About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Powering the Experience-Driven Institution Phal Nanda on October 2, 2023 at 3:17 pm

The new school year is starting, students and faculty flock back to campus excited for the upcoming year of learning, connecting, and challenges to overcome. Students are wandering into their dorm… Read more on Cisco Blogs

The new school year is starting, students and faculty flock back to campus excited for the upcoming year of learning, connecting, and challenges to overcome. Students are wandering into their dorm room, courtyards, all over campus with smart phones, smart watches, tablets, laptops, gaming systems, and all sorts of other devices.  Thousands upon thousands of devices all start connecting to the network. Stakeholders (faculty, staff, and students) expect a high-quality connected experience from one end of campus to the other, regardless of device or application.

This requires a secure, intelligent automated environment across the university taking advantage of the latest technology, Wi-Fi 6E enabled hardware, with applied AI to help create a frictionless unified user experience across the entire campus.

Higher Education Challenges

Currently, the IT Landscape in Higher Education faces many challenges. As the higher education sector continues to evolve in a digital transformation, university networks must combat these challenges such as:

IT Ecosystems – Dated systems, increasing complexity and silos make it difficult to adopt new technologies and innovate at scale.
Connectivity – Students need and expect high-quality digital experiences. Access to broadband and Wi-Fi are critical to students and faculty.
Safety and Security– As security moves to the network and cyber-attacks are more sophisticated, physical security is interconnected with network security.
Devices – IT teams are now managing more devices and need ways to track these assets, monitor for cyber threats, and manage performance.

For universities, staying current with technology and regular network infrastructure upgrades is critical to ensuring the educational mission is not hindered by technological limitations.  A wireless network is no longer a luxury or commodity, but a utility for educational institutions. Cisco helps solve these challenges by harnessing the capabilities of Wi-Fi 6E and applying cutting-edge AI technology to the Experience-driven Institution.

Cisco Higher Education Solutions

The true power of Cisco Wireless lies in the creation of a unified experience across the campus.  With Cisco wireless solutions focused on experience, simplified operations, digital transformation and security, IT professionals can expect the same level of connectivity and performance through:

OpenRoaming allows students, faculty, and staff to connect seamlessly across campus, improving experience across the network.
Our-on-prem, and cloud solutions help mitigate risk by providing insight into client connectivity easily with visibility of performance to troubleshoot any issues that spring up.
Future-proof your network with Cisco wireless unified Wi-Fi 6E access points (APs) with cloud operations and dual mode.
Deliver better outcomes with Cisco’s wireless ecosystem partnerships.
MT Sensors and IoT solutions enable universities to assess and adapt the physical and digital for your ideal sustainable, smart workspace.
Digitize the physical world to keep students, faculty, and staff safe.
Control and secure wireless connectivity and everything in between with Cisco Security Solutions
Role Based segmentation and access management, incorporating ISE or other segments, and defining network policy for device onboarding for maximum efficiency and mitigate risk.
Minimize onsite IT employee time with centralized, remote network management.
Leverage applied AI for enhanced daily network operations and performance.
Provide a seamless onboarding experience for client devices and network deployment.

Cisco Wireless’ Wi-Fi 6E solutions with Applied AI create a secure, sustainable, flexible network that delivers a frictionless, unified user experience across the entire campus.  The experience-driven institution for higher education is here thanks to Cisco’s innovative networking solutions.

Resources for education

Join Cisco at EDUCAUSE 2023 and see Cisco Wireless solutions in action. To learn more about Cisco in education, explore these resources:

EDUCAUSE 2023

Cisco in Education

Cisco Education Portfolio Explorer

Cisco Wireless

Cisco Solutions for Higher Education

Cisco Solutions for K-12 Education

Cisco and E-rate

Share

  Cisco securely connects and creates the frictionless experiences your students, faculty, and administrators expect – helping create flexible learning classrooms.  Read More Cisco Blogs 

By |2023-10-03T00:52:09+00:00October 3, 2023|Cisco: Learning|0 Comments

Investing in your success scaling SMB sales like never before Craig Cieplinski on October 2, 2023 at 3:00 pm

Co-authored by Stephen Lawrence, Head of Global SMB, Distribution & E-commerce Marketing 

 

Cisco Partners, have we got news for you! When it comes to SMB, we have a $19B net-new logo (NNL) … Read more on Cisco Blogs

Co-authored by Stephen Lawrence, Head of Global SMB, Distribution & E-commerce Marketing 

Cisco Partners, have we got news for you! When it comes to SMB, we have a $19B net-new logo (NNL) opportunity in front of us. And another $6B to capture working with your existing SMB customers.  Got your attention? Read on to learn how Cisco is investing in your success to scale SMB sales like never before.

