Providing Out-of-Band Connectivity to Mission-Critical IT Resources

4 Critical Things to Know About Zero Trust Security

Zero trust security is not a new concept, however it has gained popularity in recent years. As companies become increasingly distributed, they must offer network access that’s flexible, without putting sensitive data at risk. This is where zero trust security comes in.

In this post, we’ll cover 4 critical things you should know about zero trust security, such as what it is, why companies use it, how it works, and more.

What is Zero Trust Security?

Zero trust security can be boiled down to a simple concept: always verify every user and device trying to access the network.

Traditional networking safeguards are based on the castle-and-moat architecture. This means that all users and devices within the network are deemed trustworthy and can access the resources they need. Those outside of the network (or moat) must be verified and trusted before gaining access to the network. One of the glaring problems with this approach is that it doesn’t consider the possibility of attacks coming from a trusted user/device within the network. This means that an attacker simply needs to hack into the network, and then there are few (if any) obstacles remaining in their way.

Zero trust reimagines security with the concept that organizations should not automatically trust anyone/anything trying to connect to their network. Instead, they should verify everyone and everything that tries to connect, including users/devices outside and inside of its perimeter. In other words, trust no one.

Where Did Zero Trust Security Come From?

The zero trust concept was first prototyped in the early 2000s. In 2010, John Kindervag coined the term ‘zero trust’ for the concept, and its adoption by Google a few years later increased the industry’s interest in the zero trust model.

This new security architecture came from the realization that the traditional castle-and-moat configuration was becoming increasingly vulnerable. Years ago, a typical organization’s data and sensitive information were kept in a central location. This made the network and its resources easy to protect, and also easy for IT staff to monitor for threats and address attacks.

Now, organizations are adopting technologies that offer greater networking capabilities for distributed access. These technologies include public and private clouds, third-party services, virtualized SD-WAN & firewall solutions, and more. Securing an entire network means putting in place multiple safeguards. The traditional architecture is now being replaced by the more robust yet nimble security setup of zero trust.

Why Are Companies Using Zero Trust Security?

One of the canonical goals of networking is to allow information to flow between computers, people, and organizations. Yet with information becoming more and more decentralized and relayed through various channels, risk is on the rise. And because traditional security architectures simply can’t provide omnipresent protection for data and communications, zero trust security is being adopted by organizations across the globe.

A major benefit of zero trust is that it provides hardened security, regardless of how distributed the network is. Whether a company serves a single contained network, or hundreds of branch locations distributed around the world, zero trust security offers peace of mind for every interaction. This means more thorough protection from outside and inside threats, because verification is needed — always.

This complements Secure Access Service Edge and SD-Perimeter implementations (more on those below), which companies use to offer more flexible networking and define least-privilege access rights. Used in conjunction with these configurations, zero trust security also eliminates the need for companies to backhaul traffic through their main security controls. This translates to fewer slowdowns and more availability, so companies can meet their business goals without their networks holding them back.

Real-world examples include scaling, working from home, and even securing data at HQ.

  • Setting up new locations comes with its own set of security risks. However, companies using a zero trust model can get granular control of who & what can access their network. This can help eliminate attacks from stolen equipment, devices, and credentials.
  • When setting up a Secure Access Service Edge (SASE) implementation, whether for faraway locations or remote & on-the-go workers, zero trust keeps networks & resources secure. It requires user identities and devices to be verified, eliminating many methods of attack.
  • When defining access rights using an SD-Perimeter approach, zero trust enables companies to make sure that access to resources is given only to appropriate personnel. This ensures data stays secure from malicious intent by actors outside or inside of the organization.
  • How Does Zero Trust Security Work?

    Zero trust security assumes that threats can come from anywhere, including from inside the organization. The big takeaway, however, is that zero trust is not a single new tool or technology. Instead, it uses a combination of existing tech and methodologies such as micro-segmentation, multi-factor authentication, and least-privilege access.

    A zero trust model works by segmenting parts of the network into small sections, each with their own security controls. In order to gain access to a segment, a user must verify their identity using multi-factor authentication (MFA). Once a user is verified, least-privilege access means they can use only the resources they need to perform their job. This is essentially a perimeter around what the user is allowed to access.

