Solution Brochure Juniper Networks Solution Portfolio for Public Sector Network Security Protect against Network Downtime, Control Access to Critical Resources, and Provide Information Assurance STRM NS-Security Manager Infranet Controller On-Line Reporting Data Virtual Chassis Finance Video SSL VPN Firewall Apps Internet
2 Juniper Networks Juniper Networks Solution Portfolio for Public Sector Network Security Juniper Networks Public Sector Security Solution Overview Juniper Innovation in Government is a high-performance network infrastructure that enables next-generation networks, providing the responsive and trusted environment needed to fuel government transformation. Network security has always been a high priority within various public sector organizations with the need to protect people, privacy and assets. This challenge is now rising to new levels as many public sector organizations attempt to enhance their cyber security perimeter defenses. While various types of security protections are being integrated into public sector network infrastructures, many departments and organizations are still struggling with a mixture of security solutions that may or may not work together. This solution brochure provides an overview of the Juniper Networks public sector network security solutions for military defense, criminal justice, public administration, healthcare, and research and education organizations. These security solutions are designed to work with each other and with other leading security vendors solutions, keeping your network, applications and data safe, private and reliable.
3 Challenges High-performance governments view the network as critical to achieving mission objectives, but are under tremendous pressure to keep up with escalating demands and risks with fewer resources, which jeopardizes their effectiveness. As public sector organizations extend communications and applications to a broader set of users, the flow of electronic information is growing and becoming more diverse. These needs must be managed by public sector IT departments in conjunction with a safe and always available network. Public sector IT departments face a constant balancing act with network security, as they are expected to implement and manage increasingly complex network security at a reasonable cost. The key challenge is how to lock down the network as tightly as possible, while not limiting the flexibility and communications that help increase productivity and spur government transformation. Trends Today, several trends are influencing public sector network security. Network perimeters are more dynamic as organizations expand and contract secure network access to mobile workers, contractors and partners. More public sector locations and users are connecting directly to the Internet rather than funneling through headquarters. While this may be faster and more convenient, it also exposes the public sector organization s network to greater security risks. Content-rich, collaborative and geospatial applications are driving the demand for securing, optimizing, and having visibility and control over applications across the network. External to the public sector, cyber threats are becoming more financially and criminally motivated, leading to an increase in targeted attacks. Public sector organizations are looking for security solutions that work together to protect against emerging network and application threats, control access to valuable resources, and help public sector departments comply with the growing number of government and industry regulations. Juniper Networks Solution Portfolio for Public Sector Network Security Juniper s Innovation in Government creates efficient, high-performance security solutions by providing a responsive and trusted networking environment. This helps public sector IT managers protect users, devices and data against threats, secure access to network resources, and help meet compliance requirements. Our public sector network security solution portfolio includes: AAA/802.1X solutions authenticate and authorize network access, and secure data transmission and communication into and throughout your network. Unified Access Control (UAC) solutions combine user identity, device health, location and policy information to ensure appropriate network access. Integrated Firewall/IPSec VPN/Unified Threat Management (UTM) appliances deliver highperformance network and application protection from internal and external attacks such as worms, viruses, trojans and spyware. SSL VPN appliances offer ubiquitous yet secure application access to remote employees, business partners and clients. Intrusion Detection and Prevention () solutions protect against application layer attacks and discover rogue servers and applications on the network. Juniper Networks Security Threat Response Manager (STRM) delivers centralized log and event management, correlation, reporting, and network behavior anomaly detection. Juniper Networks NetScreen-Security Manager (NSM) delivers centralized network security command and control.