Your expertise is increasingly in demand

As SMBs stampede to the cloud, they are increasingly relying on technology to ensure their business is growing and their applications are accessible, resilient, and secure.  All of this entails an IT complexity conundrum that, quite frankly, SMBs do not have the time or resources to manage.  This is where Cisco partners come in. You and your expertise play an increasingly important role for SMBs as they rely on you more and more to deliver the solutions and services they need to run their business.

Provide the experience outcomes SMBs want

At Cisco, as much as we love talking about Zero Trust, Secure Access, and SD-WAN. SMBs really don’t want to talk about technology. SMBs want to talk to our partners about how they can solve their business challenges and deliver the experience outcomes they need.  SMBs want their employees to be able to work from anywhere.  They want to ensure that their business is secure. They want to be smart about running their business efficiently.  Cisco has simplified its SMB portfolio to speak to those experience outcomes: The Hybrid SMB, Secure SMB, Remote SMB, and Smart SMB.  You can start having those outcome conversations today. Leverage our tools and SMB Portfolio training here to get started.

Extending our reach and driving SMB demand

With more than 90% of Cisco’s SMB revenue flowing through Cisco partners, it is critical to deliver the right enablement, support, and resources to you to engage new and existing SMB customers. We are invested and committed to driving impact for you by developing the Cisco SMB experience outcomes that are affordable, simple, and flexible so that it’s easier for you to engage SMB customers—and deliver on what SMB decision makers care about.

Acquiring new customers is key and Cisco has already invested in our brand and has evolved our digital front door cisco.com/smb, giving customers more choice in how they engage with us. With just a few clicks, the SMB Experience Explorer tool can help new SMB customers find the right Cisco solutions through a simple and personalized transaction. And good news! We have also made this available to all Cisco partners. You can now embed this tool on your websites directly and start having those conversations with your SMB customers.

Within our Marketing Velocity Central platform, we are investing in SMB-specific marketing resources for our Cisco partners. This includes simplified messaging copy blocks, portfolio overviews, social media copy, email templates, as well as assets like solutions guides, infographics and paid media kits. These SMB toolkits empower you to take this SMB messaging to your own markets faster.

We’ve got you covered

Cisco has evolved our sales coverage model too.

We have dedicated SMB Territory Managers in region to help you to plan, drive demand, cross-sell and get the support you need.  We also invested in SMB Architecture Specialists available to you when speaking to SMBs.  For example, a partner salesperson can receive help from a Cisco SMB Security Sales Specialist if he or she needs to get into a deep discussion about Secure Access or Zero Trust with their customer.

We have also invested in SMB Sales Acceleration Managers (SAMs) in the field, doubling our coverage across the globe.  The SAMs’ sole REMIT is to make sure you have access to everything available to you to expand your SMB business practice. They can also help with demand generation and sales execution.

Meeting SMB customers where they want to buy

Whether you are a Managed Service Provider (MSP), an integrator VAR, an e-commerce partner, or distributor, we want to ensure you are as successful and profitable as possible on the routes to market (RTMS) where SMBs are buying. For our VARs, we have doubled down on investments in our new SMB profitability programs Perform Plus and Perform Plus Activate. We are also supporting our MSP and SP Partners with service creation and their demand generation efforts to attract new customers.

Currently, 47% of our SMB business is delivered through a provider partner.  And Managed Service providers will represent an even larger part of the business moving forward.  In fact, SMB IT security spending through MSPs is expected to grow by 11% to USD311 billion this year!

