1
1

00:00:00,480  -->  00:00:02,240
<v ->Network Access Control.</v>
2

2

00:00:02,240  -->  00:00:04,390
In this lesson, we're going to talk all about
3

3

00:00:04,390  -->  00:00:06,130
network access control.
4

4

00:00:06,130  -->  00:00:09,130
Now, network access control or NAC is used to protect your
5

5

00:00:09,130  -->  00:00:11,920
network from both known and unknown devices.
6

6

00:00:11,920  -->  00:00:14,490
This is achieved because NAC ensures the device is scanned
7

7

00:00:14,490  -->  00:00:16,950
to determine its current state of security prior to being
8

8

00:00:16,950  -->  00:00:18,580
allowed access to your network.
9

9

00:00:18,580  -->  00:00:20,640
Network access control can be used for computers
10

10

00:00:20,640  -->  00:00:22,180
that are within your internal network
11

11

00:00:22,180  -->  00:00:23,610
that are physically located inside
12

12

00:00:23,610  -->  00:00:25,680
your buildings and are connected to it.
13

13

00:00:25,680  -->  00:00:28,060
Or it can also be applied to devices that are connected
14

14

00:00:28,060  -->  00:00:30,570
to your network remotely through a VPN.
15

15

00:00:30,570  -->  00:00:32,930
Now, when a device attempts to connect to the network,
16

16

00:00:32,930  -->  00:00:35,010
it's placed into a virtual holding area
17

17

00:00:35,010  -->  00:00:36,450
while it's being scanned.
18

18

00:00:36,450  -->  00:00:38,270
This scan can be extremely simple,
19

19

00:00:38,270  -->  00:00:40,570
like verifying that it's based on the authentication
20

20

00:00:40,570  -->  00:00:42,610
using EAP and just making sure that it has
21

21

00:00:42,610  -->  00:00:45,960
the right username and password or it can be more intense.
22

22

00:00:45,960  -->  00:00:47,680
For example, the device can be checked for
23

23

00:00:47,680  -->  00:00:49,030
a number of different factors,
24

24

00:00:49,030  -->  00:00:50,970
including its antivirus definitions,
25

25

00:00:50,970  -->  00:00:52,740
to make sure that they're up to date the status
26

26

00:00:52,740  -->  00:00:54,130
of the security patching and making sure
27

27

00:00:54,130  -->  00:00:56,210
that's up to date and other items that might
28

28

00:00:56,210  -->  00:00:58,440
introduce security threats into your network
29

29

00:00:58,440  -->  00:01:00,590
if you allow that device to connect to you.
30

30

00:01:00,590  -->  00:01:02,570
Now, if a device passes this inspection,
31

31

00:01:02,570  -->  00:01:05,110
it's then going to be allowed to enter and receive access
32

32

00:01:05,110  -->  00:01:07,030
to all of the organizational resources
33

33

00:01:07,030  -->  00:01:08,760
that are provided by your network.
34

34

00:01:08,760  -->  00:01:10,740
If the device fails the inspection, though,
35

35

00:01:10,740  -->  00:01:13,160
it's going to be placed into a digital quarantine area
36

36

00:01:13,160  -->  00:01:15,490
and there it's going to await remediation .
37

37

00:01:15,490  -->  00:01:16,730
While it's in this area,
38

38

00:01:16,730  -->  00:01:18,840
the device can receive its antivirus updates.
39

39

00:01:18,840  -->  00:01:20,390
It can get operating system patches.
40

40

00:01:20,390  -->  00:01:22,720
And any other security configurations and services
41

41

00:01:22,720  -->  00:01:23,830
that it might need.
42

42

00:01:23,830  -->  00:01:26,650
But it cannot largely communicate with the other portions
43

43

00:01:26,650  -->  00:01:28,460
of the network because it's trapped inside
44

44

00:01:28,460  -->  00:01:31,970
this screen subnet that's reserved for quarantine devices.
45

45

00:01:31,970  -->  00:01:35,320
Like a bad child, this device has been placed into a timeout
46

