Showing posts with label access. Show all posts
Showing posts with label access. Show all posts

Tuesday, November 14, 2017

VDI Gateway Federation with BIG-IP

Today let’s look at how F5 BIGIP APM can consolidate, secure and federate all the core VDI gateways technology. For instance, if an organization decides move from one VDI technology to another or if you’re consolidating VDI technologies, BIG-IP can help.

On the BIG-IP we’ve set up three VDI environments. Microsoft RDS/RDP with a broker authentication server, VMware Horizon and Citrix ZenApp. With only a corporate account, a user can authenticate to all of them as needed and access all available desktop content.

In this example, we connect to the BIG-IP APM. This is the default view.

And here we’ve put some advanced security fields like OTP or multifactor authentication for instance.

So here we’d use our username and password and for additional security we'll choose a secondary grid. By default, a grid is not generally available from any of the VDI vendors. When we select grid, BIG-IP APM will present a grid for a PIN entry. This is provided through a partnership with Gemalto. BIG-IP is connecting to Gemalto servers to present the grid to the user. We then enter our confidential PIN.
 Upon auth, we’re presented with our BIG-IP APM Webtop and BIG-IP did the necessary single sign on for all the VDI technologies and environments assigned to us.

With a single, multifactor authentication we’re able to gain access to our federated BIG-IP Webtop and select the specific VDI resource we need.

From an administrative view, here is the full Visual Policy Editor (VPE) for the overall solution. This also shows where the OTP/Grid is if you follow the Host FQDN path.

And here are the specific inspections and criteria for the VDI scenario. You can see a path for each VDI vendor along with specific inspections and actions depending on the situation.

Special thanks to F5 Sr. Security SE Matthieu Dierick for the explanation and you can watch the demo video.

ps


Wednesday, July 26, 2017

Lightboard Lessons: What is BIG-IP APM?

In this Lightboard, I light up some lessons on BIG-IP Access Policy Manager. BIG-IP APM provides granular access controls to discreet applications and networks supporting 2FA and federated identity management. You can also check out Chase's written article What is BIG-IP APM?



ps

Tuesday, February 14, 2017

Shared Authentication Domains on BIG-IP APM

How to share an APM session across multiple access profiles.

A common question for someone new to BIG-IP Access Policy Manager (APM) is how do I configure BIG-IP APM so the user only logs in once.

By default, BIG-IP APM requires authentication for each access profile.


This can easily be changed by sending the domain cookie variable is the access profile’s SSO authentication domain menu.

Let’s walk through how to configure App1 and App2 to only require authentication once.

We’ll start with App1’s Access Profile.


Once you click through to App1’s settings, in the Top menu, select SSO/Auth Domains.


For the Domain Cookie, we’ll set the value to f5demo.com since App1 and App2 use this domain and it is a FQDN. Of course, click Update.

Next, we’ll select App2’s Access Profile. Like App1, we select SSO/Auth Domains and set the Domain Cookie value to f5demo.com.

To make sure it works, we’ll launch App1 in our browser.


We’re prompted for authentication and enter our credentials and luckily, we have a successful login.


And then we’ll try to login to App2. And when we click it, we’re not prompted again for authentication information and gain access without prompts.


Granted this was a single login request for two simple applications but it can be scaled for hundreds of applications. If you‘d like to see a working demo of this, check it out here.

ps




Wednesday, January 20, 2016

Internet of Insider Threats

Identify Yourself, You Thing!

Imagine if Ben Grimm, aka The Thing, didn’t have such distinctive characteristics like an orange rocky body, blue eyes or his battle cry, ‘It’s Clobberin’ Time!’ and had to provide a photo ID and password to prove he was a founding member of the Fantastic Four. Or if the alien in John Carpenter’s The Thing gave each infected life-form the proper credentials to come and go as they please. Today the things we call ‘Things’ are infiltrating every aspect of society but how do organizations identify, secure and determine access for the 15+ connected chips employees will soon be wearing to the office? And what business value to they bring?

Gartner refers to it as the ‘Identity of Things’ (IDoT) and an extension to identity management that encompasses all entity identities, whatever form those entities take. According to Gartner, IoT is part of the larger digital business trend transforming enterprises. It means that the business, the people/employees and the ‘things’ are all responsible in delivering business value. The critical part is the relationships between or among those participants so the business policies and procedures can reflect those relationships. Those relationships can be between a device and a human; a device and another device; a device and an application or service; or a human and an application or service.