We are excited to share the latest programs available to drive MSP profitability across the board:

For MSPs and Services Providers, we have a new partner journey to help new MSPs navigate Cisco SMB programs, pricing, and offers.
The new Cisco Partner Program Provider role is designed to empower and reward our MSPs who grow and differentiate themselves by providing new managed services offerings.
Cisco Partners can start today by enrolling in theCisco Meraki for MSPs Partner Journey where you will receive the information, tools, and free Black Belt Academy training necessary to build your managed service with Meraki.

So, what are you waiting for?

Jump on board today to take advantage of all the SMB resources, training, programs, and incentives available to you to scale your SMB business like never before!

Learn how to build differentiated practices with the new SMB Black Belt training curriculum, which includes highly informative topics, such as SMB, MSP, Security, Meraki, Hybrid Work and Sustainability.

And stay tuned for further exciting SMB program announcements at Cisco Partner Summit 2023 this November!

Take advantage of all the SMB resources, training, programs, and incentives

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    Cisco Partners LinkedIn

Share

  Cisco Partners, have we got news for you! When it comes to SMB, we have a $19B net-new logo (NNL) opportunity in front of us. And another $6B to capture working with your existing SMB customers.  Got your attention? Read on to learn more.  Read More Cisco Blogs 

By |2023-10-03T00:52:09+00:00October 3, 2023|Cisco: Learning|0 Comments

A Day in the Life of CX is better with YOU! Alistair Wildman on October 2, 2023 at 11:07 pm

It is CX Day, and it is time to celebrate! At Cisco, we are leveraging this global celebration, established by the Customer Experience Professionals Association (CXPA), as an opportunity to celebrate… Read more on Cisco Blogs

It is CX Day, and it is time to celebrate! At Cisco, we are leveraging this global celebration, established by the Customer Experience Professionals Association (CXPA), as an opportunity to celebrate the positive impact our Customer Experience teams have on our customers and partners every day.

Today we celebrate the people who keep our technology running, our teams productive, our websites up, our businesses secure, and our customers delivering outcomes. These CX professionals influence the next wave of technology innovation based on direct feedback from our customers and partners about their usage of apps, tools, hardware, and systems. I am proud of the work our CX team does that contributes to the experiences our customers can create for their own customers.

Of course, we can’t celebrate our team without acknowledging our customers and our partners, who give us a reason to celebrate every day. We are humbled and proud to be able to help them transform, innovate, grow, and accomplish all the business outcomes they strive to achieve. Here are just a few examples.

Princess Cruises partnered with Cisco CX to improve the experience for their passengers. Princess is the world’s leading premium cruise line, operating a fleet of modern ships visiting over 380 destinations around the globe. Transformation for Princess Cruises meant pushing the limits of technology to provide highly personalized, frictionless, and innovative experiences to their customers and crew on the ship using wearable technology. Princess constantly collaborated with Cisco to innovate for customers and crew. The team recently developed a long-term strategic plan and roadmap, which will continue to build on the award-winning guest and crew experiences for which Princess is known.

BBVA is one of the largest financial institutions in the world. Over the last few years, BBVA has undergone a huge digital, multi-architecture transformation. They have become known for being an innovator in their industry, using leading-edge technologies to achieve great outcomes. With Cisco Business Critical Services, they were able to increase service availability and reliability, while reducing human errors through automation in the provisioning and operational processes, greatly improving their customers’ experiences.
Children’s National Hospital, a nationally ranked pediatric acute care children’s hospital located in Washington, D.C., is all about providing the best care. For them, transformation meant securely extending the availability of complete patient information to remote sites. Today, Cisco CX is helping them complete their mission by strategizing, architecting, and building a holistic end-to-end secure network based on Zero Trust principles.

Learn more about Cisco CX here. We will provide even more exceptional experiences for our customers and partners in the coming years to continue delivering the business outcomes our customers expect and deserve.

We would love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoCX on Social!