46

00:01:35,320  -->  00:01:38,040
and there it has to sit until it's rehabilitated.
47

47

00:01:38,040  -->  00:01:40,370
Once it's been rehabilitated and can meet the requirements
48

48

00:01:40,370  -->  00:01:42,040
of the initial NAC inspection,
49

49

00:01:42,040  -->  00:01:44,930
it can then be moved into the regular network and receive
50

50

00:01:44,930  -->  00:01:48,199
full access again, to all the organization's resources.
51

51

00:01:48,199  -->  00:01:50,760
NAC solutions can either run as a persistent
52

52

00:01:50,760  -->  00:01:52,410
or non-persistent agent.
53

53

00:01:52,410  -->  00:01:54,370
Now, persistent agents are a piece of software
54

54

00:01:54,370  -->  00:01:55,810
that's installed on a device
55

55

00:01:55,810  -->  00:01:57,630
that's requesting access to the network.
56

56

00:01:57,630  -->  00:01:59,420
This works well in a corporate environment
57

57

00:01:59,420  -->  00:02:00,810
because the organization might own
58

58

00:02:00,810  -->  00:02:02,570
all the different devices and controls,
59

59

00:02:02,570  -->  00:02:05,370
and it can then understand what the software baselines are.
60

60

00:02:05,370  -->  00:02:07,970
But this doesn't work well if you're in an environment
61

61

00:02:07,970  -->  00:02:10,680
where people are going to use, "Bring your own devices."
62

62

00:02:10,680  -->  00:02:12,579
Now, instead in those cases,
63

63

00:02:12,579  -->  00:02:15,490
you're going to want to use a non-persistent agent.
64

64

00:02:15,490  -->  00:02:17,950
A non-persistent agent solution is very popular,
65

65

00:02:17,950  -->  00:02:20,440
especially in college campuses where people bring their own
66

66

00:02:20,440  -->  00:02:22,430
devices and connect them to the network.
67

67

00:02:22,430  -->  00:02:25,040
These non-persistent agents are going to require the users
68

68

00:02:25,040  -->  00:02:27,520
to connect to the network, usually over wifi.
69

69

00:02:27,520  -->  00:02:29,730
And then they're going to go to a web based captive portal
70

70

00:02:29,730  -->  00:02:31,120
where they're going to log in.
71

71

00:02:31,120  -->  00:02:32,850
Once they do that, they're going to click on a link
72

72

00:02:32,850  -->  00:02:35,440
that's going to download an agent onto their computer.
73

73

00:02:35,440  -->  00:02:37,080
It's going to scan the device for compliance
74

74

00:02:37,080  -->  00:02:39,300
and then delete itself from the user's machine
75

75

00:02:39,300  -->  00:02:41,070
once it's done with the inspection.
76

76

00:02:41,070  -->  00:02:42,300
If they pass the inspection,
77

77

00:02:42,300  -->  00:02:43,880
there'll be granted access to the network,
78

78

00:02:43,880  -->  00:02:46,500
if they're not, there'll be placed in a quarantine.
79

79

00:02:46,500  -->  00:02:49,190
Network access control can be offered as either a hardware
80

80

00:02:49,190  -->  00:02:51,630
or a software based solution when you're implementing it
81

81

00:02:51,630  -->  00:02:53,030
inside your networks.
82

82

00:02:53,030  -->  00:02:54,718
One of the most commonly used network access control
83

83

00:02:54,718  -->  00:02:59,030
mechanisms is known as the IEEE standard 802.1x
84

84

00:02:59,030  -->  00:03:01,500
which is port based network access control.
85

85

00:03:01,500  -->  00:03:03,100
Most modern NACs are going to be built
86

86

00:03:03,100  -->  00:03:05,450
on top of the 802.1x standard,
87

87

00:03:05,450  -->  00:03:08,440
adding additional features and capabilities to it as well.
88

88

00:03:08,440  -->  00:03:10,600
In addition to this NAC health policy,
89

89

00:03:10,600  -->  00:03:12,160
where we're checking to make sure everybody meets
90

