1、Cisco Confidential 2010 Cisco and/or its affiliates. All rights reserved. 1移 动终 端整合解决方案李 嵩SBN Security TeamCisco Confidential 2010 Cisco and/or its affiliates. All rights reserved. 2 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3SOURCES: A, Public Filings, Morgan Stanley
2、 Research, Gartner, IDCPC/Web 时代 后 -PC 时代移动优先 时代 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4“如何掌控多种移动 OS?”“如何分发 APP应用,如何推进 BYOD?”“如何分发文档资料并保证安全 ?”“如何保证信息安全合规 ?”“我需要不停的去满足用户的新需求 , 同时还有确保安全合规 ” 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5无
3、 线 网 络CiscoPrime Infrastructure有 线 网 络CatalystSwitchesIdentity Services Engine (ISE)Cisco WLCMDM Mobile Device ManagerVPN接入 MDM ManagerMobility Services Engine(MSE)CiscoAnyConnect 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6Enterprise App Mgmt (Distribution, Config)Inv
4、entoryManagement Device Management (Backup, Remote Wipe, etc.)Policy Compliance (Jailbreak detection, PIN lock, etc.)Secure Data ContainersAcceptable Use Policy (AUP)Classification/ProfilingRegistrationSecure Network Access (Wireless, Wired, VPN)Context-Aware Access Control (Role, Location, etc.)Cer
5、t + Supplicant Provisioning User Device OwnershipMobile + PC设备管理网络层管控 管控融合MDM 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7 ISE通 过 和下面六家 MDM厂商合作,开放 API接口 进 行互 联 Cisco 通 过测试 的厂商如下, ISE 1.3 我 们 会有更多的 MDM厂商加入 : AirWatch Version 6.2 MobileIron Version 5.5 SAP Afaria 7.0 SP3
6、 Citrix (Zenprise) Version 7.1 Good Technology Version 2.3 Fiberlink MaaS360 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 设备 注册 周期性的合 规 性 检测 非合 规 性修复 通 过 ISE 进 行 设备远 程操作 客 户终 端 设备 自管理功能 2010 Ci
7、sco and/or its affiliates. All rights reserved. Cisco Confidential 10User: Group: Certificates: Device Registered: Manufacturer: Model: OS Version: Apps:Encryption: Password: Compromised:Profiles:Ownership: Location: Cisco ISE MobileIron设备 注册 设备 注册启用 VLAN 移除企 业 Email启用 ACL 初始提示安装企 业应 用启用 group ACL 移
8、除被管控的企 业应 用启用 ToS (为 QoS使用 ) 移除企 业应 用 访问权 限URL 重定向 移除企 业 数据Tag 数据包 选择 性擦除企 业 数据整机擦除数据应 用企 业 网 络 及安全配置移除企 业 网 络 及安全配置设备状态 + 管控动作MobileIron深度设备状态识别Cisco ISE网络层管理动作 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11User: Group: Certificates: Device Registered: Manufacturer: Mo
9、del: OS Version: Apps:Encryption: Password: Compromised:Profiles:Ownership: Location: 模拟场景 : 未注册 iPad进入企业网络环境 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12注册成功 :设备网络策略部署完毕,给予企业内网访问权限终端状态 Posture实时检查设备是否合规User: UnknownGroup: UnknownCertificates: NoneDevice Registered: N
10、oManufacturer: UnknownModel: UnknownOS Version: UnknownApps: UnknownEncryption: UnknownPassword: UnknownCompromised: UnknownProfiles: UnknownOwnership: UnknownLocation: HQCisco ISE:授权访问 WiFi限制访问权限 于客户 vLan重定向浏览器访问设备注册地址移交至 MobileIron设备注册MobileIron:设备注册 MDM配置设备安全策略 :- 锁屏密码- 数据加密策略- 禁用摄像头- 禁用 iCloud配置