@CiscoCX Twitter (X)  Alistair Wildman LinkedIn

Share

  It is CX Day! At Cisco we are using this day as an opportunity to celebrate the positive impact that our Customer Experience (CX) teams have made in the lives of their fellow employees, customers, and partners.  Read More Cisco Blogs 

By |2023-10-03T00:52:08+00:00October 3, 2023|Cisco: Learning|0 Comments

Cisco’s Digital Impact Office powers digital inclusion across the globe Russell Smith on October 2, 2023 at 5:25 pm

Russell (Rusty) Smith is a Senior Director in Cisco’s Digital Impact Office

I grew up in a small town. My mom worked as an assistant for the city administrator. When our phone would ring, I heard my … Read more on Cisco Blogs

Russell (Rusty) Smith is a Senior Director in Cisco’s Digital Impact Office

I grew up in a small town. My mom worked as an assistant for the city administrator. When our phone would ring, I heard my mom responding to the needs of the community—real people were on the other end of the line. She listened. She made people feel included. My mom helped everyone in our town solve problems in ways that I cannot begin to describe. It made a lasting impression on me. That type of servant leadership in the name of inclusion is precisely what we do in Cisco’s Digital Impact Office, the home of Cisco Networking Academy and Country Digital Acceleration.

“What it really comes down to is connecting more people to the digital economy.”

The Digital Impact Office is a manifestation of Cisco’s Purpose, to Power an Inclusive Future for All. Communities spanning the globe benefit from the collaborative works of Country Digital Acceleration and Cisco Networking Academy. The work of the Digital Impact Office makes a substantial contribution to Cisco’s commitment to positively impact one billion people across the globe by FY2025. Digital inclusion is brought to life through the combined power of Cisco Networking Academy and Country Digital Acceleration. We power transformative projects spanning the globe, laying the groundwork for broadband connectivity, innovation for Smart Cities, and beyond. What it really comes down to is connecting more people to the digital economy. Digital inclusion means making investments in infrastructure and skills. The jobs of the future made available to everyone, everywhere. Cisco is uniquely equipped to partner with organizations and communities ready to build a more inclusive future.

Digital Impact is about community

When you think about it, the topic of digital inclusion is an invitation to have a greater conversation about community. For instance, the focus of Cisco’s Country Digital Acceleration is not building a thing or selling a product. Rather it’s extending an invitation. We meet people where they are. Listening to real-life stories helps us understand issues individuals face on a daily basis. Quite literally, the work we do helps our partners extend beyond the walls of their organizations. Digital inclusion brings entire communities along the journey. The story of impact is inspiring. One such example is the Autonomous Living Project.

Powered by Cisco technology, the Autonomous Living Project is a solution for anyone who requires lifelong support. The technology has the power to enable an inclusive community for all including people who are aging, have different abilities, and require lifelong care needs. The pilot program operating in Ontario, Canada supports individuals and families where they are, and transforms service delivery. Cisco technology drives, scales, and revolutionizes service delivery to support independent living through smart notifications and smart device integration. This technology is the product of inclusive design. Developed by Cisco Country Digital Acceleration in partnership with a host of other organizations, the Autonomous Living Project currently supports individuals with special needs and their caregivers. Everyone wins when we design with and for inclusion. This is only the beginning.

Connecting people to skills and jobs of the future

There is a palpable sense of excitement, fueled by a focus on full-spectrum digital inclusion. Central to Cisco’s Purpose is a mandate to drive digital acceleration and connect individuals to the jobs of the future. Cisco Networking Academy is a champion of this story of digital impact, positively impacting lives by driving inclusive socio-economic development. Over the course of its more than 25 years, over 20.5 million global learners have taken Cisco Networking Academy courses to gain digital skills. As one of the most long-standing, successful IT skills-to-jobs programs in the world, Cisco Networking Academy is key to forging lasting partnerships in communities. It’s a game-changer in bridging the digital divide and learning in-demand skills. Networking Academy students land family-sustaining jobs and power the digital transformation of their own communities. In fact, globally, 95% of students that have taken Cisco certification aligned courses attribute obtaining a job or education opportunity to Cisco Networking Academy.

Digital inclusion, powered by the work of Cisco Networking Academy and Country Digital Acceleration translates to increased opportunities for individuals spanning the globe. I am inspired reflecting upon how far we have come, and eagerly look ahead to what’s next. In communities where Cisco is a trusted partner, we have the power to unleash human potential, and that inspires us all.

To learn more about the work of the Digital Impact Office, visit 

Cisco Networking Academy and Country Digital Acceleration.

