MOBILITY BEYOND BYOD Jonas Gyllenhammar Consulting Engineer Junos Pulse solutions
BYOD DEFINED Corporate Owned Devices Employee Owned Devices (BYOD) Guest Devices Today's business environment requires coordinated access 2 Copyright 2012 Juniper Networks, Inc. www.juniper.net
USER EXAMPLES FOR MOBILITY Guest Devices Employee Owned Corporate Owned Doctor s own ipad Hotel employees on ipad Teacher s own ipad Student s own ipad Employee owned laptops, smartphones and tablets at an enterprise Visitors at a museum Visitors at an enterprise Hospital issued ipad School issued mobile devices Visitors at a hospital Visitors at a hotel Hospital issued laptops School issued laptops 3 Copyright 2012 Juniper Networks, Inc. www.juniper.net
MOBILE USER TYPES AND REQUIREMENTS Open Access, Guest Users Self provisioning Open, no encryption, captive portal Simple experience Device aware policy Differentiated access Guest Devices Corporate Issued Devices Self provisioning Secure certificate based authentication User, application, device aware policy Device management On-device security Secure network, cloud SSO Device agnostic Follow-me policies Application management Content monitoring Corporate Owned Devices Employee Owned Devices BYOD (Employee owned) Self provisioning Secure certificate based authentication User, application, device aware policies Device management On-device security Device, data loss, data theft prevention Secure network, cloud access Device agnostic Follow-me policies 4 Copyright 2012 Juniper Networks, Inc. www.juniper.net
VISIT THE SIMPLY CONNECTED LIVE DEMO AND TOMORROW S SIMPLY CONNECTED IN ACTION - AN OVERVIEW OF DIFFERENT USE-CASES 5 Copyright 2012 Juniper Networks, Inc. www.juniper.net
Enterprises should focus on mobile data protection (MDP), network access control (NAC), and mobile device management (MDM) tools to support their BYOD and new enterprise mobile platform efforts. MOBILITY BEYOND BYOD END TO END REMOTE ACCESS, ANYTIME, ANY DEVICE 6 Copyright 2012 Juniper Networks, Inc. www.juniper.net
CREATE YOUR DEVICE ACCESS REQUIREMENTS Client Deployed Mobile Security Mobile Device/Appl. Mgmt LAN/WLAN Access Remote Access Access to Corporate Resources Corporate Device Personal Device (BYOD) Guest Device Contractor / Consultant Device Its not about BYOD.. Its about an Access Management policy / solution. 7 Copyright 2012 Juniper Networks, Inc. www.juniper.net
JUNOS PULSE SINGLE CLIENT, GATEWAY MULTIPLE SERVICES Junos Pulse PCs & Macs Junos Pulse Smartphones & Tablets MAG Series Junos Pulse Gateway Junos Pulse Services supported: Junos Pulse Secure Access Service (SSL VPN) Junos Pulse Access Control Service (UAC) Junos Pulse Application Acceleration Service Junos Pulse Mobile Security Suite Access Enterprise Resources 8 Copyright 2012 Juniper Networks, Inc. www.juniper.net
ANYTIME, ANY DEVICE FROM ANYWHERE Identify User Device Role 1 Onboard Corporate or Personal On Campus Offsite From Home 2 Manage Device-specific Ensure Adherence to Policy 4 Secure 24/7 Protection Anywhere Loss & Theft 3 Protection Device Location 9 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EMPLOYEES ON PERSONAL/COMPANY OWNED DEVICE HOST CHECKING & APPLICATION RESTRICTION Corporate Network Junos Pulse Mobile Security Suite Remote onboarding & access and the highest level of security with automatic scan for latest OS, viruses signatures, jail broken Dr. Rose 369 Scan Connect is Clean Complete Access MAG Series Gateway running Junos Pulse Secure Access Service (SSL VPN) Any Device Any Guest Devices Time Employee Owned Corporate Owned 10 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EMPLOYEES ON CORPORATE LIABLE DEVICE ON BOARDING, HOST CHECKING AND APPLICATION RESTRICTION 1 User downloads Junos Pulse Client from App Store 2 JPMSS pushes: VPN Profile WiFi Profile SCEP Profile JPMSS delivers 24/7 security via AV & antimalware MDM such as password mgmt Jailbroken/ Compliant? Rooted? 3 The device initiates a tunnel to the MAG Series Junos Pulse Gateway 4 Secure Access Service runs a HostCheck on the device Active Directory /LDAP Data Finance Patch Remediation 8 Mobile User User has appropriate access to his role 7 User matched to corporate role 6 Valid user on AD; device is OK 5 Secure Access authenticates the user against AD MAG Series Junos Pulse Gateway running Secure Access Service SSL VPN Video Apps Corporate Data Center 11 Copyright 2012 Juniper Networks, Inc. www.juniper.net
EMPLOYEES ON CORPORATE LIABLE DEVICE APPLICATION RESTRICTION AND COORDINATED THREAT CONTROL 10 User requests data from application Client issues an attack of some kind 11 12 SRX get the User/Role/IP information. Applies AppSecure polices 9 Session is published to IF-MAP Active Directory /LDAP Data Finance SRX Series Patch Remediation 16 Mobile User User/device is Quarantined or Disconnected 15 SA gets the event and takes Action 14 UAC takes action or publish event to IF-MAP 13 SRX IPS detects the attack and issues a Sensor Event to UAC MAG Series Junos Pulse Gateway running both Secure Access Service Access Control Service Video Apps Corporate Data Center 12 Copyright 2012 Juniper Networks, Inc. www.juniper.net
DEMO 13 Copyright 2012 Juniper Networks, Inc. www.juniper.net
Q & A 14 Copyright 2012 Juniper Networks, Inc. www.juniper.net
15 Copyright 2012 Juniper Networks, Inc. www.juniper.net
16 Copyright 2012 Juniper Networks, Inc. www.juniper.net
17 Copyright 2012 Juniper Networks, Inc. www.juniper.net