90

00:03:12,160  -->  00:03:13,510
a minimum level of standard,
91

91

00:03:13,510  -->  00:03:15,260
there could also be different rule-based methods
92

92

00:03:15,260  -->  00:03:17,470
that you can use for granting or denying access
93

93

00:03:17,470  -->  00:03:19,410
to your networks using NAC.
94

94

00:03:19,410  -->  00:03:22,060
There's going to be more than just this health policy.
95

95

00:03:22,060  -->  00:03:24,050
We can do it with lots of different things.
96

96

00:03:24,050  -->  00:03:26,360
We can check things like the time, the location,
97

97

00:03:26,360  -->  00:03:29,240
the role or rules to decide whether or not this device
98

98

00:03:29,240  -->  00:03:31,830
should be granted entry to our network.
99

99

00:03:31,830  -->  00:03:33,160
With time-based factors,
100

100

00:03:33,160  -->  00:03:35,560
we're going to find access periods for given hosts,
101

101

00:03:35,560  -->  00:03:37,270
using a time-based schedule.
102

102

00:03:37,270  -->  00:03:39,150
For example, you might work in a company
103

103

00:03:39,150  -->  00:03:40,660
that only operates from 9:00 in the morning,
104

104

00:03:40,660  -->  00:03:42,000
till 5:00 in the afternoon.
105

105

00:03:42,000  -->  00:03:43,950
And if you try to log in at 2:00 in the morning,
106

106

00:03:43,950  -->  00:03:45,640
you're going to be denied access.
107

107

00:03:45,640  -->  00:03:47,610
Now you have to be careful in using these time-based
108

108

00:03:47,610  -->  00:03:48,443
approaches though,
109

109

00:03:48,443  -->  00:03:51,490
or you could block legitimate access by mistake.
110

110

00:03:51,490  -->  00:03:52,323
In my company,
111

111

00:03:52,323  -->  00:03:54,700
we have employees that work on both sides of the world.
112

112

00:03:54,700  -->  00:03:56,730
So when I'm sleeping at 2:00 in the morning here,
113

113

00:03:56,730  -->  00:03:58,930
some of my employees are over in Asia and they're accessing
114

114

00:03:58,930  -->  00:04:01,620
our networks and we need to make sure they can do their job.
115

115

00:04:01,620  -->  00:04:03,990
So I can't block people at 2:00 in the morning.
116

116

00:04:03,990  -->  00:04:06,310
But we could make it so they can only access things
117

117

00:04:06,310  -->  00:04:07,880
during their daytime hours.
118

118

00:04:07,880  -->  00:04:10,550
And we can only access things during our daytime hours.
119

119

00:04:10,550  -->  00:04:12,850
If we want to use a time-based model.
120

120

00:04:12,850  -->  00:04:14,220
Now, another way you can do things is
121

121

00:04:14,220  -->  00:04:16,000
with location-based factors.
122

122

00:04:16,000  -->  00:04:17,480
With location-based factors,
123

123

00:04:17,480  -->  00:04:19,260
we're going to evaluate the location of the endpoint
124

124

00:04:19,260  -->  00:04:22,380
requesting access using geolocation of its IP,
125

125

00:04:22,380  -->  00:04:24,520
it's GPS or other mechanisms.
126

126

00:04:24,520  -->  00:04:26,770
For example, if I know that one of my employees
127

127

00:04:26,770  -->  00:04:28,130
always logs in from Florida,
128

128

00:04:28,130  -->  00:04:30,520
but now all of a sudden they're logging in from Italy,
129

129

00:04:30,520  -->  00:04:32,390
that would be something that will be flagged and we might
130

130

00:04:32,390  -->  00:04:34,760
want to put them into remediation until we figure out,
131

131

00:04:34,760  -->  00:04:35,897
are they really in Italy
132

132

00:04:35,897  -->  00:04:38,410
or is it somebody attacking their account?
133

133

00:04:38,410  -->  00:04:39,243
Now, after all,
134

134

00:04:39,243  -->  00:04:41,440
maybe that person is on vacation and they're accessing their
135