Share

  Cisco's Digital Impact Office brings together Cisco's Networking Academy and Country Digital Acceleration program to build an inclusive global economy.  Read More Cisco Blogs 

By |2023-10-03T00:52:08+00:00October 3, 2023|Cisco: Learning|0 Comments

When it Comes to Compliance Requirements – Topology Matters! Jorge Quintero on September 29, 2023 at 7:00 pm

When I look at the evolution of network security and how IT and security practitioners have protected the network for the last 30 years, I can’t help but notice how traditional network security e… Read more on Cisco Blogs

When I look at the evolution of network security and how IT and security practitioners have protected the network for the last 30 years, I can’t help but notice how traditional network security enforcement points (insert your favorite firewall here) are still used to secure networks and workloads. They have evolved to offer a diverse set of features (i.e., IPS, decryption, application detection) to deeply analyze traffic coming in and out of the network to protect workloads. However, while firewalls are very capable appliances, it has been proven that they are not enough to keep malicious actors at bay, especially if those actors manage to breach the firewall defenses and move laterally in the network. But why is this?

We are in the digital era, where the concept of the perimeter is no longer contained to a location or a network segment. To offset this new reality and provide a more tailored-based policy control for protecting workloads, vendors have moved security closer to the workload.

There are two approaches to do this -, using agent or agentless techniques to build a micro-perimeter around the workloads.

Which approach is the correct one to take? Well, this depends on multiple factors, including organizations, type of application, or team structure. So, let’s start untangling this.

The challenge(s)

The most direct approach to protect applications is to install software agents on every workload and call it a day. Why? Because then every workload has its own micro-perimeter, allowing access to only what is necessary.

However, it is not always possible to install a software agent. Perhaps it is a mainframe application or a legacy operating system that requires fine-grained policies due to a compliance mandate. Or application workloads that are in the cloud and the agent installation is simply not possible due to organizational constraints.

And this is not the only challenge or consideration for choosing your approach. The teams or groups that comprise any company often have different security requirements from each other, leading to the triad challenge: people, processes, and technology.

Let’s start with people (policy owner) and process (policy execution). Usually, each organization has its own set of unique requirements to protect its application workloads, and a defined process to implement those requirements in the policy. To support this, a tool (technology) is required, which must adapt to each organization’s needs and should be capable of defining a common policy across agent and agentless workloads.

To start unwrapping this, you need to ask yourself:

What are we protecting?
Who is the owner of the policies?
How is policy execution done?

As an example:

Say you want to protect a finance application (what) using an agent-based approach (how), and the owner of the policies is the App Team/Workload Team (who). In this scenario, as long as the application doesn’t break and the team can continue to focus on coding, this is generally an acceptable approach. However, when implementing the common policy, the translation from human language to machine language tends to generate extra rules that are not necessarily required. This is a common byproduct of the translation process.

Now, let’s assume that in your organization the protection of a legacy application (what) is tasked to the Network/NetSec team (who) using an agentless enforcement approach with network firewalls (how) because in this case, it is not possible to install software agents due to the unsupported legacy operating system. As in the first example, extra rules are generated. However, in this case, these unnecessary extra rules create negative consequences because of firewall rules auditing requirements for compliance mandates, even though they are part of the common policy.

Topology as the source of truth – pushing only what is required

Cisco Secure Workload has been addressing the people, process, and technology challenges since its inception. The solution embraces both approaches – installing software agents on workloads regardless of form factor (bare-metal, VM, or container) or by using agentless enforcement points such as firewalls. Secure Workload adapts to each organization’s needs by defining the policy, such a zero trust microsegmentation policy, to effectively apply micro-perimeters to application workloads in support of the zero trust approach. All within a single pane of glass.

However, as explained in the example above, we still needed to align our policy to the compliance needs of the Network/NetSec team, only using the policy rules that are required.

To tackle the additional rules challenge, we asked ourselves, “What is the most efficient way to push policies into a network firewall using Secure Workload?”

The answer boiled down to a common concept for Network/NetSec teams – the network topology.

So how does it work?

With Secure Workload, the term topology is intrinsic to the solution. It leverages the topology concept using a construct named “Scopes”, which are totally infrastructure agnostic, as shown in Figure 1.

