securing ssh admin access pragma systems fortress ssh cisco enterprise routing products

16
Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

Upload: dorthy-caldwell

Post on 21-Jan-2016

233 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

Securing SSH Admin Access

Pragma Systems Fortress SSH Cisco Enterprise Routing Products

Page 2: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• Unauthorized access to command line• Stolen passwords• Revoked / Expired Public Keys• Spoofing the client

The Threat:

X.509 certificate with RFC 6187 (single factor) Server side certificate validation

CAC/smartcard with RFC 6187 (2 factor)Most secure authentication – Sever side certificate and PIN

NEWOnly from Cisco and Pragma

Page 3: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

For customers that need:

Secure access to command line

With two factor authentication Authenticate with X.509 certificate & PIN

• Most secure

• Government Certified

• Standard RFC-6187

• First end-to-end solution with Cisco and Pragma Systems

Page 4: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

SSH Access with DoD Common Access Cards

X.509 Authentication

SSH Session Establishment

CiscoSSH Server Feature

PragmaFortress CL SSH Client

CAC card reader

Page 5: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

Demonstration

Page 6: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• To reach the router or switch,

• End-user starts SSH session on their PC

Fortress CL Client

Page 7: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• User inserts Smart Card

• Smart card has the user’s credentials

Page 8: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• User now clicks “connect button”.

Page 9: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

User enters User-ID;

Selects Smart Card / CAC button

Click on ellipsis button

Page 10: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

If end-user has more than one credential, he selects the certificate that he wants to use.

Certificates are stored on the smart-card.

Page 11: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• Click on connect

David.S.Kulwin

David.S.Kulwin

Page 12: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• End-user enters PIN.

• Router now has:1. Certificate and2. PIN 3. User name

SSH handshake now proceeds

Page 13: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• SSH session starts from end-user PC to Cisco Router.

Page 14: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

• Easy to use two-factor authentication • X.509 Certificates for SSH • Standards Compliant• FIPS certified

For Secure Access:

Page 15: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products

For Further Information:

Contact your Pragma representative for a demonstration or 30 day trial version

[email protected]

Contact your Cisco Systems sales representative.

Page 16: Securing SSH Admin Access Pragma Systems Fortress SSH Cisco Enterprise Routing Products