    Here’s a basic example: One segment contains SD-WAN and firewall controls. If Ryan is an admin responsible for SD-WAN management, and Priya is an admin responsible for firewall management, the company must define these perimeters respectively. Then, Ryan can be verified and granted access only to the SD-WAN tools, while Priya can be verified and granted access only to the firewall tools. If either user tries to gain access outside of their perimeter, they will be denied by their company’s zero trust security measures.

    Though it’s not a quick fix or turnkey solution, zero trust is transforming the ways organizations secure their networks. What’s more, the market is expanding with new solutions that offer increased granular control over access, using technologies like IP tracking, geo-fencing, and others. And using an open platform like Nodegrid, the possibilities are endless for organizations wishing to evolve their security and block threats from across the globe.

    Check out ZPE Systems’ full list of security partners that can help you achieve a zero trust model.

    ZPE Systems and 128 Technology Announce Strategic Partnership

    Fremont, CA, September 17, 2020 – Today, ZPE Systems, Inc., a leading provider of network infrastructure management solutions, and 128 Technology, Inc. (128T), a leading provider of software-defined networking solutions, announced a strategic partnership to offer combined networking and out-of-band management capabilities. As a result of the agreement, customers will experience faster and smarter designs, deployments, and support for their networking solutions.

    ZPE Systems’ Nodegrid hardware and software directly host 128T’s SD-WAN offerings, such as their Session Smart™ routing application, for an all-in-one platform that vastly improves branch networking. Nodegrid’s strong capabilities are enhanced by this tight integration with 128T, to deliver a powerful combined solution that’s easier to deploy and support.

    “ZPE has a very strong communications channel with 128T,” says ZPE Systems’ CEO and Cofounder Arnaldo Zimmermann. “With this partnership, our customers can benefit from an always-ready OOB platform with SD-WAN and cellular failover. In addition, they no longer need to worry about the handoff during support — they get direct assistance with both their Nodegrid appliances and their 128T solution.”

    “The evolution to software-defined networking is delivering breakthroughs across several quantifiable areas and giving enterprises newfound freedom and business agility.  However, because most networks today are a heterogenous mix of solutions from several vendors, the complexity of managing today’s enterprise networks has increased significantly as well,” said Ritesh Mukherjee, Vice President of Product Management, 128 Technology.  “ZPE Systems has established itself as an innovator in the area of network management. Through this partnership we are taking steps to ensure our customers can experience the benefits of software-defined routing, while also maintaining the highest levels of visibility, management and control of their networks.”

    Both companies are intimately familiar with each other’s products, which makes for an ideal offering for customers looking to consolidate their infrastructure, cut costs, and meet the demands of their branch networks. This all-in-one solution is further improved by Nodegrid’s remote out-of-band capabilities. Nodegrid’s out-of-band is supported through separate WAN links as well as through major cellular networks. This gives customers reliable access to their critical systems and high-availability environments, even during outages and service disruptions.

    Together, ZPE Systems and 128T pledge to deliver the highest quality support, and have already demonstrated their strong partnership for a top utilities provider. When this customer required help with their proof-of-concept (POC), ZPE and 128T came together to assist with creating a streamlined and efficient design for the customer’s required implementation.

    Read the official press release here.

    About ZPE Systems, Inc.

    ZPE Systems is rethinking the way networks are built and managed by providing software-defined, vendor-neutral infrastructure management and networking solutions.

    ZPE Systems’ Nodegrid® platform consolidates, organizes, and simplifies the need for a complete remote access and control solution; Nodegrid solutions address the OOB management needs of the data center, unifies edge networking environments, manages converged infrastructure and provides intelligent automation. ZPE’s smart, consolidated IT management solutions reduce downtime, deliver OPEX savings, and extend the reach of IT workforces.

    ZPE’s global headquarters is located in Fremont, California with offices throughout the US and globally in Ireland, India, Brazil and Japan.

    ZPE Systems, the ZPE logo and Nodegrid are registered trademarks of ZPE Systems, Inc.

    To learn more, visit www.zpesystems.com.

    About 128 Technology

    We’re relentless in our commitment to creating a world where the network is no longer following changes in the computing environment—it’s leading.