It allows you to create a topology tree in Secure Workload based on context, where you can group your applications and define your policy by using human intent. For example, “Production cannot talk to Non-Production” and apply the policy following the topology hierarchy.

The Scope Tree is the topology of your application workloads within the organization, but the key is that it can be shaped for different departments or organizational needs and adapted to each team’s security requirements.

The concept of mapping a workload Scope to a network firewall is called “Topology Awareness.”

Topology Awareness enables the Network/NetSec teams to map a particular Scope to a specific firewall in the network topology, so only the relevant set of policies for a given application is pushed to the firewall.

So, what does this execution look like? With the Scope mapping achieved, Secure Workload pushes the relevant policy to the Cisco Secure Firewall by way of its management platform, Secure Firewall Management Center (FMC). To maintain compliance, only the required policy rules are sent to FMC, avoiding the extra unnecessary rules because of Topology Awareness. An example of this is shown in Figure 2:

Key takeaways

Operationalizing a zero trust microsegmentation strategy is not trivial, but Secure Workload has a proven track record of making this a practical reality by adapting to the needs of each persona such as Network/NetSec admins, Workload/Apps owners, Cloud Architects, and Cloud-Native engineers – all from one solution.

With topology awareness, you can:

Meet compliance and audit requirements for firewall rules
Protect and leverage your current investment in network firewalls
Operationalize your zero trust microsegmentation strategy using both agent and agentless approaches

For more information on agentless enforcement please read: Secure Workload and Secure Firewall Unified Segmentation Blog

Want to learn more?  Find out more at by checking out our Secure Workload resources.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Provide zero trust segmentation with fine-grain rules to application workloads where an agent cannot be installed using existing network firewalls.  Read More Cisco Blogs 

By |2023-09-30T05:58:42+00:00September 30, 2023|Cisco: Learning|0 Comments

Announcing Expanded DISA IL5 Authorization for VMware Cloud on AWS GovCloud (US)  Joe Witles, Jason Crocker, Nic Hall and Ruchi Tandon on September 20, 2023 at 5:37 pm

Some great news for our existing and prospective customers of [...]

By |2023-09-30T05:58:25+00:00September 30, 2023|VMware : Cloud|0 Comments

Distributed ZTNA enables simple and scalable secure remote access to OT assets Ruben Lobo on September 28, 2023 at 4:00 pm

Zero trust network access (ZTNA) is the ideal architecture for securing remote access to enterprise resources.
But in OT environments, ZTNA needs to be distributed.

 

Remote access is key for… Read more on Cisco Blogs

Zero trust network access (ZTNA) is the ideal architecture for securing remote access to enterprise resources.
But in OT environments, ZTNA needs to be distributed.

Remote access is key for operations teams to manage and troubleshoot operational technology (OT) assets without time-consuming and costly site visits. In many organizations, machine builders, maintenance contractors, or the operations teams themselves have installed their own solutions: cellular gateways that nobody knows about or remote access software that IT is not controlling.

Traditional remote access solutions have too many drawbacks

These backdoors are at odds to the OT security projects undertaken by the IT/CISO teams and create a shadow-IT situation which makes it difficult to control who is connecting, what they are doing, and what they can access.

On the other hand, Virtual Private Networks (VPN) installed by IT teams in the industrial DMZ (iDMZ) have drawbacks of being always-on solutions with all-or-nothing access to OT assets. This makes it challenging to control when someone connects and what they have access to without using jump servers to manage sessions and complex firewall rules that need to be frequently updated to prevent wide-open access.

Existing ZTNA solutions do not translate well to OT

Industrial organizations are starting to deploy Zero Trust Network Access (ZTNA) solutions as alternatives to always-on VPNs. ZTNA is a security service that verifies users and grants access only to specific resources at specific times based on identity and context policies. It starts with a default deny posture and adaptively offers the appropriate trust required at the time.

The solution consists of a ZTNA trust broker, typically a cloud service, that mediates connections between remote users and OT assets. The trust broker communicates with a ZTNA gateway deployed in the industrial network. The gateway establishes an outbound connection to the trust broker which in turn cross-connects to the remote user, thereby creating a communication path to the OT assets in the proximity of the gateway.

