Identity Management in 802.1x
           networks
Network without Identity
              Management
              Microsoft AD, DC and
              Radius(IAS/NPS) server                    Finance Team

Finance
Dept


                                                        Project Team




                                       Network switch
                                       Network switch
Client            Private
                   Private
Project           Network
                  Network

                                                         Visitor




                   Internet
                    Internet
Why is identity management needed
             in networks

• Security to your network.

• Protecting confidential data.

• Per Project level isolation.
What is Identity Management
Authentication/Authorizati   Account ID
on Server
                              Domain


                               VLAN
                             Membership
                                           Identity
                                            Identity
         Network switch
         Network switch
                              IP Address



                             Mac Address
How does an Identity Aware Network
             look like
                Microsoft AD, DC and                                      Finance Team
                Radius(IAS/NPS) server


      Finance
      Dept
      VLan
                                                                          Project Team




                                                         Network switch
                                         Enabled with




                                                         Network switch
                                          Enabled with
                                           identity
                                            identity
                                         management
                                          management


      Client
      Project               Private
                             Private
                            Network
                            Network                                        Visitor
      Vlan




Guest VLAN
 Guest VLAN
                                         Internet
                                          Internet
Network without VLAN

                                                       t   Team
                                                 Projec
                                    e Te   am
                              Financ

       Ne
         tw
           or
              k   Sw
                    itc
                          h



   Since there is no vlan
    Since there is no vlan
  isolation in the switch,
   isolation in the switch,
anyone connecting to the
 anyone connecting to the
switch will have access to
 switch will have access to
anything in the network.
                                       Finance                               Project Team
 anything in the network.
                                       Team                       Visitors
How does VLAN isolation work?



  Ne
    tw
         or
            k   Sw
                  it c
                         h




                             Finance              Project Team
                             Team      Visitors
How Does Authentication work ?
                                                Radius verifies the
                                                 Radius verifies the                    Switch sends the user
                                                                                         Switch sends the user
                                               Account ID /Domain
                                                Account ID /Domain                           identity to
                                                                                              identity to
   •    Microsoft AD, DC                           id with AD
                                                     id with AD                         Authentication Server
                                                                                         Authentication Server
   •    Radius(IAS/NPS) server



Radius processes the policy
 Radius processes the policy
     set for that user : :
      set for that user
     1.Security Group
      1.Security Group
2.Radius attributes (In this
 2.Radius attributes (In this
  case vlan membership)
   case vlan membership)                     Vlan                                                   Project Team
                                                  Mem
                                                     b   ersh




                                                                       Network Switch
                                                                       Network Switch
                                                              ip

            Client                 Private
                                    Private
            Project                Network
                                   Network
            Vlan



                                 Based on the information sent
                                  Based on the information sent                                User connects to
                                                                                                User connects to
                                  by Radius, the switch places
                                   by Radius, the switch places                                  the networks
                                                                                                  the networks
                                       the person in the
                                        the person in the
                                      corresponding vlan
                                       corresponding vlan
Questions ?

Identity management

  • 1.
    Identity Management in802.1x networks
  • 2.
    Network without Identity Management Microsoft AD, DC and Radius(IAS/NPS) server Finance Team Finance Dept Project Team Network switch Network switch Client Private Private Project Network Network Visitor Internet Internet
  • 3.
    Why is identitymanagement needed in networks • Security to your network. • Protecting confidential data. • Per Project level isolation.
  • 4.
    What is IdentityManagement Authentication/Authorizati Account ID on Server Domain VLAN Membership Identity Identity Network switch Network switch IP Address Mac Address
  • 5.
    How does anIdentity Aware Network look like Microsoft AD, DC and Finance Team Radius(IAS/NPS) server Finance Dept VLan Project Team Network switch Enabled with Network switch Enabled with identity identity management management Client Project Private Private Network Network Visitor Vlan Guest VLAN Guest VLAN Internet Internet
  • 6.
    Network without VLAN t Team Projec e Te am Financ Ne tw or k Sw itc h Since there is no vlan Since there is no vlan isolation in the switch, isolation in the switch, anyone connecting to the anyone connecting to the switch will have access to switch will have access to anything in the network. Finance Project Team anything in the network. Team Visitors
  • 7.
    How does VLANisolation work? Ne tw or k Sw it c h Finance Project Team Team Visitors
  • 8.
    How Does Authenticationwork ? Radius verifies the Radius verifies the Switch sends the user Switch sends the user Account ID /Domain Account ID /Domain identity to identity to • Microsoft AD, DC id with AD id with AD Authentication Server Authentication Server • Radius(IAS/NPS) server Radius processes the policy Radius processes the policy set for that user : : set for that user 1.Security Group 1.Security Group 2.Radius attributes (In this 2.Radius attributes (In this case vlan membership) case vlan membership) Vlan Project Team Mem b ersh Network Switch Network Switch ip Client Private Private Project Network Network Vlan Based on the information sent Based on the information sent User connects to User connects to by Radius, the switch places by Radius, the switch places the networks the networks the person in the the person in the corresponding vlan corresponding vlan
  • 9.