are well prepared fail because of poor time management. Time management is the key to a successful lab attempt. 

You should also review exam guidelines, which have important information about exam dos and don’ts. If the guidelines are not carefully followed, then you will lose critical marks that may cause you to fail the exam. 

It is difficult to pass lab exam in the first attempt. That said, learn from your mistakes, identify your shortcomings and weaknesses and devise plans to rectify them. This approach will give you a great chance to pass in the subsequent attempts.  

The CCIE Security Practice Labs, CCIE Security Learning Matrix, and CCIE Security Equipment and Software List are some of the resources provided by Cisco to help you prepare for the lab. 

Finally, lab exam preparation is about motivation and momentum. If you are missing any one of those, then it will be extremely difficult to get to the finish line. 

Cisco certification updates to the CCIE Security exam  

The major update to the current blueprint of the exam is cloud adoption tasks. This includes Umbrella and Umbrella VA tasks. However, this revision affects less than 20% of the exam and will not cause disruption for the candidates already preparing for the lab exam. 

The security appliances, such as Identity Services Engine (ISE), are now heavily exposed for Application Programming Interfaces (APIs). Therefore, we expect you to understand the construction of secure API call using POSTMAN and be able to execute them. We also expect you to understand Python at the basic level so that you can program the API calls.  

Most of the exam—98%—is focused on virtual machines (VMs) of security appliances and core devices running in the ESXi environment while the remaining 2% of the exam is focused on the physical devices, including the Adaptive Security Appliance (ASAs), to test you on Active/Active Failover and Clustering that requires context and is not supported on the virtual ASA (ASAv).  

The exam format is the same—The first three hours are focused on the Design module and the remaining five hours are focused on the Deploy, Operate, and Optimize module. 

We use automation to perform the exam grading. That being said, if any task is marked incorrect by the script, it is cross checked manually as an additional step to preserve grading fairness. 

There could be multiple exam forms in production, and each may have different passing scores. The passing score is based on the exam difficulty level, which is determined using a specific procedure. 

We do hardware and software updates only when we revise the blueprint. However, if for any unforeseen reason we need to perform an update, we will notify the certificate community six months in advance on the Cisco Learning Network so that you have enough time to prepare accordingly. 

The CCIE Security journey 

As technology has changed, so has the CCIE Security program. From its humble beginnings slowly being introduced to the CCIE program as network security took off to now becoming its own unique skillset, the CCIE Security certificate enhances your knowledge to propel your career.  

With the right preparation and perseverance, you too can earn this certification and use it to grow and find success in the industry. 

Resources

Cisco Certification Roadmaps
Security Certifications Community
Learning Path: Implementing and Operating Cisco Security Core Technologies (SCOR)
Tutorial: Introduction to Firewall Management Center APIs – Security
Tutorial: Introduction to the Cisco ISE Policy Set – Security
Tutorial: Securing your API Token with Vault: Security

Sign up for Cisco U. 

By |2023-10-26T07:57:56+00:00October 26, 2023|Cisco: Learning|0 Comments
Go to Top