In field networks like traffic control cabinets at roadway intersections, or utility pole-mounted capacitor bank control cabinets, installing dedicated ZTNA gateways is not an option because space is an issue. When space is available, having to maintain dedicated ZTNA gateway hardware just to access a few OT assets puts an undesirable burden on customers.

In larger industrial networks, such as manufacturing plants, the ZTNA gateway is centralized in the iDMZ to avoid the cost and complexity of distributing dedicated hardware in the OT network. But this centralized architecture puts the ZTNA gateway too far from the OT assets and suffers the same drawback of the legacy VPN design:

In such environments IP addresses are often reused, and many assets sit behind NAT boundaries which makes them unreachable to the ZTNA gateway in the iDMZ. The complexity now falls on the end customer to expose these private IPs to the higher layers of the Purdue model.
In addition, because the ZTNA gateway is far from the OT assets, preventing lateral movement of remote users between OT assets becomes challenging.

Both these aspects negate key tenants of ZTNA, namely resource isolation and limiting lateral movement.

Cisco is embedding the ZTNA gateway in industrial networks

With Secure Equipment Access (SEA), Cisco is solving the challenges of deploying secure remote access to operational assets at scale. It embeds the ZTNA gateway function into Cisco industrial switches and routers, making secure remote access capabilities very simple to deploy at scale. There is no point hardware solution to source, install, and manage. No complex iDMZ firewall rules to configure. Enabling remote access is just a software feature to activate in your Cisco industrial network equipment.

Distributing the ZTNA gateway function anywhere in the network lets you remotely access every asset. The Cisco industrial switch or router that provides secure and reliable connectivity to OT assets, now also provides zero trust remote access to these assets, whatever its IP address or your NAT strategy. And the same network equipment can also enforce micro-segmentation policies to prevent lateral movements in the case the asset is used as a jump host. Only Cisco offers such an advanced security capability in industrial switches and routers today.

Enabling zero trust network access for OT

Managing a large number of ZTNA gateways across your operational environment is simple. Cisco Secure Equipment Access comes with a cloud portal that centralizes gateway management and configuration of remote access policies. It acts as a ZTNA trust broker, verifying users and granting access only to specific resources based on identities and contexts.

Remote employees, vendors, and contractors connect to the Secure Equipment Access cloud portal where they are authenticated and offered access only to the devices you choose, using only the protocols you specify, and only on the day and time you allow.

Remote access sessions start with a default deny posture and Secure Equipment Access adaptively offers the appropriate trust required at the time. Assets are hidden from discovery and lateral movements are made impossible. IP addresses are never exposed in the iDMZ, further reducing your attack surface.

Operations administrators can easily create credentials to meet their business needs and grant access to OT assets in two different manners:

Clientless ZTNA. Users just need a web browser to access remote OT assets using RDP, VNC, HTTP/S, SSH, or Telnet.
Agent-based ZTNA (which we call SEA Plus). Cisco SEA establishes a secure IP communication channel between the user’s computer and the OT asset so any desktop application can be used for advanced tasks, such as file transfer or PLC programming using native applications for instance.

Cisco Secure Equipment Access is designed to enforce strong zero trust security policies and offer advanced monitoring and compliance capabilities:

Multifactor authentication (MFA) to address the risk of stolen credentials.
Single sign-on (SSO) to streamline the user experience and enforce strict user policies from a centralized location.
Device posture check to assess the remote user’s security posture and only grant access to hosts with malware protection software installed for instance.
Session monitoring with the ability to join a session and view in real time what a remote user is doing.
Session termination offering administrators the ability to kill an active session.
Session recording to go back in time and watch what remote users did.

We will detail these features in upcoming blog posts over the next few weeks. Make sure you subscribe to our OT Security newsletter to receive them in your inbox. In the meantime, learn more about Cisco Secure Equipment Access (SEA), and have a look at our Cisco Validated Design Guide for assistance on how to implement ZTNA in your operational environment.

Share

  Zero trust network access (ZTNA) is the ideal architecture for securing remote access to enterprise resources. But in OT environments, ZTNA needs to be distributed.  Read More Cisco Blogs 

By |2023-09-29T16:58:10+00:00September 29, 2023|Cisco: Learning|0 Comments
Go to Top