24

NAP with IPSEC and PKI in a Real World

Embed Size (px)

Citation preview

Page 1: NAP with IPSEC and PKI in a Real World
Page 2: NAP with IPSEC and PKI in a Real World

Know University of Vila Velha

Phases of the Project

Demos

How to Start

Q&A

Page 3: NAP with IPSEC and PKI in a Real World

University of Vila VelhaThe first private university of ES with more than 32 years of expertise in higher education

Page 4: NAP with IPSEC and PKI in a Real World

University of Vila VelhaThe largest private library of Espírito Santo

Page 5: NAP with IPSEC and PKI in a Real World

University of Vila VelhaLaboratories of biomedical and agricultural courses

Page 6: NAP with IPSEC and PKI in a Real World

University of Vila VelhaComputing Labs

Page 7: NAP with IPSEC and PKI in a Real World

~ 18.000 Students

~ 1.200 Teachers

1.500 Computers

14 Buildings

Hospital

Laboratories of Biomedical

Agricultural course

4 Campi

+ 40 services for students and Teachers (WEB)

Radio

University TV

Page 8: NAP with IPSEC and PKI in a Real World

IT Team - DTI

4 Systems Analysts

5 Technical Support

2 Trainees

3 Shifts (from 07:00 to 23:00)

Page 9: NAP with IPSEC and PKI in a Real World

~ 60 attacks daily (only from our Labs !)

Hundreds of notebooks ( Teachers and Students) in the network

Physical network grow to fast

Students became more dangerous

Page 10: NAP with IPSEC and PKI in a Real World

Improve security for our Network

Restrict access for some Servers

Deploy more services to Students and Teachers

Improve the agility to changes in the Campus

Find the best solution - Security X Cost

Reduce TCO

Page 11: NAP with IPSEC and PKI in a Real World

Learn the flow of data in our environment

Documentation and classification of our services, data and network

Page 12: NAP with IPSEC and PKI in a Real World

Deploy Server and Domain Isolation (IPSec) with Kerberos

Merge Administrative and Student Network in the same physical network

Page 13: NAP with IPSEC and PKI in a Real World
Page 14: NAP with IPSEC and PKI in a Real World
Page 15: NAP with IPSEC and PKI in a Real World
Page 16: NAP with IPSEC and PKI in a Real World

Deploy PKI project

Deploy Wireless network for Students and Teachers

Change IPSec authentication from Kerberos for Certificates

- Secundary Benefits -

2-factor authentication (token for Admin access)

Improve security for VPN Access

Page 17: NAP with IPSEC and PKI in a Real World
Page 18: NAP with IPSEC and PKI in a Real World

Deploy NAP (Reporting Mode )

Page 19: NAP with IPSEC and PKI in a Real World
Page 20: NAP with IPSEC and PKI in a Real World

Deploy Forefront Client

Deploy NAP - Enforcement mode

Deploy NAP for Linux Clients

Page 21: NAP with IPSEC and PKI in a Real World

1. Understand how your data flow in your enviroment

2. Create a Documentation of groups, services, servers and exemption lists

3. If possible use PKI

4. Create a Project LAB for testing

5. Deploy IPSec with FallBack enable

6. Deploy NAP (reporting mode)

Page 22: NAP with IPSEC and PKI in a Real World
Page 23: NAP with IPSEC and PKI in a Real World

Microsoft Developer Network (MSDN)

(Webcasts, Blogs, Chats,

http://microsoft.com/msdn

Trial Software e Virtual Labs

http://www.microsoft.com/technet/downloads/trials/default.mspx

http://www.microsoft.com/nap

http://blogs.technet.com/nap/

Case IPSec - http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=49593

Case NAP - http://www.microsoft.com/brasil/technet/ithero/abril07/default.mspx

Article IPSec - http://www.microsoft.com/technet/community/columns/secmvp/sv0906.mspx

Microsoft Technet

(Webcasts, Blogs, Chats)

http://microsoft.com/technet

Page 24: NAP with IPSEC and PKI in a Real World

© 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market

conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation.

MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.