| |
|
The division between the trusted
network and untrusted network has traditionally been a fixed
perimeter. This concept is no longer adequate because systems
routinely cross between untrusted and trusted networks. An infected
system can quickly infect other systems on the network after
catching a virus on the Internet.
The corporate LAN is especially vulnerable because network resources
are more open and prevalent. To remain safe and productive, the
network must ensure that all systems are compliant with corporate
security policies without impeding workflow.
CyberGatekeeper Server Appliance
CyberGatekeeper Server hardens the existing network by only allowing
access to authorised devices and reporting and blocking rogue
endpoints. Non-compliant endpoints are quarantined until remediation
brings them back into compliance.
The CyberGatekeeper Server appliance supports multiple methods for
managing access to the network. NAC methods include: the new Dynamic
NAC enforcement which requires no changes to infrastructure or
equipment; 802.1x NAC which uses VLANs; and in-line NAC which uses a
bridge to filter traffic in-line.
Capabilities provided by CyberGatekeeper Server include:
| - |
Authentication using 802.1x or Windows domains
|
| - |
Automatic and interactive remediation
|
| - |
Continuous validation of endpoint compliance
|
| - |
Centralised policy updates and configuration
|
| - |
NAC
quarantine methods include Dynamic NAC, 802.1x, and in-line
filtering |
How CyberGatekeeper
Server Works
Endpoints with agents participate in audits with CyberGatekeeper
Server. The server checks for compliance against security policies
and uses that information to create reports and control access to
the network. If a network device does not have an agent, it can be
white listed.
CyberGatekeeper Server supports different network access control
methods to restrict access. The appropriate access control mechanism
depends on the organisation's requirements and infrastructure.
Network Access Control methods include 802.1x, in-line, interfaces
to most SSL VPNs, and InfoExpress's Dynamic NAC which requires no
network changes.
If a rogue or non-compliant device is detected, CyberGatekeeper
blocks network access. If an unhealthy PC is detected,
CyberGatekeeper can automatically remediate the device or walk the
user through the remediation process.
|
|
|
New Page 1
Links
Introduction
DNAC
CyberGatekeeper Server
CyberGatekeeper Remote
|
|