4 Juniper Networks Juniper Networks Solution Portfolio for Public Sector Network Security Built on the same platforms and software that power the world s largest service providers, our network security solutions are a strategic part of any high-performance network. Public sector organizations worldwide are leveraging Juniper solutions to boost their productivity by providing fast, reliable and secure access to network applications and services. With these solutions, your organization can achieve: Adaptive threat management Network access control Improved regulatory compliance Adaptive Threat Management The Juniper Networks Adaptive Threat Management Solution is a highly adaptive and scalable solution consisting of a tightly integrated network security and management portfolio. It provides real-time response to today s ever-changing security landscape and business needs. Juniper s Adaptive Threat Management is a multi-layered security solution consisting of several key components. STRM NS-Security Manager Infranet Controller On-Line Reporting Data Virtual Chassis Finance Video SSL VPN Firewall Apps Figure 1. Juniper Networks Adaptive Threat Management Solution Internet High-performance firewalls protect the network perimeter by using dynamic packet filtering known as stateful inspection to deny malicious traffic. The firewall collects information on the malicious traffic and when the next packet arrives from a malicious entity, it is flagged using the state information. Stateful inspection provides a higher level of security compared to traditional firewalls by opening pin holes through which legitimate traffic can flow. By using policy-based management, security policies can be defined to permit traffic from specified sources to specified destinations. The second component is a market-leading system with up to a 10 Gigabit performance. Traffic permitted by the firewall is next inspected by to stop network and application-level attacks. The effectively provides day-zero protection against worms, viruses, trojans, spyware, keyloggers and other malware. It also provides information on rogue servers, as well as types and
5 versions of applications and operating systems that may have unknowingly been added to the network. The works tightly in conjunction with the Juniper Networks Secure Access (SA) SSL VPN remote access product to automatically disable remote sessions upon detecting malicious activity and quarantine the remote user or host. This automatic action helps prevent further damage to enterprise resources when an attack occurs. The Adaptive Threat Management solution includes the industry-leading management platform, Security Threat Response Manager and Juniper Networks NSM. STRM aggregates and correlates network and security information from all security components and provides extensive visibility into all threats and attacks. Further, STRM can proactively take corrective action in response to threats and attacks. NSM enables IT administrators to centrally provision and manage all aspects of the threat management solution. The strength of this solution is that all of the components work seamlessly and cohesively to create a comprehensive, scalable and adaptive protection mechanism for meeting the needs of the public sector enterprise. Flexible Access Control Like many public sector organizations, yours probably has employees, citizens and partners with wide-ranging duties and varying levels of responsibility, who use a variety of endpoint devices to access your network. Your challenge is to offer these users easy network access while maintaining your necessary privacy, network integrity and data security. To do this, you need a solution that limits individual user access to job/user-appropriate resources. Juniper s award-winning Secure Access SSL VPN and UAC network access control solutions restrict network access based on user identity, endpoint device health and location. They restrain non-compliant users and devices from accessing resources, helping eliminate threats. These solutions work with your existing network elements, business applications and identity management solutions to safeguard critical network resources and protect against network downtime and loss to the business. When used in conjunction with Juniper, both of these solutions provide an added level of threat protection by isolating threats at the user and endpoint device level. The standards-based UAC solution also works seamlessly with any 802.1X access point or switch, including the Juniper Networks EX-series Ethernet switches. Govt HQ Wired/Wireless Mobile Dynamically handle guests, partners, contractors, unmanageable devices Mitigate threats by controlling access across wired/wireless networks Infranet Controller Centralized validation Distributed enforcement Switch Access Point Wireless ISG Control access to applications Gain visibility and control for user/device access to network, resources and applications Data Center ISG Branch Office Mobile SSG Flexible solution to support access control in distributed networks Internet Leverage for correlation network threat information to dynamically protect the network Figure 2. Juniper Networks UAC Solution
6 Juniper Networks Juniper Networks Solution Portfolio for Public Sector Network Security Simple Compliance Solutions Now more than ever, public sector organizations face a growing number of government and industry regulations. Many of these regulations are designed to make sure electronic records and information are secured properly. Network compliance projects implemented on a per-project basis often result in increased equipment and operational costs, waste and redundancy. A better approach to meeting evolving compliance requirements is a flexible set of integrated solutions that fit into your existing infrastructure and provide maximum return on investments, while simultaneously managing risk and change. Juniper enables you to comply with regulatory and corporate governance standards with bestin-class security solutions that offer a flexible architecture for securing servers, protecting transported data, controlling access to network resources and data, and enforcing proper endpoint device health, monitoring and logging. Juniper firewall/vpn/utm and Juniper platforms secure data from malicious and unintentional attacks and monitor network events. Juniper s Secure Access SSL VPN and UAC solutions control remote and local access to networks, applications and data, and they help agencies meet their Continuity of Operations (COOP) requirements for secure teleworking. STRM and NSM offer centralized monitoring, reporting and provisioning of the network, reducing ongoing operational challenges and associated costs. Bottom line, these solutions help organizations meet corporate governance requirements and gain the best total cost of ownership over a longer compliance solution window. Network Security Solution Planning, Implementation and Deployment Juniper Networks provides a comprehensive and flexible portfolio of industry-leading technical support, professional services and education programs to help customers and partners realize maximum value from their network investments. Support Services provide the support that large networks demand, and let customers select from a variety of options to augment their in-house technical expertise. There are 15 Juniper Networks Global Technical Assistance Centers (JTACs) located around the world that manage customer cases 24x7x365. Professional Services provide customized consulting services to assist customers in planning and designing networks with maximum efficiency. Educational Services deliver expert education and technical certification programs to help customers build their IP network expertise through standard technical programs, Web-based courses, customized workshops and hands-on lab sessions.
