|
Security-Enabled
Infrastructure Centralized
Command and Control Advanced Security
Applications |
Trusted End-System SolutionView Solution Brief PDFProtecting the Infrastructure from Vulnerable or “Non-trusted” Systems
The Trusted End-System solution allows you to deploy cost-effective end-system admission control for every LAN-connected user. TES is part of the family of Secure Networks solutions that integrate advanced security and management features to centralize and automate granular control of the entire network infrastructure. With a Trusted End-System solution, you can not only minimize the disruption caused by vulnerable network devices but ensure seamless access for trusted users with up-to-date security profiles. It also provides effective protection against more sophisticated network threats by automatically quarantining suspect devices, greatly simplifying the deployment of security updates. There is no requirement for user interaction with this process. TES leverages the power of centralized, policy-based management, so it is easy to deploy and administer.
Benefits
Trusted End-System Solution Benefits
Implementation
The Foundation of a Trusted End
System Enterasys has developed two complementary approaches to the Trusted End-System solution to meet the needs of all types or sizes of enterprises. The Agent-Based Trusted End System is designed for interoperability with leading-edge endpoint security applications from Zone Labs and Sygate. Zone Labs “Integrity” and Sygate “Secure Enterprise” security software products have been certified by Enterasys Networks Security Response Team for interoperability within a Secure Networks infrastructure. Security policy rules and profiles are defined and distributed using the NetSight™ Atlas Policy Manager application. When a user or device attempts to connect to the network, the end system is assessed via the Zone Labs or Sygate security agent. The results of this evaluation are forwarded to an Assessment Server and Authentication Server to determine the level of trust. If the results of both authentication and security assessments are positive, the Matrix™ switch will permit network access in conformance with security policies. If the results of the security assessment are negative, the user or device is assigned a Quarantine Role until the corrective actions have been taken. The Network-Based Trusted End-System solution complements the agent-based approach. It does not require a security agent to reside on each connecting device, making it particularly useful for organizations such as universities that often cannot control the number or type of end systems accessing the network. Once again, NetSight Atlas Policy Manager defines the end-system security requirements. When a user or device first attempts to connect to the network, its credentials are passed to an Authentication Server while the end system is scanned using vulnerability assessment and operating system patch assessment tools. This process is used to determine if that device meets the requirements for a trusted end system.
Key Components
The Trusted End-System (TES) solution is built using these core products: Matrix™ Switches
Why Enterasys
What Sets Enterasys' Trusted End
System Solution Apart Importantly, the Trusted End-System solution is designed to enhance already installed Secure Networks solutions, and can be deployed with a relatively cost-effective upgrade. A range of associated professional services are also available to assist with the rapid configuration and optimization of the TES solution. Like all Enterasys Secure Networks solutions, the Trusted End-System solution was developed using open standards to interoperate in multi-vendor environments for simplified deployment, inherent scalability and greater overall investment protection. |
IT administrators know that many workstations
and other networked devices connect
to the corporate infrastructure without the
latest security updates. These end systems
are vulnerable to malicious attacks that
could compromise critical resources, leading
to business disruption and revenue impairment.
Enterasys’ Trusted End-System
(TES) solution uniquely addresses this
challenge, enhancing your organization’s
overall security posture to maximize network
availability and business productivity.