Showing posts with label Cisco solution. Show all posts
Showing posts with label Cisco solution. Show all posts

Wednesday, September 12, 2007

IronPort OS Gets Encryption Update

Cisco Systems' IronPort division is perhaps best known for its anti-spam e-mail appliances and technologies. But it wants to be known for more.

That might happen with the new encryption and data-loss prevention (DLP) features it's rolling out in its new AsyncOS operating system 5.5 release. The AsyncOS operating system powers IronPort's e-mail security appliances.

"This is data-loss prevention made easy," Nick Edwards, project manager for IronPort, told InternetNews.com. It takes advantage of investments customers have made in their anti-spam infrastructures and gives them really good tools for data-loss prevention.

Edwards added that AsyncOS started from a FreeBSD kernel on which IronPort developed its own proprietary MTA (mail transfer agent) and other features.

Among the key enhancements in AsyncOS 5.5 is full e-mail encryption. Edwards explained that all encryption takes place at the gateway of the sending organization and can be done by policy.

Once an outbound message has hit the server, an e-mail message is sent to the recipient that says they have a secure message waiting for them and if they go to a specific Web site login, they can retrieve it.

"It provides for a universal approach for deploying encryption without the need for some kind of end-to-end compatibility," Edwards said. "It takes complexity off the table and makes deployment easier."

According to Edwards, the fact that a recipient has to click on a link and go to a Web site to see their encrypted mail has not had any push back from customers.

The new AsyncOS release also helps users more easily tag and identify e-mail that should not be leaving the enterprise. Called "smart identifiers," they help to identify content, such as Social Security and credit-card numbers that should not be in outbound e-mail.

Edwards noted that IronPort had the ability to do custom filters prior to this release, but customers had to do a lot more manual lifting. Smart identifiers are intended to be as easy as point and click.

"The reason why it's called smart identifiers and not just identifiers is we've introduced logic to allow the platform to understand what it's looking at," Edwards explained.

Though the new AsyncOS adds features, existing users shouldn't necessarily expect that it will improve the performance of their e-mail security appliance. Edwards described the performance as "flat" for existing customers for the features they're already using.

"But if someone is going to deploy encryption, which is pretty CPU intensive, it depends on their rollout and how much mail they will encrypt," Edwards said. "We're not in the business of promising customers that they'll never experience a performance decline, but we are committed to giving them parity for their existing feature set release to release."

The release is the first made by IronPort since being acquired by Cisco (Quote) earlier this year for $830 million. Though it's still relatively early in the integration, Edwards noted that there are a lot of interesting opportunities for IronPort to interoperate with Cisco.

"Cisco has a ton of products all across the network infrastructure and many look interesting to us to deploy our security technology on."

Monday, August 27, 2007

Intel adds desktop NAC to latest chips

Intel's move to provide new integration with NAC (network access control) tools in its latest vPro desktop processors could provide interesting opportunities for use with the device authentication systems while further strengthening the technology standards it supports, according to industry watchers.

One of a handful of new security features built into the vPro Core 2 Duo chips introduced by Intel on Monday, the added support for the 802.1x standard for NAC and interoperability with Cisco's Network Admission Control guideline -- delivered via the processors' Intel Embedded Trust Agent -- could help accelerate adoption of the device authentication systems while solidifying support for the two formats, experts said.

NAC systems are used to scan device and user authentication information whenever a machine attempts to log onto to a network protected by the tools. In addition to protecting against potential break-ins from uninvited outsiders, the tools are also considered a useful alternative for enterprises to employ in segregating access to IT systems shared with partners or contractors.

Using the Embedded Trust Agent, Intel said that it can now provide NAC systems -- including any built on the 802.1x or Cisco NAC platforms -- to garner device identity information directly from processor, bypassing the need for the authentication technologies to interact with PC operating system software.

One of the potential methods to circumvent NAC systems outlined by security researchers thus far has been to use some method to spoof or misrepresent device information to dupe the network defense tools. By presenting machine identity data on the processor, such attacks could be largely eliminated, Intel officials said.

While Intel did not promote direct linkage between Embedded Trust Agent and Microsoft's flavor of NAC -- known as Network Access Protection and already integrated into the software giant's Vista OS -- Cisco and Microsoft have previously announced an agreement to make all of their respective network authentication systems compatible.

Similar support for NAC on mobile platforms will arrive with Intel's next batch of Centrino chips, slated for shipment sometime in 2008, said company officials.

Cisco officials participating in Intel's vPro launch said that the CPU-level NAC integration could prove to be a significant accelerant to adoption of the technology, which most industry experts have charted as relatively slow thus far, despite the networking giant's claim that many of its customers are tuning on the next-generation authentication systems.

"The strength of NAC is certainly based on the reliability of the information that you can present to the network, and having direct access to information on the hardware provides a whole new opportunity that hasn't been present only with OS interaction," said Brendan O'Connell, senior product manager for Cisco's Security Technology Group.

"In the past, even with existing NAC systems, what's happened is that when a PC starts up on the network, the security decision is held off while other things are being run in the background, but we're hoping to see that change and get in the door earlier," he said. "There are some big advantages for getting this type of information to present device security posture assessment sooner in the process, both for desktops and down the road for other types of devices."

Monday, August 6, 2007

Cisco Introduces Innovative New Data Center Virtualization Orchestration Solution

Cisco has announced VFrame Data Center (VFrame DC), an orchestration platform that leverages network intelligence to provision resources together as virtualized services. This industry-first approach greatly reduces application deployment times, improves overall resource utilization, and offers greater business agility. Further, VFrame DC includes an open API, and easily integrates with third party management applications, as well as best-of-breed server and storage virtualization offerings.

With VFrame DC, customers can now link their compute, networking and storage infrastructures together as a set of virtualized services. This services approach provides a simple yet powerful way to quickly view all the services configured at the application level to improve troubleshooting and change management. VFrame DC offers a policy engine for automating resource changes in response to infrastructure outages and performance changes. Additionally, these changes can be controlled by external monitoring systems via integration with the VFrame DC web services application programming interface (API).

"Taking advantage of the ubiquity of the network to orchestrate data center services could help data centers evolve beyond their current siloed functions," said Lucinda Borovick, Director of Data Center Networks, IDC. "This approach has the potential to deliver more efficient application provisioning, reduce costs, and increase IT productivity."

VFrame DC is a highly efficient orchestration platform for service provisioning which requires only a single controller and one back-up controller. The real time provisioning engine has a comprehensive view of compute, storage and network resources. This view enables VFrame DC to provision resources as virtualized services using graphical design templates. These design templates comprise one of four VFrame DC modular components: design, discovery, deploy, and operations. These components are integrated together with a robust security interface that allows controlled access by multiple organizations.

Wednesday, June 27, 2007

50 School Districts Choose Parent Notification Solution from SchoolMessenger and Cisco

SchoolMessenger, a leading U.S. parental notification company, and Cisco, today announced that more than 50 school districts across the country have adopted their integrated parental notification solution. In addition, SchoolMessenger for Cisco Unified Communications, which was introduced last summer, now includes SMS text messaging to supplement voice and e-mail notification to reach a large audience using a range of devices.

Reports show that when notification solutions are used in schools, parents report improved peace of mind, and truancy rates decrease by up to 13 percent. In addition, by managing a single, centralized solution, and using its existing telecom investment, districts report that the solution pays for itself in less than two years when compared with annual subscription-based notification services.

SchoolMessenger for Cisco Unified Communications is a Web-based communications solution that integrates with a district's existing investment in Cisco Unified Communications. It is currently in use in 15 states, with the greatest concentration found in Texas and California.

More >>