Enterprise security building self-built access system

Source: Internet
Author: User
Keywords System Security Enterprise Security
Tags access access system allowing basic cisco company control enterprise

Enterprise security building self-built access system, this article describes the experience of self-built access to the system, the system in a stable operation of a large Internet company for 5 years.

Access to the system profile

Network Access Control (NAC) is a Cisco-sponsored, multi-vendor initiative designed to prevent emerging hacking technologies such as viruses and worms from compromising enterprise security. With NAC, businesses can only allow legitimate, trusted devices (such as PCs, servers, PDAs) to access the network without allowing other devices to access it.

To remedy the situation

Internet companies in addition to the basic listing of the United States there is no pressure of safety and compliance, all business development and work efficiency as the first driving force, so costly and labor-intensive construction depends mainly on event-driven security, we encountered before entering so few An unlucky thing:

Office network a large number of PC antivirus was uninstalled staff, and did not promptly patch, the result was very low arp virus at the time, several network office off, affecting the development of a thousand small RD.

Angry young staff post, uncle door check meter, we almost did not find out who is.

Pain points

Based on historical lessons, the brief summary of the pain points we want to solve on the access system is:

Authentication: WiFi and cable access to the device / IP can be bound to the case, the investigation of security incidents can be targeted to people

Permissions restrictions: different functions of the crowd network permissions are not the same, the minimum permissions

Security reinforcement: to meet the company's baseline security requirements of the equipment can access the network, did not install antivirus without patching to prohibit access

Any of the above problems, in fact, there are other solutions, such as binding mac and the like, but when we Beijing four buildings, two thousand RD, extensive use of wifi mobile office, wired network access to some buildings are silly hub , Some H3C 31, some Cisco 29, visual access to get on the.

Threesome must have my teacher

According to the rankings of the then gartner, we investigated the products of several foreign manufacturers and summarized the advantages of them under the following conditions:

Authentication and authorization integration with the Microsoft domain SSO

Wired and wireless switch automatically certified

Network Control Reduce network infrastructure dependencies on the third floor

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.