Home|Login|Register|Feedback|Help  
Select a Location / Language
English
 
ASIA PACIFIC
PRODUCTIVITY NOW
SECURITY
PRODUCT RESOURCES
Firewalls
Intrusion Detection Systems (IDS)
Virtual Private Networks (VPN)
Security Management (VMS)
Identity Management (ACS)
Web Filtering
e-Business Security (SSL)


POWERnow
Identity Management

Cisco Secure Access Control Server (ACS)

The Cisco Secure Access Control Server (ACS) is a high-performance, highly scalable, centralized user access control framework. Cisco Secure ACS offers centralized command and control for all user authentication, authorization, and accounting from a Web-based, graphical interface, and distributes those controls to hundreds or thousands of access gateways in your network. With ACS you can manage and administer user access for Cisco IOS¨ routers, virtual private networks (VPNs), firewalls, dial and broadband DSL, cable access solutions, voice over IP (VoIP), Cisco wireless solutions, and Cisco Catalyst¨ switches via IEEE 802.1x access control.

Get an overview of Identity Management

WHAT'S NEW

What's new in Identity Management:

  1. Cisco IOS software Identity Enhancements
    • PKI Infrastructure Support
      • Ability to use digital certificates between routers instead of pre-shared keys
      • Makes deploying Site to Site VPN more scalable
    • PKI-AAA Integration
      • Extends PKI authentication to perform authorization based on digital certificates
      • Allows AAA server to push policy down to router, AAA says what services are permitted, router then builds ACL
      • Benefit, policy does not have to be individually administered for routers
      • Benefit, easy to change policy, since in AAA, not multiple individual routers
    • Secure RSA Private Key
      • If router is stolen, Boot Flash (ROMMON) hacked, and password recovery is attempted, the private key is erased
      • Protects against stolen routers being used
    • N-tier CA Chaining
      • Similar to how tiered DNS works
      • Starts at leaf, then traverses up tree to root seeking appropriate CA
      • Benefit is Geographic and Organizational scale
    • Authentication Proxy
      • Useful for split tunnel situations
      • Downloads per-user ACL from AAA after authenticating
      • HTTP, FTP, or telnet sessions initiated from either trusted (inside) or untrusted (outside)
    • Secure ARP
      • Associates Mac Address and IP Address before gaining access to a tunnel
      • Prevents hijacking of IP address
    • 802.1X
      • 802.1x port-level authentication on 3700 switch modules
  2. Identity-Based Networking Services and IEEE 802.1x
    An architectural framework based on technology standards that allows the network administrator to implement true identity-based network access control and policy enforcement, right down to the user and individual access port level. IEEE 802.1x is an open-standards-based protocol for authenticating network clients (or ports) on a user-ID basis. IBNS and 802.1x are supported on all Cisco Catalyst switches, including Catalyst 6500, 4500, 3550, and 2950 switches, Cisco ACS Server as well as Cisco Aironet Access Points.

 
» Find out how to deploy Cisco Security products with the SAFE Blueprint.
» Contact Cisco to discuss the solutions available.
 






Related Tools

VPN Savings Calculator
Security Investment - ROI Briefcase
PIX: Total cost of ownership
Top 10 Security Tips


Let Cisco Help You

Cisco Channel Promotions
Partner Locator
Contact Cisco Rep



Related Links

Security At Cisco

Korean Security Site

Chinese Security Site

FSB


Virtual Tour

INDUSTRY SOLUTIONS | NETWORKING SOLUTIONS | PRODUCTS & SERVICES | ORDERING | TECHNICAL SUPPORT & DOCUMENTATION | LEARNING & EVENTS | PARTNERS & RESELLERS | ABOUT CISCO
Home | Log In | Register | Contacts & Feedback | Help | Site Map
© 1992-2006 Cisco Systems, Inc. All rights reserved. Terms and Conditions, Privacy Statement, Cookie Policy and Trademarks of Cisco Systems, Inc.