For instance, how does the system(s) know that the wearable asking for Wi-Fi access is the one connected to your wrist? It really doesn’t since today’s Identity and Access Management (IAM) systems are typically people-based and unable to scale as more entities enter the workplace. Not to mention the complexity involved with deciding if the urine powered socks the VP is wearing gets access. The number of relationships between people and the various entities/things will grow to an almost unmanageable point. Could anyone manage a subset of the expected 50 billion devices over the next 4 years? And set policies for data sharing permissions? Not without a drastic change to how we identify and integrate these entities.

Talk about the Internet of Insider Threats. That's IoIT for those counting.

Gartner suggests that incorporating functional characteristics of existing management systems like IT Asset Management (ITAM) and Software Management Systems (SAM) within the IAM framework might aid in developing a single-system view for IoT. The current static approach of IAM doesn’t take into account the dynamic relationships, which is vital to future IAM solutions. Relationships will become as important as the concept of identity is for IAM in the IDoT, according to Gartner.

My, your, our identities are unique and have been used to verify you-are-you and based on that, give you access to certain resources, physical or digital. Now our identities are not only intertwined with the things around us but the things themselves also need to verify their identity and the relationship to ours.

I can hear the relationship woes of the future:
A: I’m in a bad relationship…
B:Bad!?! I thought you were getting along?
A:We were until access was denied.
B:What are you talking about? You guys were laughing and having a great time at dinner last night.’
A:Not my fiancé…it’s my smart-watch, smart-shoes, smart-socks, smart-shirt, smart-pants, smart-belt, smart-glasses, smart-water bottle, smart fitness tracker and smart-backpack.'
IT said, 'It’s not you, it’s me.'

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, November 4, 2015

Ask the Expert – Why Identity and Access Management?

Michael Koyfman, Sr. Global Security Solution Architect, shares the access challenges organizations face when deploying SaaS cloud applications. Syncing data stores to the cloud can be risky so organizations need to utilize their local directories and assert the user identity to the cloud. SAML is a standardized way of asserting trust and Michael explains how BIG-IP can act either as an identity provider or a service provider so users can securely access their workplace tools. Integration is key to solve common problems for successful and secure deployments.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, April 21, 2015

RSA2015 Partner Spotlight - RSA Risk Based Authentication

RSA Technology Consultant Josh Waterloo talks about the evolution of two-factor authentication and how risk based auth is starting to take hold. He also shows us a demo of the integration between RSA SecurID and BIG-IP APM to provide risk based, strong authentication for corporate access to sensitive information.

 

