Cisco Cisco Aironet 1250 Series Access Point 정보 가이드

다운로드
페이지 3
Martin Pencev
Head of IT
Unicredit Slovakia
Customer Case Study
Solution
The new Cisco ISE security solution was implemented by local specialist ANECT and 
builds on a Cisco Borderless Network foundation. It supports a Cisco Open Network 
Environment (ONE) architecture for automated provisioning and fast deployment 
of services and applications. Deployed across the bank’s fixed local and wide area 
networks, Cisco ISE covers all 75 branches. The solution also secures the Cisco 
Unified Wireless Network at its headquarters buildings in Bratislava, managed by a 
Cisco 5508 Wireless Controller in each data center, so executives can connect to 
the wireless LAN using notebooks with Cisco AnyConnect software. 
To optimize visibility and control, the Cisco ISE security solution was integrated with 
the Cisco Prime network management platform. That combination brings together the 
wired and wireless domains with security policy management in a converged package 
for faster troubleshooting and more efficient network operations. This capability 
enables visibility into endpoint connectivity regardless of device, network, or location.
“A key aim for us was to take advantage of the profiling capabilities of Cisco ISE for a 
more secure and dynamic network without increasing management,” says Pencev.
During the implementation phase, the IT team used some of its NAC hardware 
as a test environment for Cisco ISE, and has continued doing so as more ISE 
features are brought into play. Since Cisco ISE requires only two physical and two 
virtual servers, compared to the eight needed previously, the upgrade allows more 
efficient resource deployment.
Separate service set identifiers (SSIDs) were created for corporate users, onsite 
contractors, and guests. Corporate users have unrestricted access, with security 
assured wherever they work. Contractors working regularly on bank premises on 
domain PCs are in a different security group, and occasional visitors are authenticated 
via a dedicated guest portal.
Results
For UniCredit Slovakia, the key benefit of the Cisco ISE solution is that it enables 
unified security policy management and brings a significant uplift in security. “In 
a penetration test that followed the ISE implementation, the auditing agency was 
unable to make any headway and had to ask us for special access to continue 
testing,” says Pencev.
The guest network is quicker and easier to manage: a matter of growing importance 
to the bank as the number of visitors from UniCredit subsidiaries elsewhere in Europe 
mounts up in advance of the planned merger. “We have many more visits by foreign 
managers now, and they require corporate access,” Pencev says. “Using the Cisco 
ISE guest portal, we can flexibly and securely create temporary access for them.”
In such a situation of growing cross-border staff mobility, the bring-your-own-device 
(BYOD) policy enabled by Cisco ISE, allied with the existing wireless infrastructure 
based on Cisco Aironet® 1142 Series Wireless Access Points and Cisco 5508 Series 
Wireless Controllers will provide convenience for those itinerant managers.
Meanwhile, greater ease of troubleshooting means a corresponding gain in operational 
efficiency, with less time needed to resolve incidents. Clarification of roles for the IT 
team is another valuable outcome. Setting up guest network access is now a simple 
matter handled by the firm’s chief security officer, freeing the network administration 
team to get on with other tasks.
The new system has led to a major improvement in network management and 
visibility. Any endpoint can be deployed rapidly, with granular network access based 
on the endpoint type, including IP cameras, Cisco wireless access points, printers, 
and so on. And the single management pane allows the IT team to see at a glance 
all attributes assigned to any user.
© 2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. 
 
Page 2 of 3