Layered Safety for RADIUS With Cisco

Sep 24, 2024
Dream world for the CISO Organizations have all kinds of assets to guard. And a few assets are simpler to guard than others. Nevertheless, it’s not the straightforward stuff that retains a CISO up at evening. Earlier than we dive into the tougher examples, let’s think about a situation that enables a CISO to sleep peacefully. On this situation, when a employee “goes to work” (both within the workplace or remotely), they open their company laptop computer and login to a SaaS utility. This employee varieties the URL into their browser, logs in with their SSO supplier and authenticates utilizing their fingerprint (biometric) on the gadget. Behind the scenes, this consumer is connecting to the applying by a Zero Belief Community Entry (ZTNA) resolution and authenticating with SAML protocol (or OIDC or OAuth2.0), the trendy authentication technique for cloud functions. This situation is the dream situation (and simpler) to guard: Fashionable, cloud utilityCoverage-driven utility entryPhishing-resistant authenticationTrusted, managed gadget The truth verify Nevertheless, the dream situation can also be the least prone to be the reason for a breach. As a substitute, attackers are exploiting legacy know-how or networks the place it’s tough to deploy further safety and implement coverage, like phishing-resisting multi-factor authentication (MFA) or ZTNA. Whereas organizations are on their infrastructure modernization journey, we have to have a sensible plan to guard the lengthy tails of legacy property which are nonetheless in place and could also be tough to safe. What might be performed? Layered safety with RADIUS One in every of these under-rated, however frequent, authentication protocols is RADIUS (Distant Authentication Dial-In Consumer Service). RADIUS is a conventional network-based authentication protocol for customers and gadgets that want to hook up with the community. In case your group is able the place routers, switches, wi-fi entry factors and VPNs all use RADIUS, Cisco can assist. First, Cisco Identification...

0 Comments