11、企业 Email 加密附件策略分发企业应用 (初始化提醒安装 )- 配置 Cisco AnyConnect 配置企业侧 SharePoint的安全访问安装快捷图标 访问 IT及财务门户模拟场景 : 未注册 iPad进入企业网络环境 ISE 及 MDM管控动作 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13移除违规 App后 :恢复所有网络权限SharePoint访问 , 企业电子邮件及企业应用 Apps自动重新部署User: Chris WilliamsGroup: FinanceCert
12、ificates: PresentDevice Registered: YesManufacturer: AppleModel: iPadOS Version: 6.1Apps: Violation - DropboxEncryption: EnabledPassword: EnabledCompromised: NoProfiles: PresentOwnership: CorporateLocation: HQCisco ISE:禁止访问企业文件服务器重定向浏览器访问 AUP用户规范内网页面设备处于隔离 vLan环境 仅提供自我矫正所需的网络权限模拟场景 : 用户安装违规应用 Apps自动
13、矫正违规行为 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14基于域控 AD的策略变化 :所有的策略变化都基于企业 AD的变化User: Michelle JonesGroup: DirectorateCertificates: PresentDevice Registered: YesManufacturer: AppleModel: iPadOS Version: 6.1Apps: NoneEncryption: EnabledPassword: EnabledCompromised:
14、NoProfiles: PresentOwnership: CorporateLocation: HQCisco ISE:标记数据包启用加密传输标记 VOIP 优先传输授权访问内部加密文件模拟场景 : 用户提升为管理层与企业AD无缝集成自动授权Cisco Confidential 2010 Cisco and/or its affiliates. All rights reserved. 15 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16Access-AcceptRegistered D
15、evice NoMyDevicesISE BYOD RegistrationYesMDMRegistered NoISE Portal Link to MDM OnboardingYes 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 2010 Cisco and/or its affiliates. All rights reserve
16、d. Cisco Confidential 19这 个需要注意 证书 中的FQDN 是域名 还 是 IP地址 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 导 入 MDM证书 到 ISE中 ISE和 MDM时间 不能超 过 5分 钟 。最后都 设 置 NTP服 务 器。 ISE 添加 MDM服 务 器 时 ,可以用 IP也可以用 Domain name,但如果 证书FQDN是 Domain Name 就必 须 使用 统 一的信息。 分配 API权 限 给 互 联账户 。 2010 Cis
17、co and/or its affiliates. All rights reserved. Cisco Confidential 21 ISE 能 设 置下面的 15种属性 值 ,MDM合 规 属性可以提供更多的 组 合 合 规 性 检测类 : 此功能通 MDM服 务 器反 馈验证结 果 移 动设备 合 规检测 PIN密 码检测 越 狱 信息 硬件厂商信息,包括厂商名字,型号 类 型,序列号,操作系 统 版本。 每 4小 时 会重新 检测 一次,如果不合 规 会 发 送 CoA 中断 认证 会话合 规 性 设 置需要在 MDM合 规 性 设 置需要在 ISE配置 2010 Cisco and
18、/or its affiliates. All rights reserved. Cisco Confidential 22 移 动终 端登 录 需要 进 行安全合 规检测Jail BrokenEncryptionISE Registered PIN LockedMDM Registered Jail Broken安全合 规检测 条件 授 权 策略 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23Own Common Task 2010 Cisco and/or its affiliates
19、. All rights reserved. Cisco Confidential 24 为 管理 员 和用 户 界面集成了 MDM功能,用 户 可以通 过 自管理 页 面 发 送 请 求 给 MDM 服务 器, 进 行 远 程操作 (例如 : 远 程 设备 擦除 ) MyDevices Portal Endpoints Directory in ISE 编辑 复原 设备 丢 失 处 理 删 除 全部擦除 公司内容擦除 PIN锁 定选项 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2525
20、2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26 iOS 平台接入 过 程体 验 (以 iOS 7.x 为 例) Andriod平台接入 过 程体 验 (以 Andriod 4.3 为 例) 部署配置文档下 载 link: http:/hkg-filer03b-web/wg-s/security_solutions/Published/Chinese%20documents/Security%20Knowledge%20Share/ 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29