Dynamic Segmentation
The Dynamic Segmentation solution is Aruba's security architecture that provides the ability to dynamically assign roles and enforce application-aware policies to all devices connecting to the infrastructure, regardless of connection method (wireless, wired or VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two.). ClearPass Policy Manager provides robust policy management and orchestration capabilities to derive roles, based on user and device identity, device profiling, and health along with time and location.
Two primary enforcement options for wired enforcement in Dynamic Segmentation are:
User-Based Tunneling
Port-Based Tunneling
In earlier releases, this feature was called per user tunneled node, which was built on top of Aruba’s per port tunneled node (now known as port-based tunneling. Port-based tunneling allows the switch to tunnel traffic to an Aruba Mobility Controller on a per-port basis i.e., all traffic on a configured switch port was statically tunneled to an Aruba Mobility Controller. User-based tunneling implements the capability to tunnel traffic on a user role-basis or device basis, tunneling traffic of a given client or device, based on an assigned user role. The policies associated with that client could be driven through a RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources. server such as ClearPass Policy Manager, a downloaded role from ClearPass Policy Manager, or by local MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. authentication in the switch. User-based tunneling can authenticate these devices using ClearPass Policy Manager, and tunnel the client traffic, utilizing the advanced firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. and policy capabilities in the Aruba Mobility Controller. It can also provide high availability and load balancing with controller clustering in ArubaOS 8.4.0.0, providing secure access to IoT Internet of Things. IoT refers to the internetworking of devices that are embedded with electronics, software, sensors, and network connectivity features allowing data exchange over the Internet. devices within the Aruba Intelligent Edge wired network.
|
|
Live upgrade in a cluster deployment is not supported as part of the wired Dynamic Segmentation solution. |
Was this information helpful?
Great! Thanks for the feedback
Sorry about that! How can we improve it? Send your comments and suggestions!