Providing 802.1X Enforcement For Network Access Protection Mudit Goel Development Manager Windows Enterprise Networking Microsoft Corporation.

Slides:



Advertisements
Similar presentations
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements

© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Feature: Purchase Requisitions - Requester © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
May 30 th – 31 st, 2006 Sheraton Ottawa. Network Access Protection Gene Ferioli Program Manager Customer Advisory Team Microsoft Corporation.
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Feature: Payroll and HR Enhancements © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Agenda Introduction Network Access Protection platform architecture
Network Access Protection Platform Architecture Joseph Davies Technical writer Windows Networking and Device Technologies Microsoft Corporation.
Jayson Ferron CIO Interactive Security Training WSV206.
Co- location Mass Market Managed Hosting ISV Hosting.
Getting Ready for Network Access Protection Jeff Alexander Technology Advisor Microsoft.
Sreenivas Addagatla - Development Lead Lambert Green - Test Lead Microsoft Corporation.
Windows Server 2008 Network Access Protection (NAP) Technical Overview.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Windows 7 Training Microsoft Confidential. Windows ® 7 Compatibility Version Checking.
Feature: Web Client Keyboard Shortcuts © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Session 1.
Built by Developers for Developers…. © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Damian Leibaschoff Support Escalation Engineer Microsoft Becky Ochs Program Manager Microsoft.
1 Week #7 Network Access Protection Overview of Network Access Protection How NAP Works Configuring NAP Monitoring and Troubleshooting NAP.
Feature: Assign an Item to Multiple Sites © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Using the WDK for Windows Logo and Signature Testing Craig Rowland Program Manager Windows Driver Kits Microsoft Corporation.
Implementing Network Access Protection
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Feature: Print Remaining Documents © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
Asif Jinnah Microsoft IT – United Kingdom. Security Challenges in an ever changing landscape Evolution of Security Controls: Microsoft’s Secure Anywhere.
Connect with life Connect with life
Windows Azure Connect Name Title Microsoft Corporation.
Module 8: Configuring Network Access Protection
FonePlus Hugh Teegan Architect Mobile Devices Microsoft Corporation.
Module 9: Designing Network Access Protection. Scenarios for Implementing NAP Verifying the health of: Roaming laptops Desktop computers Visiting laptops.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Feature: Document Attachment –Replace OLE Notes © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product.
Feature: Customer Combiner and Modifier © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Feature: Employee Self Service Timecard Entry © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Sudarshan Yadav Sr. Program Manager, Microsoft
Welcome Windows Server 2008 安全功能 -NAP. Network Access Protection in Windows Server 2008.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
demo Instance AInstance B Read “7” Write “8”

Configuring Network Access Protection
customer.
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
May 30 th – 31 st, 2007 Chateau Laurier Ottawa. Securing Your Network – End to End Connectivity Pat Fetty Senior Program Manager Windows Customer Advisory.
NAC-NAP Interoperability
demo Demo.
© 2008 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED,
demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
projekt202 © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
Module 6: Network Policies and Access Protection.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Module 5: Network Policies and Access Protection
Asif Jinnah Field Desktop Services Enabling a Flexible Workforce, an insider’s view.
D-Link Wireless AP with NAP 802.1x solution
Implementing Network Access Protection
Deriving more value from your Windows investment
Title of Presentation 12/2/2018 3:48 PM
System Center Marketing
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
Шитманов Дархан Қаражанұлы Тарих пәнінің
Title of Presentation 5/24/2019 1:26 PM
NAP / PWG Discussion August 17, 2009.
Presentation transcript:

Providing 802.1X Enforcement For Network Access Protection Mudit Goel Development Manager Windows Enterprise Networking Microsoft Corporation

Goals Overview Network Access Protection (NAP) – architecture and extensibility Demonstrate 802.1x NAP Target audience Hardware Vendors (e.g.: 1x hardware) Connectivity software (1x supplicant, EAP methods)

What Is In It For You? Add value to your hardware based products or solutions Demonstrated interoperability with NAP Easy configuration of 1x Hardware for NAP Unique value that you can add to your device Easier to develop EAP related software EAP extensibility model Client: Supplicants and Methods Server: Methods More satisfied customers

Internet Intranet Remote Employees Remote Access Gateway Web Server Customers Perimeter X Infrastructure Servers Extranet Server Business Partners Life In A Highly-Connected World Interconnected networks Distributed data Mobile workers Business extranets Remote access Web services Wireless Mobile smart devices

Problem Very little isolation in network Customers control very small percent of endpoints De-perimeterization of devices happening now Customers have little or no way of enforcing or even validating security policy compliance Need for security at multiple layers