135

00:04:41,440  -->  00:04:43,950
work email from Italy and maybe they're not.
136

136

00:04:43,950  -->  00:04:45,570
And somebody's actually hacked their account
137

137

00:04:45,570  -->  00:04:46,860
and using their credentials.
138

138

00:04:46,860  -->  00:04:49,200
So we need to validate that before we give them access
139

139

00:04:49,200  -->  00:04:50,033
to the network,
140

140

00:04:50,033  -->  00:04:53,290
both of these could be caught using location-based access.
141

141

00:04:53,290  -->  00:04:55,690
Now another one we have is role-based factors,
142

142

00:04:55,690  -->  00:04:58,290
and this is going to reevaluate a devices authentication
143

143

00:04:58,290  -->  00:05:00,420
when it's being used to do something.
144

144

00:05:00,420  -->  00:05:02,520
This is known as adaptive NAC.
145

145

00:05:02,520  -->  00:05:04,440
Now, for example, let's say your device tries
146

146

00:05:04,440  -->  00:05:06,950
to join a sub-net that's used for server management
147

147

00:05:06,950  -->  00:05:09,490
and it's on the user account and a user laptop.
148

148

00:05:09,490  -->  00:05:10,820
This should be rejected.
149

149

00:05:10,820  -->  00:05:13,250
We shouldn't let that user account and user laptop connect
150

150

00:05:13,250  -->  00:05:15,440
directly to our server management subnet.
151

151

00:05:15,440  -->  00:05:17,910
But if I tried to connect a server to that domain,
152

152

00:05:17,910  -->  00:05:19,970
it would allow that to happen because it's an authorized
153

153

00:05:19,970  -->  00:05:23,090
function for that server based on its role.
154

154

00:05:23,090  -->  00:05:24,560
Now, by using adaptive NAC,
155

155

00:05:24,560  -->  00:05:26,450
we're going to be looking at the role of the device
156

156

00:05:26,450  -->  00:05:28,410
and figuring out if it's doing something that it should
157

157

00:05:28,410  -->  00:05:30,040
or should not be allowed to do.
158

158

00:05:30,040  -->  00:05:32,560
And we can then adapt based on that.
159

159

00:05:32,560  -->  00:05:34,790
The final one we have is rule-based factors,
160

160

00:05:34,790  -->  00:05:37,740
and we can use a complex admission policy if we want to,
161

161

00:05:37,740  -->  00:05:39,340
to enforce a series of rules.
162

162

00:05:39,340  -->  00:05:41,120
And we basically can write these up with a bunch
163

163

00:05:41,120  -->  00:05:43,518
of logical statements, if this, then that,
164

164

00:05:43,518  -->  00:05:45,580
if this, then this other thing,
165

165

00:05:45,580  -->  00:05:47,320
if this, then this third thing,
166

166

00:05:47,320  -->  00:05:49,840
and we can make these things happen, for example,
167

167

00:05:49,840  -->  00:05:53,220
if Jason and instructor let him access this folder,
168

168

00:05:53,220  -->  00:05:55,890
if Jason and student deny him access,
169

169

00:05:55,890  -->  00:05:58,580
that's the idea of this rule based mentality.
170

170

00:05:58,580  -->  00:06:00,580
Now, this is obviously a very simple example,
171

171

00:06:00,580  -->  00:06:02,710
but hopefully you're getting the idea of how you can create
172

172

00:06:02,710  -->  00:06:06,170
rules to secure your network using network access control.
173

173

00:06:06,170  -->  00:06:08,920
Our goal here is to make a policy based on a series of rules
174

174

00:06:08,920  -->  00:06:11,130
and then allow or deny things to those people
175

175

00:06:11,130  -->  00:06:13,500
based on the different conditions.
176

176

00:06:13,500  -->  00:06:15,950
As you can see, NAC can be extremely useful
177

177

00:06:15,950  -->  00:06:17,700
as part of our defense in-depth strategy,
178

178

00:06:17,700  -->  00:06:20,170
and it helps to enforce a zero trust architecture
179

179

00:06:20,170  -->  00:06:21,383
within our networks.