ps

Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, March 26, 2015

Lost in Translation...in Italy

I've been travelling recently. To places and fields that have limited to no mobile connectivity and this can be a challenge when a challenge arises.
train1Immediately following Mobile World Congress in Barcelona earlier this month, my family embarked on a multi-week European vacation. After spending a couple more days in Spain, we jumped on the rail to Paris for a couple days and then on to Rome for 10 days. The Eiffel Tower along with 'I see London, I see France, I see Daddy's....' request was our daughter's and Italy was something we've wanted to do for a while. During the train ride - which was fantastic - we saw vineyards, castles, the Alps, old bunkers and tons of scenery you never get on an airplane. It's almost like eavesdropping on these remote lives as you pass by at 187 mph while they hang their clothes to dry or tend to their fields. Yes, mobile connectivity was very spotty but it was not a big deal since we were enjoying the views and had no reason to 'connect.' I even turned the phone off at various times just for the peace.
In the major cities like Paris and Rome and if you have roaming of course, you're able to connect to one of the available 3G mobile networks within that country. While not LTE, you get decent connectivity and can accomplish many of the mobile tasks that have become commonplace - email, maps, navigation, browsing and so forth. Incidentally, if you want to learn how LTE Roaming works, check out this video we did at MWC15. It is when you venture out, Griswold style, when you can get into trouble.
colleseumWhile in Rome, we visited many of the typical tourism destinations like The Coliseum, Pantheon, Vatican, Spanish Steps, Trevi Fountain and others. It seemed like our entire trip was going exactly as planned and we were having a wonderful time. That is, until the day we left Rome to return to Barcelona for our flight home. The real adventure was about to begin - like the last 20 minutes of a movie when you think everything is wrapped up and that last big crisis hits.
We bought, what we thought, were rail tickets from Rome back to Barcelona. They were less expensive than our inbound rail, which for some reason, didn't fire off the warning bells but we thought that since it was direct, it should be fine. We get on the train and have a nice semi-private area to stretch out and relax on the trip back. As we start the journey, everything seems great - the scenery, the company and we packed some good snacks for the ride. The conductor came through, verified our tickets and we felt like we could unwind. After a little while, we can see the Mediterranean Sea but it is on the wrong side of the train. A little concerned, I asked a uniformed staff if this was the train to Barcelona and was assured that it was. OK, maybe we go South for a few stops but turn around and head North. Seemed reasonable.
mt v1We arrive at the Pompei station and get to see Mt. Vesuvius but at this point, we start to get concerned. I find the rail staff for a second time and again asked if this is the train to Barcelona. Even adding that we're going South and wondered if it turns and goes North (up & around, etc.) at some point. Again I'm told that we are going to Barcelona. More time passes and as we get further South, connectivity gets spotty. As it goes in and out, I search, 'does the train from Rome to Barcelona go under the Mediterranean Sea?' There is the English Channel Chunnel so maybe this does the same thing? Nope. Now I'm panicked.
I find yet a third staff member and ask where are we going. It is at that point I learn that we are not headed for Barcelona Spain but Barcellona (Pozzo di Gotto) Italy. We're supposed to be on our return home flight from Spain in less than 36 hours and we're heading for Sicily. He says there is an airport in Catania and we might be able to get a flight to Barcelona. But with no connectivity, we can't see what is available and didn't want to risk arriving with no flights. I ask when is the next train back to Rome...at least get back there. We're told to get off at the next stop, San Giovanni, and we might be able to catch the overnight. Frantically, we grab our stuff, jump off and look around. Pretty grim. After a couple ups and downs of stairs with our bags, we finally make it to the ticket window. I explain that we want to go to Barcelona and the agent tells us, we just missed the train. I pull out a mobile translator and again attempt to communicate. I get frustrated, the agent gets frustrated and we're stuck. I grab a piece of paper and write SPAIN on it and his eyes finally light up but there is no path from where we are to Barcelona. It's 18:00 hours and we have less than 24 hours to reach Spain.
While a crowd gathers behind us, we ask about a train to Milan. Luckily, there is one and it leaves in 30 minutes. We'll take it! It's an overnight and we don't arrive in Milan until 11am the next day. Down to 20 hours before our plane leaves for to LAX. Hopefully we can get on a Milan to Barcelona flight but without connectivity, there's no way of knowing. We get on the train and I start crying - not so much because we're lost in a foreign country but the relief we're finally going in the right direction. Since we can't determine our next steps, the only thing to do is attempt to rest in this little 3 bunk room. The conductors on this route helped as much they could and told us that this happens to people almost every other month. We're not alone but we're nowhere near a solution.
We finally get to Milan and immediately jump in a cab to take the 45 minute/90Euro ride to the airport. We also have some 3G connectivity and at least see there are a few flights to Barcelona but also rely on the cab driver to point us in the right direction. In addition, the connectivity is so spotty on the way that trying to book a flight becomes impossible. At the airport we find the ticket window and buy some of barcthe last remaining tickets for the last flight to Barcelona that day. After not bathing or sleeping for two days, I still felt relieved. We just might make it. As an eerie aside, just the day before our flight path went over the same location as the crashed Germanwings plane. Our jaws dropped when we learned of the tragedy.
We land in Barcelona with 12 hours to spare. Get to our hotel, eat, shower and collapse for a few hours. Not taking any chances, we head out early, make our flight and am grateful to finally be home to tell this story. I learned a lot about geography, mobile connectivity, communication, security, and about myself. We've become so dependent on connectivity and it seems that we've become one with our mobile devices but when there is no signal and they can't help in a crisis, paper, pencils and people still matter. While harrowing, it was an amazing adventure and a fitting end to our wonderful trip.
ps
Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, December 16, 2014

Blog Roll 2014

It’s that time of year when we gift and re-gift, just like this text from last year. And the perfect opportunity to re-post, re-purpose and re-use all my 2014 blog entries. If you missed any of the 96 attempts including 57 videos, here they are wrapped in one simple entry. I read somewhere that lists in blogs are good. I broke it out by month to see what was happening at the time and let's be honest, pure self promotion. 

Thanks for reading and watching throughout 2014.

Have a Safe and Happy New Year.

 

January

February

March

April

May

June

July

August

September

October

November

December

And a couple special holiday themed entries from years past.

 

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]