Clinic

41
Clinic Security and Policy Enforcement in Windows Server 2008

description

Clinic. Security and Policy Enforcement in Windows Server 2008. Introduction. Name Company affiliation Title/function Job responsibility Windows Server 2003, XP and Vista experience Security Experience Expectations. Facilities. Class hours Building hours Parking Restrooms Meals - PowerPoint PPT Presentation

Transcript of Clinic

Page 1: Clinic

Clinic

Security and Policy Enforcement in Windows

Server 2008

Page 2: Clinic

Introduction

Name

Company affiliation

Title/function

Job responsibility

Windows Server 2003, XP and Vista experience

Security Experience

Expectations

Page 3: Clinic

Facilities

Class hours

Building hours

Parking

Restrooms

Meals

Phones

Messages

Smoking

Recycling

Page 4: Clinic

About This Clinic

Description

Clinic Objectives

Audience

Prerequisites

Page 5: Clinic

Clinic Outline

Security Enhancements in Windows Server 2008

Network Access Protection

Page 6: Clinic

Technology Technology framework to help framework to help maximize the value maximize the value of your IT of your IT investmentsinvestmentsStructured way to Structured way to drive cost drive cost reduction, security reduction, security & efficiency gains & efficiency gains and boost agilityand boost agilityBased on industry Based on industry analyst and analyst and academic workacademic workProvides guidance Provides guidance and best practices and best practices for step-by-step for step-by-step implementationimplementation

Infrastructure Optimization

Page 7: Clinic

Security Enhancements in Windows Server 2008

Page 8: Clinic

Overview

Methods of Security and Policy Enforcement

Network Location Awareness

Network Access Protection

Windows Firewall with Advanced Security (WFAS)

Internet Protocol Security (IPSec)

Windows Server Hardening

Server and Domain Isolation

Active Directory Domain Services Auditing

Read-Only Domain Controller (RODC)

BitLocker Drive Encryption

Removable Device Installation Control

Enterprise PKI

Methods of Security and Policy Enforcement

Network Location Awareness

Network Access Protection

Windows Firewall with Advanced Security (WFAS)

Internet Protocol Security (IPSec)

Windows Server Hardening

Server and Domain Isolation

Active Directory Domain Services Auditing

Read-Only Domain Controller (RODC)

BitLocker Drive Encryption

Removable Device Installation Control

Enterprise PKI

Page 9: Clinic

Technical Background

Windows Firewall with Advanced SecurityWindows Firewall with Advanced Security

Internet Security Protocol (IPSec)Internet Security Protocol (IPSec)

Active Directory Domain Services AuditingActive Directory Domain Services Auditing

Read-Only Domain Controller (RODC)Read-Only Domain Controller (RODC)

Enterprise PKIEnterprise PKI

BitLocker Drive EncryptionBitLocker Drive Encryption

Page 10: Clinic

Windows Firewall with Advanced Security

Page 11: Clinic

Demonstration: Windows Firewall with Advanced Security

• Creating Inbound and Outbound Rules

• Creating a Firewall Rule Limiting a Service

Page 12: Clinic

IPSec

Integrated with WFAS

IPSec Improvements

Simplified IPSec Policy Configuration

Client-to-DC IPSec Protection

Improved Load Balancing and Clustering Server Support

Improved IPSec Authentication

Integration with NAP

Multiple Authentication Methods

New Cryptographic Support

Integrated IPv4 and IPv6 Support

Extended Events and Performance Monitor Counters

Network Diagnostics Framework Support

Integrated with WFAS

IPSec Improvements

Simplified IPSec Policy Configuration

Client-to-DC IPSec Protection

Improved Load Balancing and Clustering Server Support

Improved IPSec Authentication

Integration with NAP

Multiple Authentication Methods

New Cryptographic Support

Integrated IPv4 and IPv6 Support

Extended Events and Performance Monitor Counters

Network Diagnostics Framework Support

Page 13: Clinic

Demonstration: Creating IPSec Policies

• Creating an IPSec Rule

• Specifying different Authentication Methods

• Activate and Deactivate Rules

Page 14: Clinic

AD Domain Services Auditing

What changes have been made to AD DS auditing?

