Making a Midsized Bank’s Enterprise Network Attack Proof
Challenge
Our customer is a new generation private sector bank with 450+ branches across India. As a scheduled commercial bank, it is regulated by Reserve Bank of India. Professionally managed, the bank has contemporary technology and infrastructure including state of the art internet banking for personal as well as business banking customers.
The bank has 15000 endpoints including corporate laptop, desktop, and headless devices across 450+ branches. Its network infrastructure has a combination of managed and unmanaged devices. The bank faced a severe security threat to its enterprise network due to vulnerabilities in its ATM estate. To mitigate this threat, the bank decided to install and implement a NAC (Network Access Control) solution.
Solution
The bank evaluated the leading NAC solutions in the market and selected HPE Aruba Networks ClearPass. Its choice was shaped by two key differentiators of ClearPass: (i) support for a heterogeneous landscape (ii) ability to handle unmanaged – and not just managed – network devices.
Unique Solutions elaborated the HPE-Aruba roadmap and advantage over competition. We then carried out a Proof of Concept (PoC) spanning the bank’s head office and a few branches, in which we demonstrated the authentication flow and other key features of ClearPass. Unlike our competitors, we could show support for cross-brand switches and integration with BigFix and other third-party systems in the bank’s existing IT landscape. With these activities, we were able to establish our deep expertise in the NAC space with the bank’s evaluation committee. Accordingly, the bank selected Unique Solutions as its trusted partner for this project.
Our solution comprises HPE Aruba Networks ClearPass NAC (four instances) and our professional services for sizing, installation, implementation and ongoing managed services. It spans 12500 endpoints across the bank’s head office, 20 large branches and all ATMs. NAC features implemented include Authentication for Employee and Contractor; Authorization; and Accounting. In addition, we provide session-based authorization of unmanaged endpoints. While connecting with unmanaged switches, we have ring fenced the L3 switches at core level by implementing session-based authentication service.
Seamlessly integrated with BigFix, Symantec, and other applications in the bank’s existing IT landscape, our solution provides device profiling and total visibility into the network.
Our solution architecture provides high-availability without breaking the bank. A crude design of high-availability would call for one NAC instance at each location, thus leading to exorbitant costs. In sharp contrast, we architected a sophisticated solution that uses clusters and delivers high availability across all of the 20+ locations by using only four instances of ClearPass.
The stakeholders for this engagement included IT manager, network admin and CISO from the customer’s side; and solution architect and implementation engineers from our side.
The customer’s team was responsible for providing a detailed overview of their IT landscape and walking us through their security policies in depth. Our team was responsible for designing the solution, delivering, installing, configuring and operationalizing the required products.
Outcome
While ClearPass supports integration with BigFix, we faced challenges while implementing the specific feature. We collaborated with Aruba Networks R&D team to develop a specific update. Once we installed the patch, the integration went through with no further hiccups.
Benefits:-
- Mitigation of security threats to the bank’s enterprise network
- Cost-effective fail-safe solution
- Protection of the bank’s existing investment in third-party network devices and unmanaged switches
- Empowering the customer to react faster to incidents and thereby minimize downtime
- Easing compliance with banking industry regulations
Future Plans:-
Encouraged by the success of the first phase of the project, the bank now plans to expand the NAC solution to the next tier of branches, fully cognizant of the old security industry wisdom that once a company’s primary locations and critical IT assets are secured, attackers tend to pivot toward less prominent sites and secondary systems, using them as entry points to breach the core infrastructure.