7 Public Sector Network Security Solution Matrix The following matrix shows which Juniper Networks solutions are appropriate for different public sector locations: Table 1: Public Sector Network Security Solution Matrix Enterprise Location Data Center Campus Branch/Regional Office Mobile/Remote Workers Business Partners Firewall/ VPN Integrated Security Gateway (ISG) series NetScreen-5000 series ISG series NetScreen-5000 series Secure Services Gateway (SSG) series SSG 5 SSG 20 Intrusion Prevention Secure Remote Access SSL VPN SA 4500/6500 Security Integrated into Routing/ Switching Platforms MX-series M-series EX-series 800/8200 SA 4500/6500 MX240 M7i/M10i EX-series Policy and Management Infranet Controller (IC) series NSM WX Central Management System (CMS) IC series NSM Odyssey Access Client (OAC) 75/250 SA 700/2500 J-series UAC Agent provided from central location 200 Secure Clientless Access UAC Agent provided from central location Summary Achieve Your Business Goals with the Help of Juniper s Security Solutions Public sector organizations worldwide are leveraging Juniper solutions to achieve their business goals, improve citizen and user satisfaction, and drive down the cost of operating and maintaining their secure networks. Juniper s network security solutions can integrate easily into your branch or regional offices, data centers, and headquarters or campus locations. For more information on increasing network security while simplifying operations, please visit www.juniper.net.
8 Juniper Networks Juniper Networks Solution Portfolio for Public Sector Network Security CORPORATE HEADQUARTERS AND SALES HEADQUARTERS FOR NORTH AND SOUTH AMERICA Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA Phone: 888.JUNIPER (888.586.4737) or 408.745.2000 Fax: 408.745.2100 www.juniper.net About Juniper Networks Juniper Networks, Inc. is the leader in high-performance networking. Juniper offers a high-performance network infrastructure that creates a responsive and trusted environment for accelerating the deployment of services and applications over a single network. This fuels high-performance businesses. Additional information can be found at www.juniper.net. EAST COAST OFFICE Juniper Networks, Inc. 10 Technology Park Drive Westford, MA 01886-3146 USA Phone: 978.589.5800 Fax: 978.589.0800 ASIA PACIFIC REGIONAL SALES HEADQUARTERS Juniper Networks (Hong Kong) Ltd. 26/F, Cityplaza One 1111 King s Road Taikoo Shing, Hong Kong Phone: 852.2332.3636 Fax: 852.2574.7803 EUROPE, MIDDLE EAST, AFRICA REGIONAL SALES HEADQUARTERS Juniper Networks (UK) Limited Building 1 Aviator Park Station Road Addlestone Surrey, KT15 2PG, U.K. Phone: 44.(0).1372.385500 Fax: 44.(0).1372.385501 Copyright 2008 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. JUNOS and JUNOSe are trademarks of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. To purchase Juniper Networks solutions, please contact your Juniper Networks sales representative at 1-866-298-6428 or authorized reseller. 160030-001 May 2008