What changes have been made to AD DS auditing?

Page 15: Clinic

Read-Only Domain Controller (RODC)

New Functionality

AD Database

Unidirectional Replication

Credential Caching

Password Replication Policy

Administrator Role Separation

Read-Only DNS

New Functionality

AD Database

Unidirectional Replication

Credential Caching

Password Replication Policy

Administrator Role Separation

Read-Only DNS

Requirements/Special ConsiderationsRequirements/Special Considerations

RODC

Page 16: Clinic

BitLocker Drive Encryption (BDE)

Data Protection

Drive Encryption

Integrity Checking

Data Protection

Drive Encryption

Integrity Checking

BDE Hardware and Software RequirementsBDE Hardware and Software Requirements

Page 17: Clinic

Enterprise PKI

Easier management through PKIView

Certificate Web Enrollment

Network Device Enrollment Service

Managing Certificate with Group Policy

Certificate Deployment Changes

Online Certificate Status Protocol (OCSP) Support

Cryptographic Next Generation

Easier management through PKIView

Certificate Web Enrollment

Network Device Enrollment Service

Managing Certificate with Group Policy

Certificate Deployment Changes

Online Certificate Status Protocol (OCSP) Support

Cryptographic Next Generation

Page 18: Clinic

Implementation/Usage Scenarios

Enforce Security PolicyEnforce Security Policy

Improve Domain SecurityImprove Domain Security

Improve System SecurityImprove System Security

Improve Network Communications SecurityImprove Network Communications Security

Page 19: Clinic

Recommendations

Implement Network Access ProtectionImplement Network Access Protection

Use Windows Firewall and Advanced Security to implement IPSecUse Windows Firewall and Advanced Security to implement IPSec

Deploy Read-Only Domain Controllers, where appropriateDeploy Read-Only Domain Controllers, where appropriate

Implement BitLocker Drive EncryptionImplement BitLocker Drive Encryption

Carefully test and plan all security policiesCarefully test and plan all security policies

Take advantage of PKI improvementsTake advantage of PKI improvements

Page 20: Clinic

Summary

Windows Server 2008 includes a variety of new security initiatives and features:

• Network Access Protection• Windows Firewall and Advanced Security (WFAS)

enhancements• IPSec improvements• Windows Server Hardening• Server and Domain Isolation• Active Directory Domain Services Auditing• Read-Only Domain Controllers (RODCs)• BitLocker Drive Encryption• Removeable Device Installation Control• Improvements to Enterprise PKI capabilities

Windows Server 2008 includes a variety of new security initiatives and features:

• Network Access Protection• Windows Firewall and Advanced Security (WFAS)

enhancements• IPSec improvements• Windows Server Hardening• Server and Domain Isolation• Active Directory Domain Services Auditing• Read-Only Domain Controllers (RODCs)• BitLocker Drive Encryption• Removeable Device Installation Control• Improvements to Enterprise PKI capabilities

Page 21: Clinic

Questions and Answers

Page 22: Clinic

Network Access Protection in Windows Server 2008

Page 23: Clinic

Overview

Network Access ProtectionNetwork Access Protection

Net work Access Protection Network Access Quarantine Control

Internal, VPN and Remote Access Client

Only VPN and Remote Access Clients

IPSec, 802.1X, DHCP and VPN DHCP and VPN

NAP NPS and Client included in Windows Server 2008 ; NAP client included in Vista