    We are serial entrepreneurs, die-hard technologists, and principled pragmatists. But most of all, we’re purists—when there’s an important problem to solve, we do it right, or we don’t do it at all. The world needs more than yet another temporary solution. It needs a radical redesign of the core network building block—the router—and that’s what we’ve done. We took our innovation down to the IP layer to solve for every connected session because when the underlay works, the overlay goes away—and so does the accumulation of technical debt.

    To learn more, visit www.128technology.com.

    How ZPE Systems Improves Secure Access Service Edge

    Secure Access Service Edge transforms edge networking. See how ZPE Systems — a leading innovator in network infrastructure management — introduces even more capabilities to this cloud-based solution.

    What is Secure Access Service Edge?

    Secure Access Service Edge, or SASE (‘sassy’), is a new concept that’s disrupting traditional edge networking. SASE combines networking and security services in the cloud, to deliver both wherever you need them. This means bringing safe access to every edge of your network, whether it’s to your most remote branch locations, or to on-the-go users traveling across the globe.
    Jordan Baker
    “SASE provides flexible, on-demand edge networking that keeps users protected no matter where they are…” – Jordan Baker, Sr. Technology Writer + IT Nerd

    The Problem

    Organizations are more distributed than ever, forcing you to backhaul traffic through your data center and main enterprise firewall. This leaves you dealing with several crippling issues, like:
    • Slowed speeds due to bottlenecking
    • Frequent delays from service-chaining latencies
    • Balancing connectivity vs security, especially at remote sites
    • Cumbersome scaling that requires loads of time & resources

    The Solution

    With SASE, you get a cloud-based solution that delivers safe and reliable access as close to users as possible. SASE combines network services such as SD-WAN, bandwidth aggregation, and NaaS with security solutions like FWaaS, Cloud SWG, and VPN. It delivers all these via an identity-driven, cloud-based model and allows users to connect from anywhere, while your main network can regain smooth operation. In short, SASE untethers your network edge so users can connect wherever they go:
    • Eliminate bottlenecking with agile security
    • Get fast service using tightly-coupled virtualized functions
    • Deliver reliable & secure access anywhere, thanks to the cloud
    • Scale on demand using built-in automation support

    Why Use SASE?

    Traditionally, scaling involves deploying complex stacks of networking and security solutions. Every device in your stack requires careful provisioning, which drags down a lot of your resources and complicates your ability to bring new locations online. But with SASE, you can deploy fewer devices thanks to a converged, cloud-based stack. Because your critical functions are no longer served by individual devices, you get the flexibility to scale on demand. To manage your network, SASE simplifies your job because it is a converged software stack in the cloud. You don’t need to deal with cumbersome, on-site management or a mishmash of loosely-coupled point solutions. Your IT staff can manage your network remotely because access is no longer bound to certain locations. Your SASE platform connects your network resources and allows you to access them all from one place.

    ZPE Systems Gives You Even More Flexibility

    ZPE Systems’ Nodegrid family of hardware and software provide you with an innovative SASE network management platform. Nodegrid features consolidated, all-in-one devices that reduce your stack and your hardware footprint. The patented x86 64-bit architecture lets you host virtualized applications as well. Instead of having to juggle third-party hosting solutions, you can deploy network functions directly on Nodegrid appliances. Nodegrid is also vendor neutral, giving you the freedom to tailor your solutions to your needs. You don’t have to compromise based on a specific vendor’s offerings. Instead, choose the combination of SD-WAN, firewall, cybersecurity, and other applications that suit you, no matter which vendors they’re from. The built-in Nodegrid software gives you an additional layer of convenience, providing a single interface that normalizes control of all your solutions. You can perform updates, maintenance, and other tasks across your network, all using one intuitive tool. To top it off, ZPE’s Nodegrid devices support automation using popular tools such as Ansible, Python, JSON, Bash, and others. You can streamline scaling, and even set up zero touch provisioning to automate every deployment. Nodegrid appliances are also modular so you can adapt more easily to your business’ changing needs. Remote out-of-band management capabilities enhance your visibility and control, while dual-cellular failover keeps you more resistant to outages and helps you maintain business continuity. Article originally featured in CIO Review

