What is ZTNA:
This removes application assets from public visibility and significantly reduces the surface area for attack.
ZTNA is a class of products or service
Creates logical access boundary around an application
Applications are hidden from discovery
Access is restricted via a trust broker to a set of named entities
The broker verifies the identity, context and policy adherence of the specified participants before allowing access
The broker prohibits lateral movement elsewhere in the network.
With ZTNA there is zero trust – and you have access to nothing.
Each user can be added to a context, ie: an access group. The context defines who can access what and when
ZTNA uses Explicit Trust vs Implicit Trust
Easy to maintain
Secure by definition – no access by default
Hides everything that's not in the context
Single broker to authorize traffic
Implicit Trust
Gets access to everything ; Then needs that access to be restricted ; One mistake in access-list = big problem
Explicit Trust
Gets access to just what's needed ; No visibility to other assets ; No access-list, no firewall
What is SEA:
SEA enables operations teams to
a) Securely access,
b) configure,
c) monitor and troubleshoot a remote connected assets or machines.
DUO is a ZERO TRUST Solution it helps organizations : To Protect Access to
Critical Applications,
Data,
Systems.
By Offering
Phishing resistant authentication with Passwordless Authentication and Multi-factor Authentication (MFA),
Single Sign-On (SSO),
Adaptive Access Policies,
Device Trust,
VPN-less Remote Access.
Available in Three Editions :
a) Duo Essentials,
b) Duo Advantage,
c) Duo Premier,
Duo Network Gateway (DNG) allows users to access
On-premises websites,
Web applications,
SSH servers,
RDP,
SMB/file server hosts
Without having to worry about managing VPN credentials, while also adding login security with the Duo Universal Prompt.
NOTE : Minimum QTY 1
Tokens will not be available for POC as they needs to be tied to subscription and does not work unless linked to any particular account. However Please find below the 2 videos how Duo Hardware Tokens Work:-
Please find attached data sheet of Cisco Duo solution
Duo supports
Restful API & Web SDK - https://duo.com/docs/duoweb https://duo.com/docs/authapi
LDAP - https://duo.com/docs/ldap
RADIUS - https://duo.com/docs/radius
Windows Logon - https://duo.com/docs/rdp
SSH - https://duo.com/docs/duounix
Box
Toshiba
Cisco
KLAS is a leading healthcare IT research firm that provides the definitive ranking of vendors in the industry – it’s the trusted go-to guide for home healthcare executives making buying decisions for new technology.