Installed from Windows Server 2003 Resource Kit

Page 24: Clinic

Technical Background

NAP Platform ArchitectureNAP Platform Architecture

NAP Enforcement MethodsNAP Enforcement Methods

NAP InfrastructureNAP Infrastructure

NAP Client ArchitectureNAP Client Architecture

NAP Server ArchitectureNAP Server Architecture

Component CommunicationComponent Communication

Page 25: Clinic

NAP Infrastructure

Health Policy ValidationHealth Policy Validation

Health Policy ComplianceHealth Policy Compliance

Automatic RemediationAutomatic Remediation

Limited AccessLimited Access

Page 26: Clinic

NAP Platform Architecture

Page 27: Clinic

NAP Enforcement Client

802.1X802.1X

VPNVPN

IPSecIPSec

DHCPDHCP

NPS RADIUSNPS RADIUS

Page 28: Clinic

Demonstration: Network Access Protection

• Create a NAP Policy

• Using the MMC to Create NAP Configuration settings

• Create a new RADIUS Client

• Create a new System Health Validator for Windows Vista and Windows XP SP2

Page 29: Clinic

How NAP Works

IPSec EnforcementIPSec Enforcement

IEEE 802.1XIEEE 802.1X

Logical NetworksLogical Networks

Remote Access VPNsRemote Access VPNs

DHCPDHCP

Page 30: Clinic

IPSec Enforcement in Logical Networks

Page 31: Clinic

Communication Initiation Process with IPSec Enforcement

Page 32: Clinic

NAP Client Health Certificate Process

Page 33: Clinic

IPSec Enforcement in NAP

Page 34: Clinic

802.1x Authenticated Connections

Page 35: Clinic

NAP Authentication Process Background

Network Access Protection SettingsNetwork Access Protection Settings

Authorization PoliciesAuthorization Policies

Authentication ProcessAuthentication Process

Page 36: Clinic

Implementation/Usage Scenarios

Ensuring the Health of Corporate DesktopsEnsuring the Health of Corporate Desktops

Checking the Health and Status of Roaming LaptopsChecking the Health and Status of Roaming Laptops

Determining the Health of Visiting LaptopsDetermining the Health of Visiting Laptops

Verify the Compliance of Home ComputersVerify the Compliance of Home Computers

Page 37: Clinic

Recommendations

Carefully test and verify all IPSec PoliciesCarefully test and verify all IPSec Policies

Use Quality of Service to improve bandwidthUse Quality of Service to improve bandwidth

When using IPSec – employ ESP with encryptionWhen using IPSec – employ ESP with encryption

Plan to Prioritize traffic on the networkPlan to Prioritize traffic on the network

Apply Network Access Protection to secure client computers Apply Network Access Protection to secure client computers

Consider Using Domain IsolationConsider Using Domain Isolation

Page 38: Clinic

Summary

Network Access Protection:

Secures Remote Computers before accessing the Network

Has Client and Server Components

Can Use One or More of Several methods for Enforcement

IPSec

802.1X

VPN

DHCP

Provides Support for Third Party Software

Network Access Protection:

Secures Remote Computers before accessing the Network

Has Client and Server Components

Can Use One or More of Several methods for Enforcement

IPSec

802.1X

VPN

DHCP

Provides Support for Third Party Software

Page 39: Clinic

Questions and Answers

Page 40: Clinic

Lab: Network Access Protection

In this lab, you will:

Network Communications using WFAS

Enforcing network communication policy using Policy-based QoS

Network Access Protection with Windows Server 2008

Page 41: Clinic

What Next?

Windows Server 2008 Beta: https://connect.microsoft.com

Home Page: http://www.microsoft.com/windowsserver/longhorn/default.mspx

Webcasts: http://www.microsoft.com/windowsserver/longhorn/webcasts.mspx

Forums: http://forums.microsoft.com/TechNet/default.aspx?ForumGroupID=161&SiteID=17

Network Access Protection• Home Page: http://www.microsoft.com/nap

• Introduction to Network Access Protection: http://go.microsoft.com/fwlink/?LinkId=49884

• Network Access Protection Platform Architecture: http://go.microsoft.com/fwlink/?LinkId=49885

• Network Access Protection Frequently Asked Questions: http://go.microsoft.com/fwlink/?LinkId=49886

• IPSec: http://www.microsoft.com/ipsec

• Server and Domain Isolation: http://www.microsoft.com/technet/network/sdiso/default.mspx