    Control More of Your Network with SD-Branch

    In recent years, SD-WAN has addressed enterprise networking challenges by virtualizing the components of traditional WANs. This software-defined approach offers greater reliability by using augmented connection types, improved traffic routing through increased network transparency, and added security over broadband pathways. In all, SD-WAN provides more operational agility thanks to simple, centralized network management that allows you to remotely view and control WANs. However, traditional SD-WAN technology applies to the larger network, and does not permeate into the LANs of your individual branch locations. This leads to ever-present issues regarding performance optimization, security, and visibility. These are only compounded by the fact that each branch typically must manage a complex array of boxes that can include servers, ethernet switches, Wi-Fi controllers, and other elements, all with their own unique operating systems and management consoles. Enter SD-Branch, the solution that simplifies WAN and LAN management by consolidating multiple network functionalities. SD-Branch integrates SD-WAN, routing, firewalls, security, and LAN functions in a single platform, giving you the advantage of even greater operational agility. SD-Branch helps monitor and manage all the devices within a branch, including printers, TVs, thermostats, and other IoT devices. Benefit from more efficient bandwidth use & improved QoS, hardened security, and granular visibility at the branch level. SD-Branch can be deployed in greenfield locations, or used to upgrade branch-office boxes in smaller branches.

    How does it work, and what makes it better?

    SD-Branch integrates SD-WAN, routing, firewalls, security, and LAN or Wi-Fi functions in one platform to provide centralized and unified network management. All of these are combined as virtual functions in a cloud-like NaaS model, which allows for automated management as well as services that can be easily adjusted as business needs change. Improve operational agility thanks to rapid deployment and provisioning, centralized management, and reduced hardware costs and operating expenses. IT teams can now rapidly deploy and provision a network branch-in-a-box, and remotely identify and remedy application slowdowns. This eliminates the need for IT personnel to physically visit branch locations for support purposes, which can significantly decrease operating expenses. And to further reduce costs, branch software can be deployed on specialized hardware that consolidates network functions. Using a single pane of glass, SD-Branch provides you with centralized management for all your branch locations.
    Consider this business case: Your business has 100 office locations around the world, and each location uses an array of network devices. For network-related issues, your IT teams average 25 hours per month on-site at each location — performing troubleshooting tasks, updating devices, and addressing security breaches.

    Standard Remote Location Deployment – Pre-ZPE Systems’ Nodegrid Solutions

    100 locations x 25 hours = 2,500 hours every month While teams are on-site at these locations, they are unable to attend to more business-critical IT functions. Your organization loses 2,500 hours every month to basic networking tasks, which is time that could be spent caring for your business’ needs.

    Remote Location Deployment – With ZPE Systems’ Nodegrid Solutions

    SD-Branch significantly reduces the time needed to perform networking tasks, by virtualizing your networks’ separate functions and running them on a single platform. With centralized management, your IT teams can remotely view and control all of your organization’s SD-WANs and branches using a single interface. Are a location’s users experiencing Wi-Fi outages? Reboot the router remotely in seconds. Do employees suffer slower speeds due to a network password leak? Use SD-Branch to reset it and define access policies that allow only employees to use the network. Are casual video streaming and social media browsing sucking up valuable bandwidth? Set a rule to block specific sites altogether. Because SD-Branch allows you to see the activity within the branch, you can view and optimize each location’s network to suit your business needs. You get better operational agility using a system that consolidates functions and gives you control of your network via a single pane of glass.

    What your SD-Branch is missing…

    ZPE Systems offers a secure branch network solution with our Nodegrid family of products. Get a 24×7 remote virtual presence throughout your network thanks to our out-of-band (OOB) expertise, and take advantage of SASE capabilities for additional security. Coupled with the ZPE Cloud, Nodegrid provides you with a complete solution, from deploying an office-in-a-box, to easily and remotely managing your entire network infrastructure. Get in touch to discover how Nodegrid simplifies and secures your branches.

    Let’s Talk SD-Branch and SASE

    If you would like more information on how the Nodegrid family of Open Infrastructure Management Solutions brings a refreshing new solution to the branch, contact a ZPE solution specialist by giving us a call -or- sending us an email. We look forward to hearing from you.