Securing the Enterprise Network of Indian Subsidiary of German Automobile Major
Challenge
A key subsidiary of a global automotive group headquartered in Germany, this premium automobile manufacturer operates in India with a strong focus on engineering excellence, safety, and design. Offering a portfolio of well-crafted sedans and SUVs, it caters to the evolving needs of discerning Indian customers. The company leverages local manufacturing, global technology platforms, and a growing dealer network to strengthen its position in the competitive passenger vehicle market.
The company’s existing NAC solution could not support its heterogeneous network comprising switches and other network devices from different vendors. With a sizeable number of devices excluded from its NAC, the company lacked visibility into its network landscape.
Therefore,the company sought an advanced NAC solution that could support a heterogeneous network and provide total visibility.
Solution
Our customer evaluated the leading NAC solutions in the market and selected HPE Aruba Networks ClearPass. Its choice was primarily driven by the ability of ClearPass to support a heterogeneous landscape comprising switches and other network devices from multiple vendors.
Unique Solutions elaborated the HPE-Aruba roadmap and advantage over competition. We then carried out a Proof of Concept (PoC) wherein we demonstrated support for cross-brand switches, authentication flow and other key features of ClearPass. This enabled us to establish our technical chops in the NAC space in general and the company’s compelling reason to switch out of its existing NAC product in particular and thereby get selected by the company as its trusted partner for this project.
Our solution comprises four instances of HPE Aruba Networks ClearPass NAC and our professional services for sizing, installation, implementation and ongoing managed services. It spans 7000 endpoints across the company’s five factories, head office, and multiple branch offices. NAC features implemented include Authentication for Employee, Guest, Contractor; Authorization; Accounting; and Guest management.
Our solution supports a heterogeneous landscape comprising switches and other network devices from multiple vendors. Accordingly, it provides total visibility into the network.
Our solution architecture provides high-availability in more ways than one. Firstly, if a ClearPass server is down, we can move devices to VLAN with rudimentary access enabled by switch policy. Secondly, by creating clusters, we deliver high availability across all of the company’s 25+ locations by using only four instances of ClearPass unlike a crude high availability design that would require one ClearPass instance at each location and lead to manifold higher costs.
The stakeholders for this engagement included IT manager, global network head, local network admin team from the customer’s side, and solution architect and implementation engineers from our side.
Outcome
The customer’s team was responsible for providing a detailed overview of their IT landscape and walking us through their security policies in depth. Our team was responsible for designing the solution, delivering, installing, configuring and operationalizing the required products.
Once we completed the implementation, the customer’s IT manager was responsible for issuing the final approval.
Our customer wanted the same solution to be extended to group companies, subsidiaries and vendors. We fulfilled this ask with a highly generic and abstracted solution architecture.
Benefits:-
- Fortifying the enterprise against virus, malware and other causes of business downtime
- A single “model solution” that can be extended to group companies and other business associates
- Empowering the customer to react faster to incidents and thereby minimize downtime
- Fail safe solution without breaking the bank
- Get a single console view of heterogeneous enterprise network comprising devices from multiple OEMs
Future Plans:-
Encouraged by the success of the first phase of the project, the company has already expanded coverage of its NAC to 9000 endpoints.
It is a common wisdom in the security business that once a company’s primary locations and critical IT assets are well-protected, attackers tend to pivot toward less prominent sites and secondary systems, using them as entry points to breach the core infrastructure. Fully cognizant of this, the company plans to go broader and deeper with its NAC solution by extending it to its subsidiaries, vendors and branches; and expanding it to include device posture check functionality.