Network Access Protection (NAP) Solution Overview Policy Validation Are computers “healthy” – compliant with company’s security policy Network Restriction Restrict network access based on their health Remediation Provides necessary updates to become healthy Once healthy, the network restrictions are removed Ongoing Compliance Changes in computers’ health may dynamically result in network restrictions

Requesting access. Here’s my new health status Network Access Protection Walk-Through Microsoftnetwork policy server Client 802.1xSwitch / AP Remediationservers May I have access? Here’s my current health status Should this client be restricted based on its health? Ongoing policy updates to NPS Policy Server You are given restricted access until fix-up Can I have updates? Here you go According to policy, the client is not up to date. Quarantine client, request it to update Corporate Network Restricted Network Client is granted access to full intranet System health servers According to policy, the client is up to date Grant access

Microsoft Network Policy Server (NPS) NAP Server (QS) Client NAP Agent (QA) Health policy Updates HealthStatements NetworkAccessRequests System Health Servers Remediation Servers HealthCertificate Network Access Devices and Servers System Health Agent (SHA) MS and 3 rd Parties Enforcement Client (EC) (DHCP, IPSec, 802.1X, VPN) NAP Architecture Overview Client SHA – health agents check client state QA – coordinates SHA/EC EC – method of enforcement Remediation server Serves up patches, AV signatures, etc. Network access devices and server Access points, switches, VPN servers, HRA Network Policy Server QS – coordinates SHV SHV – validates client health System health server Provides client compliance policies System Health Validator (SHV) MS and 3 rd Parties

Extending NAP Published APIs SHA API QEC API SHV API EAP Host Supplicant EAP Host Method (Peer and Authenticator) 802.1x client extensibility Licensed Protocols SoH / SoHR RADIUS extensions EAP TLVs Health Certificate Enrollment Protocol Health policy Updates System Health Servers HealthStatements NetworkAccessRequests HealthCertificate Network Access Devices and Servers Remediation Servers Microsoft Network Policy Server NAP Server (QS) System Health Validator (SHV) Microsoft and 3 rd Parties 3 rd party EAP methods PEAP EapHost Client 3 rd party EAP methods 3 rd party EAP supplicants NAP Agent (QA) System Health Agent (SHA) Microsoft and 3 rd Parties EapHost 802.1x supplicant PEAP EapQEC 3 rd Party QEC

RADIUS Attributes For NAP Microsoft-Quarantine-State Machine access should be Full Access Quarantined Probation until a certain time Microsoft-Quarantine-Grace-Time Specified date and time for probation Microsoft-IPv4-Remediation-Servers Collection of IPv4 addresses of fixup servers Microsoft-IPv6-Remediation-Servers Collection of IPv6 addresses of fixup servers Microsoft-Attribute-Not-Quarantine-Capable Machine requesting access is not participating in NAP

EAP Extensibility Supplicant API 3 rd party EAP supplicants can plug-in e.g. 802.x, IKEv2, VPN Supplicants can become NAP aware by using EapHost Method API Enables 3 rd party methods to plug-in e.g. EAP-TTLS, EAP-SIM, EAP-FAST 802.1x (EAP) RADIUS (EAP) 802.1x AP / Controller Microsoft Network Policy Server Quarantine Server (QS) System Health Validator 3 rd Party EAP Methods PEAP EapHost Client 3 rd Party EAP Methods 3 rd Party EAP Supplicants NAP Agent (QA) System Health Agent (SHA) Microsoft and 3 rd Parties EapHost 802.1x supplicant PEAP EapQEC 3 rd Party QEC

Network Access Protection Demo Chandra Nakula Test Lead Windows Enterprise Networking

Demo Setup NPS Server (Radius) Vista Client DHCP Server HP Pro-curve Switch

802.1x Wired NAP Restricted VLAN Full Access VLAN ??EAP PEAP Radius Client NPS Server (Radius) Switch

Call To Action NAS Devices (1x APs / Controllers) Ensure that your device works with NAP Value: Device is NAP capable and hence more attractive to customers Use the NAP related RADIUS attributes to make your configuration for NAP easier Value: Customers would find it easier to configure your device from NPS for NAP Extend NAP to deliver value to the customer On the client, switch, or end to end

Call To Action NICs, EAP Supplicants, EAP methods Test NAP interoperability with your hardware Extend NAP to deliver value to the customer (Adopt EAPHost and NAP) Write EAP methods to Eaphost Leverage NAP in hardware, supplicants and EAP methods Use EAPHost extensibility to build your supplicants Work with us to address 802.x challenges Multi-MAC Heterogeneous environments Bootstrapping Timing issues

Additional Resources Web Resources NAP: EAP: Additional Resources Information on NAP SDK distribution WDK – actual working sample EAP Methods and Supplicant MSDN – EH Documentation and API references s Questions or feedback NAP:EAP: microsoft.com microsoft.com microsoft.com

Q&A

© 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.